« b2evolution 4.1.0 (beta) releasedb2evolution 4.0.4 (stable) released »

b2evolution 4.0.5 (stable) released & security fix

Permalink August 25, 2011 @ 05:21, by Francois Planque • Category: New releases, b2evolution.net

b2evolution 4.0.5 was released some time ago containing an important security fix.

It is recommended that everyone upgrades to that version.

Download here ?

We originally released this silently so that people would have time to upgrade without drawing any more attention to the security issue.

It is now time that people who don't nomally upgrade minor versions consider doing so too.

You might wait for b2evolution 4.1 -- to be released in a couple of weeks -- but be advised that b2evo 4.1 will be released as a beta whereas 4.0.5 is released as a stable version.

We will point more specifically to the issue once everyone now warned has been given a chance to upgrade either to v 4.0.5-stable or v 4.1-beta.

Note: the threat level for this issue is considred Moderate (2/5), but still, we want to give you time to upgrade before letting the bad guys know exactly where to look.

6 comments

Comment from: Keith [Visitor]
KeithIt's unfortunate that you guys didn't give the heads up to users on the importance sooner. Since it was done silently without the slightest indication of any changes, I assumed it just contained minor changes, not an important security update.
08/27/11 @ 20:14
Comment from: Hypocrite [Visitor]
HypocriteThe upgrade from 4.0.4 to 4.0.5 is not possible with the latest release.

After running the upgrade script, the version of b2evolution is still 4.0.4.
08/29/11 @ 18:18
Sebasti¨˘n LalauretteWell, it's good news that a new version is coming anyway. I'll be upgrading as soon as possible. Keep up the good work!
08/30/11 @ 18:20
Comment from: Francois Planque [Member] Email
Hypocrite: you probably haven't uploaded all files from the new version.
08/31/11 @ 02:23
Comment from: Hypocrite [Visitor]
HypocriteThanks. Seems like there really were some files missing even though I double checked.

The thing that confused was the _version.php file in install which says:
$current_version = 2; // 4.0.4
08/31/11 @ 08:52
Comment from: Francois Planque [Member] Email
Don't worry about that file, it's experimental ;)
09/11/11 @ 17:15

Search news