<?xml version="1.0"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Transition Technology: Ticket #693: Module security updates: February 2014</title>
    <link>http://localhost:8080/trac/ticket/693</link>
    <description>&lt;p&gt;
Hi Paul
&lt;/p&gt;
&lt;p&gt;
You'll see from this ticket; &lt;a class="ext-link" href="https://trac.transitionnetwork.org/trac/ticket/582"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://trac.transitionnetwork.org/trac/ticket/582&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
That the 6.29 &amp;gt; 6.30 core update patches bugs that don't affect us.
&lt;/p&gt;
&lt;p&gt;
However some recent security updates for modules have been released recently; &lt;a class="ext-link" href="https://www.transitionnetwork.org/admin/reports/updates"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/admin/reports/updates&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
Affected modules are;
&lt;/p&gt;
&lt;p&gt;
ctools;
&lt;a class="ext-link" href="https://drupal.org/node/2194547"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://drupal.org/node/2194547&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
filefield
&lt;a class="ext-link" href="https://drupal.org/node/2194103"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://drupal.org/node/2194103&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
image resizer
&lt;a class="ext-link" href="https://drupal.org/node/2194063"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://drupal.org/node/2194063&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
mimemail
&lt;a class="ext-link" href="https://drupal.org/node/2205939"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://drupal.org/node/2205939&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
webform
&lt;a class="ext-link" href="https://drupal.org/node/2194181"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://drupal.org/node/2194181&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
The ctools &amp;amp; webform ones look like ones we should get on top of soonish, the mimemail one looks like it could be a pain.
&lt;/p&gt;
&lt;p&gt;
Are you up for testing the updates on your local box? We can then figure out how to roll them out to the live site.
&lt;/p&gt;
&lt;p&gt;
Thanks
&lt;/p&gt;
&lt;p&gt;
Sam
&lt;/p&gt;
</description>
    <language>en-us</language>
    <image>
      <title>Transition Technology</title>
      <url>/trac/chrome/site/TransitionNetwork-Logo-Web-Small.jpg</url>
      <link>http://localhost:8080/trac/ticket/693</link>
    </image>
    <generator>Trac 0.12.5</generator>
    <item>
      
        <dc:creator>sam</dc:creator>

      <pubDate>Thu, 27 Feb 2014 16:20:58 GMT</pubDate>
      <title>description changed</title>
      <link>http://localhost:8080/trac/ticket/693#comment:1</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/693#comment:1</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;description&lt;/strong&gt;
              modified (&lt;a href="/trac/ticket/693?action=diff&amp;amp;version=1"&gt;diff&lt;/a&gt;)
            &lt;/li&gt;
          &lt;/ul&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>paul</dc:creator>

      <pubDate>Fri, 28 Feb 2014 17:05:16 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/693#comment:2</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/693#comment:2</guid>
      <description>
        &lt;p&gt;
Hi, Sam,
&lt;/p&gt;
&lt;p&gt;
I'll test these updates over the weekend and update the ticket on Monday
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>paul</dc:creator>

      <pubDate>Sat, 01 Mar 2014 15:07:35 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/693#comment:3</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/693#comment:3</guid>
      <description>
        &lt;p&gt;
Update.
&lt;/p&gt;
&lt;p&gt;
I'll test these Monday afternoon and update the ticket. Hopefully we can update the server before then end of Monday.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>paul</dc:creator>

