MT昨天发布了一个安全更新:建议用3.2版本的也升级到3.33
从3.32升级的过程:
下载:wget http://www.sixapart.com/movabletype/downloads/MT-3.33-patches/MT-3.32-patch-en.zip
解包: unzip MT-3.32-patch-en.zip
Archive: MT-3.32-patch-en.zip
creating: MT-3.32-patch-en/
creating: MT-3.32-patch-en/plugins/
creating: MT-3.32-patch-en/plugins/feeds-app-lite/
creating: MT-3.32-patch-en/plugins/feeds-app-lite/lib/
creating: MT-3.32-patch-en/plugins/feeds-app-lite/lib/MT/
creating: MT-3.32-patch-en/plugins/feeds-app-lite/lib/MT/App/
inflating: MT-3.32-patch-en/plugins/feeds-app-lite/lib/MT/App/FeedsWidget.pm
inflating: MT-3.32-patch-en/plugins/feeds-app-lite/mt-feeds.pl
creating: MT-3.32-patch-en/plugins/nofollow/
inflating: MT-3.32-patch-en/plugins/nofollow/nofollow.pl
creating: MT-3.32-patch-en/lib/
creating: MT-3.32-patch-en/lib/MT/
inflating: MT-3.32-patch-en/lib/MT/App.pm
inflating: MT-3.32-patch-en/lib/MT/Log.pm
inflating: MT-3.32-patch-en/lib/MT/Sanitize.pm
creating: MT-3.32-patch-en/lib/MT/App/
inflating: MT-3.32-patch-en/lib/MT/App/CMS.pm
inflating: MT-3.32-patch-en/lib/MT/App/Search.pm
inflating: MT-3.32-patch-en/lib/MT.pm
creating: MT-3.32-patch-en/php/
creating: MT-3.32-patch-en/php/lib/
inflating: MT-3.32-patch-en/php/lib/sanitize_lib.php
inflating: MT-3.32-patch-en/php/mt.php
复制到MT安装目录下:sudo cp -R * /home/path/to/cgi-bin/mt/
登录后看到:
Version 3.33 Copyright © 2001-2006 Six Apart. All Rights Reserved.
说明更新成功了。
SixApart相关说明:
Today we are releasing required updates for both Movable Type and Movable Type Enterprise to fix a number of vulnerabilities affecting all previous versions of the platform. The current status of our security update process:
* This is a mandatory update due to the severity of the combined vulnerabilities.
* These vulnerabilities were discovered by our own team during a routine security evaluation.
* There are currently no known malicious exploits targeting Movable Type for these issues.
* We will be disclosing full details of the vulnerabilities on our Professional Network blog in a couple of days allowing you to update in the meantime without incurring unnecessary risk.
版权声明:可以转载,转载时请务必以超链接形式标明文章 MT 3.33发布: 安全漏洞修正 的原始出处和作者信息及本版权声明。
http://www.chedong.com/blog/archives/001208.html
Comments
http://blog.thought-mesh.net/solidwallofcode/trackback_by_name_3_3.php
更新说明, 把 trackback 打开看看先
由: Fenng 发表于 2006年09月27日 上午10时19分
已更新~
由: wget 发表于 2006年09月27日 下午02时27分