b2evolution b2evolution

  • Sign in
  • Sign up
  • About
  • Downloads
  • Hosting
  • Docs
  • Support
  • Sign in
  • Sign up
  • About
  • News
 
  • « Server switching...
  • Security Alert: import-mt.php »

b2evo 1.8.6 AND 1.9.1 released!

Posted by fplanque on Dec 02, 2006 in New releases, Security info

Only December the 2nd and we already have 2 new releases this month! It may seem as we can't get enough releases out the door. But these ones are for your security, so...

It is extremely strongly advised you upgrade!

Download here!

These releases patch the security issue discovered this week in 1.x releases. (If you are running version 0.9.1 or 0.9.2 you are not affected, but it would still be a good idea to upgrade.)

Those versions are codenamed after Anne & Chris who were the first two users reporting the issue. Thanks to both of you as well as to all other users who have helped identifying and fixing this issue in such a short delay.

These versions also include additional security measures, just in case. Sort of having two locks on your door instead of one.

Bonus in version 1.8.6 "Anne": Yearly archives are back. You can display all posts for 2005 with your-blog-url?m=2005

Bonus in version 1.9.1-beta "Chris": a few little bug fixes that make this version less of a beta than 1.9.0 ;)

20 comments

Comment from: balupton

balupton

Cool, just when I downloaded and installed 1.8.5 ;) Anyway are these gonna hit the download page any time soon ;) Also, maybe all the affected releases of the security issue, should be marked as insecure or have some horrible title in the downloads page so people don’t want to download them. As always, thanks :-)
- Balupton

2006-12-02 @ 21:24

Comment from: fplanque

Oops. Downloads page updated. Sorry.

2006-12-02 @ 21:41

Comment from: John

John

I assume that the security issue is fixed by the new import-mt.php file.
Is there a file difference report between 1.9.0 and 1.9.1 or is another full install recommended for the remaining few little bug fixes?

2006-12-02 @ 22:33

Comment from: fplanque

No there is no diff. But you don’t need to do a “full install", you only need to replace the files. The database doesn’t change.

2006-12-02 @ 23:05

Comment from: John

John

Thanks for that Francois

2006-12-02 @ 23:08

Comment from: Joachim

Joachim

No there is no diff. But you don’t need to do a “full install", you only need to replace the files. The database doesn’t change.

Must I upload alle files of Version 1.9.1? My Blog runs actually with version 1.8.

2006-12-03 @ 06:49

Comment from: DontheCat

DontheCat

The link from “Anne” is broken or dead. The link to the SourceForge D/L for Anne also goes to the 1.9.1 download page.

Pls check. Thanks

2006-12-03 @ 09:57

Comment from: Derek

Derek

This is real good news, Thanks very much Francois et al

2006-12-03 @ 10:47

Comment from: Derek

Derek

In fact I am really glad to see version 1.9.x out as well as plugins for WYSIWYG editor without losing the multi page and other features. In fact I hadn’t noticed that new themes(skins) and plugins… I’m on my way to give it a test..

Just one feature for the future… Adding categories on the fly. Though its probably gonna make b2evo include more javascript, I think that it will make content management and editing much easier.(Yeh I know that I am asking for probably too much)

A very big thanks to the developers

2006-12-03 @ 13:46

Comment from: fplanque

If you are running 1.8.5 and you just want to replace the files, you need to use the 1.8.6 files, not 1.9.1.

If you are running 1.9.0 and you just want to replace the files, you need to use the 1.9.1 files.

The download page on sourceforge lets you download any version. You just need to scroll down the page a little to get to the older versions.

2006-12-03 @ 14:12

Comment from: Nelson

Nelson

So from 1.85 to 1.86, All I do is overwrite the files? All of them?

2006-12-11 @ 09:55

Comment from: fplanque

You overwrite all the files, except those in the /conf directory.

If you overwrite /conf, you have to make sure you have properly configured the new /conf files.

2006-12-11 @ 13:37

Comment from: Neil Cowley

Neil Cowley

Glad to hear it, I’ll look forward to the security fixes - thanks for the great work.

2006-12-16 @ 13:47

Comment from: vinod rawat

vinod rawat

thanks for b2evolution software - just downloaded 1.8.6

nice simple but elegant way to blog :)

best wishes & regards

thanks

vinod

2006-12-19 @ 10:20

Comment from: zviane

zviane

Hi, I’m running on an old version (0.9.0.12) and I would like to upgrade with the new version, but I just can’t overwirte the files, will I loose all my data?

2006-12-20 @ 22:42

Comment from: fplanque

Please read the instructions on the Download page.

2006-12-20 @ 22:54

Comment from: neal

neal

Is this just a simple file replace if I’m going from 1.8.1 to 1.8.6? Also, will this upgrade fix the disappearing scroll bar when the users are writing a comment using IE? (I note that the scroll bar disappeared in this text box, but I don’t know what version of b2e the site is running)

2007-01-18 @ 15:08

Comment from: Charlie T

Charlie T

Just updated and it’s looking good so far. I can never get over how stressful it is to do the update though. Something always seems to go wrong. (It’s always user error of course:)

Thanks Francois: you’re a star.

2007-01-19 @ 01:50

Comment from: Nate

Nate

More about the /conf files and upgrading…I believe the only /conf files that should not be overwritten are _basic_config.php and _config.php. Those contain your database info and your blog settings. Please correct me if this is incorrect.

But the other /conf files probably *should* be overwritten. For example, if you don’t overwrite the _application.php file then your blog will display the wrong version of b2e on your login page and backoffice. That could get confusing later on when you want to upgrade and you need to know what version you’re using.

I’m no expert, and maybe the _stats.php page shouldn’t be touched either? Maybe others? But I thought I’d raise the issue here. :-)

2007-01-19 @ 19:54

Comment from: fplanque

The conf files should not be overwritten. This does not mean they should not be updated either.

Any file that you haven’t updated yourself can be safely overwritten. The other ones should be carefully updated.

In a *basic* install, the one and only file that needs to be taken care of in _basic_config.php .

2007-01-21 @ 18:47

b2evolution News

  • Home
  • Latest comments

Search

Categories

  • All
  • New releases
    • Press releases
  • Community
  • b2evolution.net
  • Development
    • New features
    • Technology
    • Security info
    • Translations
  • The Webmaster's Blog

Archives

  • July 2024 (1)
  • March 2022 (1)
  • September 2020 (1)
  • January 2020 (1)
  • May 2019 (1)
  • March 2019 (2)
  • September 2018 (1)
  • May 2018 (1)
  • September 2017 (1)
  • March 2017 (1)
  • September 2016 (1)
  • March 2016 (1)
  • More...

XML Feeds

  • RSS 2.0: Posts
  • Atom: Posts
What is RSS?

About b2evolution

  • What is it?
  • Features
  • Getting Started
  • Screenshots
  • Online demo
  • Testimonials
  • Design philosophy
  • Free & open source
  • Terms of service

Downloads

  • Latest releases
  • Skins
  • Plugins
  • Language packs

About us

  • About us
  • Contact

Webhosting Guide

  • Web hosting blog
  • Best web hosting
  • Cheap web hosting
  • Green web hosting
  • Hosting with SSH
  • VPS hosting
  • Dedicated servers
  • Reseller hosting
  • Int'l: UK / France

Docs & Support

  • Online manual
  • Forums
  • Hire a pro !

Other

  • Adsense
  • Press room
  • Privacy policy

Stay in touch

  • GitHub
  • Twitter
  • Facebook
  • LinkedIn
  • News blog
  • RSS feed
  • Atom feed

Founded & Maintained by François Planque