Skip to content

ElkArte 1.0.8 security and bug fix update

Compare
Choose a tag to compare
@emanuele45 emanuele45 released this 31 Jul 14:23
· 4805 commits to master since this release

Today, we are pleased to release ElkArte 1.0.8. This release fixes a security issue related to the unserialize php function (related to CVE-2016-5726 and CVE-2016-5727). The release fixes also some bugs that were found or reported since the release of 1.0.7. As this is a security release, it is extremely important to update for everyone running ElkArte.
If you are running a version prior to 1.0.7, the recommended procedure is install any update since 1.0.7 and then the 1.0.8 patch.

Apart from fixing the security issue, some notable updates in 1.0.8 include:

  • stopped using INET_ATON and INET_NTOA to improve IPv6 handling,
  • fixed YouTube embedding URLs to avoid problems in certain conditions,
  • fixed editing of polls with expiration date,

This release follows our semantic version (MAJOR.MINOR.PATCH), meaning that third-point (x.x.X) releases should contain backwards-compatible bug fixes and enhancements, so for the most part you will not find new features in this release. Major new features will be reserved for second point versions (x.X.x).

Refer to the release notes on the forum for a complete list of updates.