[web2py] Re: EMERGENCY! Major security hole in 1.74.8 fixed in 1.74.9.

2010-02-01 Thread mdipierro
I am trying to find out. I know it is not in 1.74.1. On Feb 1, 3:23 pm, Timothy Farrell tfarr...@swgen.com wrote: Which version was the bug introduced in?  My production environment runs an older version than my dev environment. On 2/1/2010 1:56 PM, mdipierro wrote: User sveinh has

Re: [web2py] Re: EMERGENCY! Major security hole in 1.74.8 fixed in 1.74.9.

2010-02-01 Thread Timothy Farrell
If you know where it is in the code you can always: bzr blame filename That will give you the revision number. From that you should be able to determine the date and then version number. On 2/1/2010 3:36 PM, mdipierro wrote: I am trying to find out. I know it is not in 1.74.1. On Feb 1,

[web2py] Re: EMERGENCY! Major security hole in 1.74.8 fixed in 1.74.9.

2010-02-01 Thread mdipierro
I runs some tests. This affects 1.74.8 and 1.74.7 ONLY. It does not affect previous versions. Massimo -- You received this message because you are subscribed to the Google Groups web2py-users group. To post to this group, send email to web...@googlegroups.com. To unsubscribe from this group,

[web2py] Re: EMERGENCY! Major security hole in 1.74.8 fixed in 1.74.9.

2010-02-01 Thread mr.freeze
Can you give us details on the exploit? I would like to run my own tests. If you don't want to disclose it publicly, can you send an email? On Feb 1, 3:42 pm, mdipierro mdipie...@cs.depaul.edu wrote: I runs some tests. This affects 1.74.8 and 1.74.7 ONLY. It does not affect previous versions.