Follow us on Twitter X-Cart on Facebook Wiki
Shopping cart software Solutions for online shops and malls
 

security-patch-2007-10-29.tgz

 
Reply
   X-Cart forums > News and Announcements
 
Thread Tools
  #41  
Old 11-07-2007, 02:02 PM
 
starwest starwest is offline
 

eXpert
  
Join Date: Sep 2006
Posts: 268
 

Default Re: security-patch-2007-10-29.tgz

To clarify, if applied manually, do the changes listed in the .diff files work correctly or not? Are the issues people are seeing patching/installation issues, or are they issues with the code changes themselves?
__________________
X-Cart Gold v4.1.10 [unix]
AOM, Special Offers, CDSEO Pro, Remember Anon Carts, Back-In-Stock Notifications, MM3, Feed Manager
Reply With Quote
  #42  
Old 11-07-2007, 02:03 PM
 
balinor balinor is offline
 

Veteran
  
Join Date: Oct 2003
Location: Connecticut, USA
Posts: 30,253
 

Default Re: security-patch-2007-10-29.tgz

If you want to patch it manually pulling the changes out of the diff file or the new versions of the files they issued first it will work. Not sure what affect the changes have on the cart....
__________________
Padraic Ryan
Ryan Design Studio
Professional E-Commerce Development
Reply With Quote
  #43  
Old 11-07-2007, 02:04 PM
 
zebu zebu is offline
 

eXpert
  
Join Date: Oct 2006
Posts: 310
 

Default Problems applying new "security-patch-2007-10-29.tgz"

I recieved advise from the Qualiteam advising to apply the above patch to overcome a sql threat.

I am running 4.1.8 and downloaed the 4.1.8 upgrade patch. I seem to only have a few of teh files on my system compared to what is in the patch.

Can some one assist?

Below are the files in the patch - and the files I have or are missing

HTML Code:
4.1.8 - magnifier_xml.php (cant find this one) - Include - banner_stata.php (cant find this one) - referre_sales.php (cant find this one) -Func - func.db.php (got this one) - func.order.php (got this one) - Modules - Gift_Registry (cant find this folder) - Google_Checkout (Found) - Product Options (Found) - RMA (cant find this folder) -Survey (cant find this folder)

Am I missing something really obvious here? I have done a file serach of the whole website?
__________________
Version 4.7.7
Reply With Quote
  #44  
Old 11-07-2007, 02:14 PM
 
carpeperdiem carpeperdiem is offline
 

X-Guru
  
Join Date: Jul 2006
Location: New York City, USA
Posts: 5,399
 

Default Re: Problems applying new "security-patch-2007-10-29.tgz"

Quote:
Originally Posted by zebu
I recieved advise from the Qualiteam advising to apply the above patch to overcome a sql threat.
Am I missing something really obvious here? I have done a file serach of the whole website?

zebu,

no need to start a new thread.

yes, it's obvious.

the other files that you don't have are related to x-rma (RMA), or x-affiliate (banner_stats.php and referrer_sales.php), or x-something or another... no worries... just patch what you have.
__________________
xcart 4.5.4 gold+ w/x-payments 1.0.6; xcart gold 4.4.4
Reply With Quote
  #45  
Old 11-07-2007, 02:38 PM
 
Light Speed Light Speed is offline
 

X-Adept
  
Join Date: Mar 2003
Posts: 921
 

Default Re: security-patch-2007-10-29.tgz

IMHO The patch should look to see if those addons are installed.
If they are not ........... it should not attempt to patch files that are not there!!

Basic programming.
Reply With Quote
  #46  
Old 11-08-2007, 11:14 AM
 
jmccunep jmccunep is offline
 

Advanced Member
  
Join Date: Nov 2003
Posts: 68
 

Default Re: security-patch-2007-10-29.tgz

Does this security patch, which I've already applied to my 4.0.17 shop, need to be re-applied after upgrading to 4.0.19 or do the upgrade kits already incorporate this patch?

I'm planning to move my shop to the 4.1 branch so the same question will apply when the upgrades are complete through 4.1.8.

4.0.17 X-Cart Gold, running on Linux.
__________________
J McCune Porter | twinoakshammocks.com
X-Cart Gold version 4.7.11, unix server
X-Cart reBOOT Template by X-Cart Mods
Reply With Quote
  #47  
Old 11-08-2007, 11:17 AM
 
carpeperdiem carpeperdiem is offline
 

X-Guru
  
Join Date: Jul 2006
Location: New York City, USA
Posts: 5,399
 

Default Re: security-patch-2007-10-29.tgz

Considering this patch did not exist when the 4.0.19 upgrade was created, you can assume that 4.0.19 needs the patch again.

And if you read the docs, if your store is not 4.1.9 or later, you need the patch.

If you're going to upgrade to 4.1.x, may as well go all the way to 4.1.9 -- no reason to stop at a lower rev.
__________________
xcart 4.5.4 gold+ w/x-payments 1.0.6; xcart gold 4.4.4
Reply With Quote
  #48  
Old 11-08-2007, 10:54 PM
 
ironmansp ironmansp is offline
 

Member
  
Join Date: Nov 2007
Posts: 24
 

Default Re: security-patch-2007-10-29.tgz

This is the main thing because I suggest a mod MOD manager...
__________________
Xcart in Spain
4.1.9
Reply With Quote
  #49  
Old 11-09-2007, 09:01 AM
 
gravel gravel is offline
 

Senior Member
  
Join Date: Mar 2004
Posts: 156
 

Default Re: security-patch-2007-10-29.tgz

Quote:
Originally Posted by balinor
All we are asking for is a set of .diff files for each version that actually WORK on a fresh install of X-Cart.
Did X-Cart ever issue useable .diff files?

If the answer is "No", can somebody from X-Cart give us an ETA?
__________________
X-Cart version 4.0.17
X-Cart version 4.0.18
Web servers = Apache
OS = Linux
Reply With Quote
  #50  
Old 11-09-2007, 09:25 AM
 
carpeperdiem carpeperdiem is offline
 

X-Guru
  
Join Date: Jul 2006
Location: New York City, USA
Posts: 5,399
 

Default Re: security-patch-2007-10-29.tgz

It's easy to edit the diff to your store... if you don't have x-affil, look for:

diff -ru ../xcart_orig/include/referred_sales.php ./include/referred_sales.php

and cut this line and everything after, through

Only in ./include/func: func.db.php.rej

etc...

HOWEVER -- I MUST WARN THE FORUM PARTICIPANTS:

Your 4.1.8 store may not need any changes!

I did a compare on the files in the patch, and my 4.1.8 files were identical to the patch...

How can that be?
__________________
xcart 4.5.4 gold+ w/x-payments 1.0.6; xcart gold 4.4.4
Reply With Quote
Reply
   X-Cart forums > News and Announcements



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -8. The time now is 10:55 AM.

   

 
X-Cart forums © 2001-2020