Tuesday, 11 November 2008 10:03
A bug/security fix has just been released for Joomla. Grab it while it's hot. This fixes the issue first reported on my post 1.5.7 Security Issue?, which led to a rift between Joomla and JoomlaTools. Full details after the break:
Security
* Two moderate-level security issues were fixed in this release:
o Default filtering for content
o Filtering for Web Link descriptions
For additional information, visit the Joomla Security Center.
Components
* Articles: Remove brackets around Last Updated date and time, Start Publishing date corrections for other than UTC 00:00, hit counts correct for Articles, adding a space after a cloaked email address
* E-mail addresses: Correctly cloaked when presented in Section and Category descriptions
* Categories: Edit icon correctly shows for Articles without Title links, Print icon correct now on first page for Blog Layout
*
Sections: Plural and singular form correction, Category link properly ended, Router changes reverted to version 1.5.6 so Article ID does not append to the Article slug
* Frontpage: Article assignment correction, corrected number of Links
* Contacts: Image display correction when Image Directory is configured
* RSS Feed: Corrected spelling of Category in Category feed
* User: Added isInternal checking on referer values
* Weblinks: Language strings
Modules
*
Feed: Target attribute validation, language string correction
* Login: ItemID is preserved on redirect
* Menu: Changing Menu Link Type now functions properly, Section Language string, Article Reset button working
* Related Items: Keyword matching functions correctly and filters characters appropriately
* Stats: Corrected Time
* Sections: No authorization parameter works correctly
* Search: Form validates correctly for Transitional xHTML
Legacy
* Return statement added for Legacy Menu Check
Templates
* Beez: Lengthened E-mail Content Popup, Search button now works when pressed, password reset works correctly, corrections to Beez HTML folders, User details page corrected
* JA_Purity: Added missing language strings
Administrator
* Console: Added "Welcome to Joomla!" information and Joomla Security RSS feeds to Administrator Console
* Installation: Proper deletion of component directories, default entries for Templates and Languages are now correct for uninstall
* Media Manager: Changed default for new sites to disable Flash multi-file uploader due to incompatibility with Flash 10
* Installation: Remove confusing error message about language files for extension installations, Administrator Modules now correctly uninstall INI files
* Sample data: Updated news feeds to point to free software community sites, extensive corrections and updates to sample content
System
* API: JFolder::files and JFolder::folders corrections for Search, missing Method added to JRecordSet, Database Class correctly quotes names not using dot notation, JTableUser matches using the correct number of fields
* Cache: Correct undefined variable in Cache Class
* Language file: Corrected wording, correct installation of PDF fonts independent of language choices, several language string corrections in en-GB.ini
* Menu: Performance improvements for sites with many menu items
* Users: Temporary Users are now able to logout, secure protocol can now be used when editing account details
* Added PHP 4 compatibility for isInternal checking
© (c) 2009 - 2010 Joomla Podcast