Follow us on Twitter X-Cart on Facebook Wiki
Shopping cart software Solutions for online shops and malls
 

security-patch-2007-10-29.tgz

 
Reply
   X-Cart forums > News and Announcements
 
Thread Tools
  #11  
Old 11-05-2007, 03:43 PM
 
balinor balinor is offline
 

Veteran
  
Join Date: Oct 2003
Location: Connecticut, USA
Posts: 30,253
 

Default Re: security-patch-2007-10-29.tgz

That's what I mean, they didn't issue a .diff, they just said 'here, replace your files'. You need to use a compare program and make the changes you find, and there are quite a few depending on how custom your func.php is.
__________________
Padraic Ryan
Ryan Design Studio
Professional E-Commerce Development
Reply With Quote
  #12  
Old 11-05-2007, 09:35 PM
 
Light Speed Light Speed is offline
 

X-Adept
  
Join Date: Mar 2003
Posts: 921
 

Default Re: security-patch-2007-10-29.tgz

I also did not receive an email regarding this security patch!!!!!!!!
Reply With Quote
  #13  
Old 11-05-2007, 10:01 PM
  wjbrewer's Avatar 
wjbrewer wjbrewer is offline
Banned
 

X-Adept
  
Join Date: Feb 2005
Location: Pittsburgh, PA
Posts: 504
 

Default Re: security-patch-2007-10-29.tgz

Quote:
Originally Posted by sunny
...is there any easy way to find what the actual changes are? Our include/func.php file is rather heavily modified (by x-cart, myself and one other mod) and I'm having a difficult time differentiated between the update code and that added for modifications by others. I compared the files and this doesn't do me any good. Is there any way to figure out just the lines changed for this update?

http://www.scootersoftware.com/
Reply With Quote
  #14  
Old 11-06-2007, 12:03 AM
  ambal's Avatar 
ambal ambal is offline
 

X-Cart team
  
Join Date: Sep 2002
Posts: 4,119
 

Default Re: security-patch-2007-10-29.tgz

Quote:
Originally Posted by Light Speed
I also did not receive an email regarding this security patch!!!!!!!!

You shouldn't worry about not getting the e-mail from us to the moment as you haven't got the e-mail YET. We send our newsletters in some portions usually in order not to create a huge overload impact on our servers like if we send them all at once. I am sure you'll get the e-mail in some time later.

Also, please make sure your spam filter allows messages from our domains.
__________________
Sincerely yours,
Alex Mulin
VP of Business Development for X-Cart
X-Payments product manager
Reply With Quote
  #15  
Old 11-06-2007, 04:06 AM
 
balinor balinor is offline
 

Veteran
  
Join Date: Oct 2003
Location: Connecticut, USA
Posts: 30,253
 

Default Re: security-patch-2007-10-29.tgz

Alexander, is there a reason this patch was not released as a .diff? You guys have created about 20 hours of work for me in having to go into each of my clients stores and compare their func.php file to the new one and make the appropriate changes.
__________________
Padraic Ryan
Ryan Design Studio
Professional E-Commerce Development
Reply With Quote
  #16  
Old 11-06-2007, 05:46 AM
  dire_lobo's Avatar 
dire_lobo dire_lobo is offline
 

Advanced Member
  
Join Date: Dec 2005
Posts: 53
 

Default Re: security-patch-2007-10-29.tgz

Howdy folks!'

I contacted X-Cart last night and received the following:

"The software architects informed that a diff patch for X-Cart will be released in the nearest 1-2 business days. We'll let you know as soon as it's available."

I also went in and made sure my contact email address was current - it wasn't (remember the massive spoofing campaign I weathered? - I had to change domains - and concommitantly, emails... and hadn't updated my profile at X-Cart). I updated/fixed that too.
__________________
4.1.8 live
shared server/hosted linux
Physical Location: New Mexico, USA
Server Location: Arizona, USA
Reply With Quote
  #17  
Old 11-06-2007, 05:47 AM
 
balinor balinor is offline
 

Veteran
  
Join Date: Oct 2003
Location: Connecticut, USA
Posts: 30,253
 

Default Re: security-patch-2007-10-29.tgz

Excellent...good to hear!
__________________
Padraic Ryan
Ryan Design Studio
Professional E-Commerce Development
Reply With Quote
  #18  
Old 11-06-2007, 05:57 AM
 
geckoday geckoday is offline
 

X-Wizard
  
Join Date: Aug 2005
Posts: 1,073
 

Default Re: security-patch-2007-10-29.tgz

Why is func.php full of changes that have nothing to do with patching security, such as discount calculations? A security patch should be just that and that alone. Now I've either got to test a dozen other things or manually pick out the security related changes from the patch.
__________________
Manuka Bay Company
X-Cart Version 4.0.19 [Linux]

UGG Boots and other fine sheepskin products
http://www.snowriver.com
Reply With Quote
  #19  
Old 11-06-2007, 06:03 AM
  Sheriff's Avatar 
Sheriff Sheriff is offline
 

X-Cart team
  
Join Date: Aug 2003
Posts: 981
 

Default Re: Security Patch - 11-1-07

Quote:
Originally Posted by balinor
Sure, it's in the file area/updates:

security-patch-2007-10-29.tgz

Edited the thread title to reflect this as well.

We've updated security-patch-2007-10-29.tgz in the XB file area and now it contains diff files too.

Also I've attached security-patch-2007-10-29_diffs-only.zip file to this message for further use.
Attached Files
File Type: zip security-patch-2007-10-29_diffs-only.zip (147.9 KB, 27 views)
Reply With Quote
  #20  
Old 11-06-2007, 06:12 AM
 
balinor balinor is offline
 

Veteran
  
Join Date: Oct 2003
Location: Connecticut, USA
Posts: 30,253
 

Default Re: security-patch-2007-10-29.tgz

Well that didn't work...on a fresh install of 4.1.8, the only file that patches is /include/func/func.db.php. The rest result in a 'could not patch' error, even though they are default files. Testing other versions now.
__________________
Padraic Ryan
Ryan Design Studio
Professional E-Commerce Development
Reply With Quote
Reply
   X-Cart forums > News and Announcements



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -8. The time now is 03:03 AM.

   

 
X-Cart forums © 2001-2020