MT 3.33发布: 安全漏洞修正


MT昨天发布了一个安全更新:建议用3.2版本的也升级到3.33

从3.32升级的过程:
下载:wget http://www.sixapart.com/movabletype/downloads/MT-3.33-patches/MT-3.32-patch-en.zip

解包: unzip MT-3.32-patch-en.zip
Archive: MT-3.32-patch-en.zip
creating: MT-3.32-patch-en/
creating: MT-3.32-patch-en/plugins/
creating: MT-3.32-patch-en/plugins/feeds-app-lite/
creating: MT-3.32-patch-en/plugins/feeds-app-lite/lib/
creating: MT-3.32-patch-en/plugins/feeds-app-lite/lib/MT/
creating: MT-3.32-patch-en/plugins/feeds-app-lite/lib/MT/App/
inflating: MT-3.32-patch-en/plugins/feeds-app-lite/lib/MT/App/FeedsWidget.pm
inflating: MT-3.32-patch-en/plugins/feeds-app-lite/mt-feeds.pl
creating: MT-3.32-patch-en/plugins/nofollow/
inflating: MT-3.32-patch-en/plugins/nofollow/nofollow.pl
creating: MT-3.32-patch-en/lib/
creating: MT-3.32-patch-en/lib/MT/
inflating: MT-3.32-patch-en/lib/MT/App.pm
inflating: MT-3.32-patch-en/lib/MT/Log.pm
inflating: MT-3.32-patch-en/lib/MT/Sanitize.pm
creating: MT-3.32-patch-en/lib/MT/App/
inflating: MT-3.32-patch-en/lib/MT/App/CMS.pm
inflating: MT-3.32-patch-en/lib/MT/App/Search.pm
inflating: MT-3.32-patch-en/lib/MT.pm
creating: MT-3.32-patch-en/php/
creating: MT-3.32-patch-en/php/lib/
inflating: MT-3.32-patch-en/php/lib/sanitize_lib.php
inflating: MT-3.32-patch-en/php/mt.php

复制到MT安装目录下:sudo cp -R * /home/path/to/cgi-bin/mt/

登录后看到:
Version 3.33 Copyright © 2001-2006 Six Apart. All Rights Reserved.
说明更新成功了。

SixApart相关说明
Today we are releasing required updates for both Movable Type and Movable Type Enterprise to fix a number of vulnerabilities affecting all previous versions of the platform. The current status of our security update process:

* This is a mandatory update due to the severity of the combined vulnerabilities.
* These vulnerabilities were discovered by our own team during a routine security evaluation.
* There are currently no known malicious exploits targeting Movable Type for these issues.
* We will be disclosing full details of the vulnerabilities on our Professional Network blog in a couple of days allowing you to update in the meantime without incurring unnecessary risk.

作者:车东 发表于:2006-09-27 09:09 最后更新于:2007-04-22 21:04
版权声明:可以转载,转载时请务必以超链接形式标明文章 的原始出处和作者信息及本版权声明

Comments

已更新~

发表一个评论

(如果你此前从未在此 Blog 上发表过评论,则你的评论必须在 Blog 主人验证后才能显示,请你耐心等候。)

Creative Commons License
此 Blog 中的日记遵循以下授权 Creative Commons(创作共用)授权.
Powered by
Movable Type 3.36