<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>pingVision</title>
  <subtitle>Interactive Design + Development for Drupal websites</subtitle>
  <link rel="alternate" type="text/html" href="http://pingv.com/blog/laura/200508/drupal-4-6-3-update"/>
  <link rel="self" type="application/atom+xml" href="http://pingv.com/node/3582/atom/feed"/>
  <id>http://pingv.com/node/3582/atom/feed</id>
  <updated>2005-08-15T02:10:59-05:00</updated>
  <entry>
    <title>Drupal 4.6.3 update</title>
    <link rel="alternate" type="text/html" href="http://pingv.com/blog/laura/200508/drupal-4-6-3-update" />
    <id>http://pingv.com/blog/laura/200508/drupal-4-6-3-update</id>
    <published>2005-08-15T00:41:15-05:00</published>
    <updated>2005-08-15T02:10:59-05:00</updated>
    <author>
      <name>Laura</name>
    </author>
    <category term="website" />
    <category term="Announcement" />
    <category term="Drupal" />
    <content type="html"><![CDATA[<p>
We just updated pingVision to <a href="http://drupal.org/project">Drupal 4.6.3</a>, a security-fix that addresses another xmp-rpc breach:
</p>
<blockquote><p>
The Drupal project has released version 4.6.3 of its open-source content management platform. Drupal 4.6.3 is a maintenance release that fixes problems reported using the bug tracking system. Drupal 4.6.3 also <strong>fixes a </strong><strong><em>new</em></strong><strong> security vulnerability</strong> in the third-party XML-RPC library that Drupal ships with. Since the same bug is also present in the Drupal 4.5 series, Drupal 4.5.5 is released as well. If you cannot upgrade at once, we <strong>strongly suggest</strong> that you remove the xmlrpc.php file from your Drupal installation's root directory. The xmlrpc.php file is used only for Drupal to receive XML-RPC calls.
</p></blockquote>
<p>
Anyone running Drupal should update immediately. The download tarball is <a href="http://drupal.org/files/projects/drupal-4.6.3.tar.gz">here</a>. Also, if you are running Drupal 4.5.x, there is an update for you <a href="http://drupal.org/project/Drupal%20project/4.5">here</a>.
</p>
<p>
If you cannot do the update right away, or do not know how, here is the short-term fix:
</p>
<blockquote><p>
If you cannot upgrade immediately, <strong>you can secure your site by removing  the XML-RPC server: simply remove the file "xmlrpc.php" in the root of  your Drupal directory.</strong>
</p></blockquote>
<p>
This will prevent you from using a program like ecto to post to your site, but it will protect your site from the newly discovered security vulnerability.
</p>
<p>
---
</p>
<p>
<strong>Update:</strong> If you are running CivicSpace, a security advisory is <a href="http://civicspacelabs.org/home/node/13757">here</a>.
</p>
    ]]></content>
  </entry>
</feed>