      <pubDate>Mon, 03 Mar 2014 16:51:31 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/693#comment:4</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/693#comment:4</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.75&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.75&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
I have put all the code under git version control on my localhost so that I can always go back in time :)
&lt;/p&gt;
&lt;p&gt;
Replies given inline ..
&lt;/p&gt;
&lt;p&gt;
Replying to &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/693" title="maintenance: Module security updates: February 2014 (closed: fixed)"&gt;sam&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
Hi Paul
&lt;/p&gt;
&lt;p&gt;
You'll see from this ticket; &lt;a class="ext-link" href="https://trac.transitionnetwork.org/trac/ticket/582"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://trac.transitionnetwork.org/trac/ticket/582&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
That the 6.29 &amp;gt; 6.30 core update patches bugs that don't affect us.
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
I haven't looked at that ticket, as I noticed that we are already on 6.30
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
However some recent security updates for modules have been released recently; &lt;a class="ext-link" href="https://www.transitionnetwork.org/admin/reports/updates"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/admin/reports/updates&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
Affected modules are;
&lt;/p&gt;
&lt;p&gt;
ctools;
&lt;a class="ext-link" href="https://drupal.org/node/2194547"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://drupal.org/node/2194547&lt;/a&gt;
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
The new release also provides a patch for cleanstring.inc, that overrides the patch that was applied to the previous version.
&lt;/p&gt;
&lt;p&gt;
After switching to the new version of ctools, and clicking around, I couldn't see the problems:
&lt;/p&gt;
&lt;p&gt;
Constant CTOOLS_PREG_CLASS_ALNUM in includes/cleanstring.inc contains \x{d800}- which is ill-formed code point. PHP issues this warning:
&lt;/p&gt;
&lt;p&gt;
Warning: preg_match(): Compilation failed: disallowed Unicode code point (&amp;gt;= 0xd800 &amp;amp;&amp;amp; &amp;lt;= 0xdfff) at offset 1811 in ctools_cleanstring() (line 157 of /srv/http/XXXX/www/sites/all/modules/contrib/ctools/includes/cleanstring.inc)
&lt;/p&gt;
&lt;p&gt;
reported  in watchdog. I have updated the makefile on my localhost.
&lt;/p&gt;
&lt;p&gt;
Here are the changes for includes/cleanstring.inc that come with the latest version of ctools:
&lt;/p&gt;
&lt;p&gt;
diff --git a/sites/all/modules/contrib/ctools/includes/cleanstring.inc b/sites/all/modules/contrib/ctools/includes/cleanstring.inc
index 324d070..027def1 100644
--- a/sites/all/modules/contrib/ctools/includes/cleanstring.inc
+++ b/sites/all/modules/contrib/ctools/includes/cleanstring.inc
@@ -56,11 +56,12 @@ define('CTOOLS_PREG_CLASS_ALNUM',
&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;
'\x&lt;a class="report" href="http://localhost:8080/trac/report/2108"&gt;{2108}&lt;/a&gt;\x&lt;a class="report" href="http://localhost:8080/trac/report/2109"&gt;{2109}&lt;/a&gt;\x&lt;a class="report" href="http://localhost:8080/trac/report/2114"&gt;{2114}&lt;/a&gt;\x&lt;a class="report" href="http://localhost:8080/trac/report/2116"&gt;{2116}&lt;/a&gt;-\x&lt;a class="report" href="http://localhost:8080/trac/report/2118"&gt;{2118}&lt;/a&gt;\x{211e}-\x&lt;a class="report" href="http://localhost:8080/trac/report/2123"&gt;{2123}&lt;/a&gt;\x&lt;a class="report" href="http://localhost:8080/trac/report/2125"&gt;{2125}&lt;/a&gt;\x&lt;a class="report" href="http://localhost:8080/trac/report/2127"&gt;{2127}&lt;/a&gt;'.
'\x&lt;a class="report" href="http://localhost:8080/trac/report/2129"&gt;{2129}&lt;/a&gt;\x{212e}\x&lt;a class="report" href="http://localhost:8080/trac/report/2132"&gt;{2132}&lt;/a&gt;\x{213a}\x{213b}\x&lt;a class="report" href="http://localhost:8080/trac/report/2140"&gt;{2140}&lt;/a&gt;-\x&lt;a class="report" href="http://localhost:8080/trac/report/2144"&gt;{2144}&lt;/a&gt;\x{214a}-\x{2b13}'.
'\x{2ce5}-\x{2cff}\x{2d6f}\x{2e00}-\x&lt;a class="report" href="http://localhost:8080/trac/report/3005"&gt;{3005}&lt;/a&gt;\x&lt;a class="report" href="http://localhost:8080/trac/report/3007"&gt;{3007}&lt;/a&gt;-\x{303b}\x{303d}-\x{303f}'.
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
-'\x&lt;a class="report" href="http://localhost:8080/trac/report/3099"&gt;{3099}&lt;/a&gt;-\x{309e}\x{30a0}\x{30fb}\x{30fd}\x{30fe}\x&lt;a class="report" href="http://localhost:8080/trac/report/3190"&gt;{3190}&lt;/a&gt;-\x{319f}\x{31c0}-'.
-'\x{31cf}\x&lt;a class="report" href="http://localhost:8080/trac/report/3200"&gt;{3200}&lt;/a&gt;-\x{33ff}\x{4dc0}-\x{4dff}\x{a015}\x{a490}-\x{a716}\x{a802}'.
-'\x{a806}\x{a80b}\x{a823}-\x{a82b}\x{e000}-\x{f8ff}\x{fb1e}\x{fb29}\x{fd3e}'.
-'\x{fd3f}\x{fdfc}-\x{fe6b}\x{feff}-\x{ff0f}\x{ff1a}-\x{ff20}\x{ff3b}-\x{ff40}'.
-'\x{ff5b}-\x{ff65}\x{ff70}\x{ff9e}\x{ff9f}\x{ffe0}-\x{fffd}');
+'\x&lt;a class="report" href="http://localhost:8080/trac/report/3099"&gt;{3099}&lt;/a&gt;-\x{309e}\x{30a0}\x{30fb}-\x{30fe}\x&lt;a class="report" href="http://localhost:8080/trac/report/3190"&gt;{3190}&lt;/a&gt;-\x{319f}\x{31c0}-\x{31cf}'.
+'\x&lt;a class="report" href="http://localhost:8080/trac/report/3200"&gt;{3200}&lt;/a&gt;-\x{33ff}\x{4dc0}-\x{4dff}\x{a015}\x{a490}-\x{a716}\x{a802}\x{a806}'.
+'\x{a80b}\x{a823}-\x{a82b}\x{e000}-\x{f8ff}\x{fb1e}\x{fb29}\x{fd3e}\x{fd3f}'.
+'\x{fdfc}-\x{fe6b}\x{feff}-\x{ff0f}\x{ff1a}-\x{ff20}\x{ff3b}-\x{ff40}\x{ff5b}-'.
+'\x{ff65}\x{ff70}\x{ff9e}\x{ff9f}\x{ffe0}-\x{fffd}');
+
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
filefield
&lt;a class="ext-link" href="https://drupal.org/node/2194103"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://drupal.org/node/2194103&lt;/a&gt;
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
Already patched.
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
image resizer
&lt;a class="ext-link" href="https://drupal.org/node/2194063"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://drupal.org/node/2194063&lt;/a&gt;
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
Already patched.
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
mimemail
&lt;a class="ext-link" href="https://drupal.org/node/2205939"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://drupal.org/node/2205939&lt;/a&gt;
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
Come back to this one later, as it sounds tricky.
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
webform
&lt;a class="ext-link" href="https://drupal.org/node/2194181"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://drupal.org/node/2194181&lt;/a&gt;
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
Already patched.
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
The ctools &amp;amp; webform ones look like ones we should get on top of soonish, the mimemail one looks like it could be a pain.
&lt;/p&gt;
&lt;p&gt;
Are you up for testing the updates on your local box? We can then figure out how to roll them out to the live site.
&lt;/p&gt;
&lt;p&gt;
Thanks
&lt;/p&gt;
&lt;p&gt;
Sam
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
I think I need to look again at the wiki pages to see how to get the latest version of the makefile on the server, and the process of staging and pushing changes through to production.
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;/blockquote&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>sam</dc:creator>

