Koozali.org: home of the SME Server

Horde 3.0.9 Security issue

simon101

Horde 3.0.9 Security issue
« on: April 21, 2006, 02:32:18 PM »
Can anyone help me with a Horde security issue?
I have a server running for 2 weeks now and it has allready been tainted bij a worm!
Horde.org has a post on this:
________________________________________________________________
March 28th, 2006.
The Horde Team has released a critical security fix for the Horde Application Framework versions 3.0 and above. Version 2.x and earlier releases are not affected. The fixed Horde versions 3.0.10 and 3.1.1 are available. We strongly encourage every user to update to the new versions immediately.
________________________________________________________________

Can sombody make an update for Horde 3.0.9? (Maybe mr Bennett?)

Offline mrjhb3

  • *
  • 1,188
  • +0/-0
    • John Bennett Services
Re: Horde 3.0.9 Security issue
« Reply #1 on: April 23, 2006, 08:33:02 AM »
Quote from: "simon101"
Can anyone help me with a Horde security issue?
I have a server running for 2 weeks now and it has allready been tainted bij a worm!
Horde.org has a post on this:
________________________________________________________________
March 28th, 2006.
The Horde Team has released a critical security fix for the Horde Application Framework versions 3.0 and above. Version 2.x and earlier releases are not affected. The fixed Horde versions 3.0.10 and 3.1.1 are available. We strongly encourage every user to update to the new versions immediately.
________________________________________________________________

Can sombody make an update for Horde 3.0.9? (Maybe mr Bennett?)


Well, OK.  As soon as the mirrors sync, you can download and run the current install_horde30.sh file.

changes:
# April 24, 2006:       Added Horde 3.0.10 and gollem 1.0.2
......

simon101

Thanx
« Reply #2 on: April 23, 2006, 01:29:49 PM »
Thanx for the quick response!
Only, the Tar file that is on this directory has got a file size of 0 bytes..
http://mirror.contribs.org/smeserver/contribs//jbennett/horde30/

Friendly Greetings

Simon

Offline mrjhb3

  • *
  • 1,188
  • +0/-0
    • John Bennett Services
Re: Thanx
« Reply #3 on: April 23, 2006, 03:56:14 PM »
Quote from: "simon101"
Thanx for the quick response!
Only, the Tar file that is on this directory has got a file size of 0 bytes..
http://mirror.contribs.org/smeserver/contribs//jbennett/horde30/

Friendly Greetings

Simon


Must have been a bad sync.  1 of the 4 files I uploaded were correct.  I'll just re-upload them again.

JB
......

simon101

Downloaded again and it works!
« Reply #4 on: April 23, 2006, 08:04:56 PM »
Thanks again for the quick response.
Just to let you know, I've installed it and it works!

Offline wellsi

  • *
  • 475
  • +0/-0
    • http://www.wellsi.com
Horde 3.0.9 Security issue
« Reply #5 on: May 01, 2006, 12:14:29 PM »
Anyone using SME 6.x who has upgraded Webmail to use Horde 3 should read the news article http://no.longer.valid/news/article.php?storyid=103

Take action immediately and disable Webmail, then do one of
    Upgrade to SME Server 7 RC2
    Apply the Horde 3.0.10 updates detailed in this thread above.

Thank You to John Bennett for making this Horde 3.0.10 update available.

Ian Wells
............