| Page 1 of 2 | [ 13 posts ] | Go to page 1, 2 Next |
|
The YUI team released YUI 2.8.2 today, addressing a security issue present in YUI 2.4.0-2.8.1.
If you are a YUI 2 implementer, please review the security bulletin: http://yuilibrary.com/support/2.8.2/ You can use this forum if you have questions and we'll be happy to help answer them. |
|
the MD5 sums listed on the security bulletin webpage appear to be incorrect for YUI 2.5.0. the sums I got were:
MD5 (charts.swf) = dd337b66da67de5d94fb67dd40bd77f6 MD5 (uploader.swf) = aaefcfce0b41a4d3a2d4433441bc7736 could you verify if these are the correct values? |
Allen RabinovichYUI Developer
|
tonyquan wrote: the MD5 sums listed on the security bulletin webpage appear to be incorrect for YUI 2.5.0. the sums I got were: MD5 (charts.swf) = dd337b66da67de5d94fb67dd40bd77f6 MD5 (uploader.swf) = aaefcfce0b41a4d3a2d4433441bc7736 could you verify if these are the correct values? I just checked, and the values we have provided in the bulletin are correct. Are you sure your versions of the files haven't been rebuilt locally? If they have, chances are, small differences in the compiler version may have resulted in minute changes to the files, which of course results in a drastically different MD5. |
|
Allen, there still seems to be something wrong. Here's what I did:
downloaded these two files pointed to by the security bulletin webpage: http://yuilibrary.com/support/2.8.2/dro ... -2.5.0.zip http://yuilibrary.com/support/2.8.2/dro ... -2.5.0.zip unzip each zip file, yielding charts.swf and uploader.swf. ran md5 on the mac and got: MD5 (charts.swf) = dd337b66da67de5d94fb67dd40bd77f6 MD5 (uploader.swf) = aaefcfce0b41a4d3a2d4433441bc7736 could you double check? When I did this for the 2.7.0 and 2.8.1 files everything was fine. |
Matt ParkerYUI Contributor
|
Hi,
I think the md5's are of the old files that need replacing, not the replacements. I've put in a request to have both... Matt |
Mike HatfieldYUI Contributor
|
There are some problems with the YUI 2.8.2 release which seem in part to have been due to the global year update to 2010.
container.js, lines 4789 and 5048 get.js, line 549 yahoo.js, line 298 [comment only] yuiloader.js, lines 298 [comment only as above], lines 1864, 1865 (refer to v2.8.1 on yahooapis.com) Also (minor) none of the .css files have been updated to have a v2.8.2 header. Thanks, Mike |
|
Matt,
I've updated the security bulletin with old/new MD5 values for the files; thanks for the suggestion. -Eric |
|
Mike,
You're right; we executed a bad regex, and that damaged the 2.8.2 build. Here's what we've done: 1. The download now points to 2.8.2r1 -- a corrected build. 2. 2.8.2r1 is on the CDN. Sorry for the additional churn. -Eric |
|
Hi,
I've got a question regarding this update. Let's say I have set a far future Expires header on the affected flash files and so many people may have the affected files their browser cache, am I still vulnerable ? What can happen in this case ? In addition, where can I find some more infos on the security flaw itself ? http://yuilibrary.com/support/2.8.2/ gives instruction on how to update, but nothing what a remote attacker can do exactly. Regards |
|
hi,
is my site affected just by hosting the components or by implementing one of the affected components (charts/uploader/swfstore)? thanks, joerg |
| Page 1 of 2 | [ 13 posts ] | Go to page 1, 2 Next |
| You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum |
© 2006-2013 Yahoo! Inc. All rights reserved.
All code on this site is licensed under the BSD License unless stated otherwise.
About This Site · Security Contact Info
Powered by phpBB® Forum Software © phpBB Group