      <pubDate>Tue, 04 Mar 2014 17:23:00 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/693#comment:5</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/693#comment:5</guid>
      <description>
        &lt;p&gt;
Hi Paul
&lt;/p&gt;
&lt;p&gt;
Thanks for this.
&lt;/p&gt;
&lt;p&gt;
I was going to have a go at building a stg.tn.org on Ageir using your new Makefile to do a bit of testing.
&lt;/p&gt;
&lt;p&gt;
Could you stick it on your github and I'll have a go?
&lt;/p&gt;
&lt;p&gt;
&lt;a class="ext-link" href="https://github.com/paulbooker/transitionnetwork.org-d6.profile"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://github.com/paulbooker/transitionnetwork.org-d6.profile&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
Thanks
&lt;/p&gt;
&lt;p&gt;
Sam
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>paul</dc:creator>

      <pubDate>Wed, 05 Mar 2014 14:24:07 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/693#comment:6</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/693#comment:6</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.25&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;0.75&lt;/em&gt; to &lt;em&gt;1.0&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Hi Sam,
&lt;/p&gt;
&lt;p&gt;
Pushed the changes to Github.
&lt;/p&gt;
&lt;p&gt;
Would you document what you do or advise what part of the wiki you followed.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>paul</dc:creator>

      <pubDate>Wed, 05 Mar 2014 14:26:16 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/693#comment:7</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/693#comment:7</guid>
      <description>
        &lt;p&gt;
If you have any problems building a stage environment, let me know, and I'll see if I can help.
&lt;/p&gt;
&lt;p&gt;
Best, Paul
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>ed</dc:creator>

      <pubDate>Wed, 16 Apr 2014 11:07:14 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/693#comment:8</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/693#comment:8</guid>
      <description>
        &lt;p&gt;
has this moved on to &lt;a class="reopened ticket" href="http://localhost:8080/trac/ticket/712" title="maintenance: Create a new stgX.transitionnetwork.org site (reopened)"&gt;#712&lt;/a&gt;? it's gone quiet.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>paul</dc:creator>

      <pubDate>Wed, 30 Apr 2014 18:04:59 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/693#comment:9</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/693#comment:9</guid>
      <description>
        &lt;p&gt;
I would say it has.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>sam</dc:creator>

      <pubDate>Thu, 15 May 2014 09:00:11 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/693#comment:10</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/693#comment:10</guid>
      <description>
        &lt;p&gt;
Resolved via &lt;a class="ext-link" href="https://trac.transitionnetwork.org/trac/ticket/712"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://trac.transitionnetwork.org/trac/ticket/712&lt;/a&gt;
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>sam</dc:creator>

      <pubDate>Thu, 15 May 2014 09:00:36 GMT</pubDate>
      <title>status changed; resolution set</title>
      <link>http://localhost:8080/trac/ticket/693#comment:11</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/693#comment:11</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;status&lt;/strong&gt;
                changed from &lt;em&gt;new&lt;/em&gt; to &lt;em&gt;closed&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;resolution&lt;/strong&gt;
                set to &lt;em&gt;fixed&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
      </description>
      <category>Ticket</category>
    </item>
 </channel>
</rss>