Security Release: Joomla! 1.5.9 Is Ready For Free Download

The PHP / MySQL based open source content management system, Joomla! was updated to version 1.5.9 [Vatani], after the recent release on November 10, 2008 of Joomla! 1.5.8 coded name Wohnaiki. This security release solves two security issues of high and respectively low severity: directory traversal and SSL session token disclosure which affected all of the Joomla! 1.5.x installations, including version 1.5.8.

The first exploit type, directory traversal, could allow to an attacker to display the directory trees existing on the web server. The second exploit deals with the possibility of getting the session token by an attacker in case of non-SSL requests performed for websites running as SSL (Transport Layer Security, formerly Secure Sockets Layer) only, while the entire data transfer is still safe.

The minimum requirements for Joomla!1.5.9 are the same as in the case of all other 1.5.x versions: PHP 4.3.10, MySQL 3.23, Apache 1.3 (with mod_mysql, mod_xml and mod_zlib enabled). Another supported web server as an alternative to Apache is Microsoft IIS 6.

In Joomla! 1.5.9 version, several bugs were solved in case of components, modules, plugins, templates, language, administrator and system, such as the invalid XHTML 1.0 Transitional issues for the Contact Form, Media Manager JavaScript errors, Tool Tip corrections, OpenID Transition and more.

The latest version of Joomla! content management system and framework can be downloaded from Downloadtube website. It is recommended to upgrade to the latest version in order to avoid possible problems caused by attackers and to improve the performances of your Joomla! based website.

http://www.downloadtube.com/blog/wp-content/plugins/sociofluid/images/digg_48.png http://www.downloadtube.com/blog/wp-content/plugins/sociofluid/images/reddit_48.png http://www.downloadtube.com/blog/wp-content/plugins/sociofluid/images/dzone_48.png http://www.downloadtube.com/blog/wp-content/plugins/sociofluid/images/stumbleupon_48.png http://www.downloadtube.com/blog/wp-content/plugins/sociofluid/images/delicious_48.png http://www.downloadtube.com/blog/wp-content/plugins/sociofluid/images/blinklist_48.png http://www.downloadtube.com/blog/wp-content/plugins/sociofluid/images/furl_48.png http://www.downloadtube.com/blog/wp-content/plugins/sociofluid/images/newsvine_48.png http://www.downloadtube.com/blog/wp-content/plugins/sociofluid/images/technorati_48.png http://www.downloadtube.com/blog/wp-content/plugins/sociofluid/images/magnolia_48.png http://www.downloadtube.com/blog/wp-content/plugins/sociofluid/images/google_48.png http://www.downloadtube.com/blog/wp-content/plugins/sociofluid/images/facebook_48.png http://www.downloadtube.com/blog/wp-content/plugins/sociofluid/images/yahoobuzz_48.png http://www.downloadtube.com/blog/wp-content/plugins/sociofluid/images/sphinn_48.png http://www.downloadtube.com/blog/wp-content/plugins/sociofluid/images/mixx_48.png http://www.downloadtube.com/blog/wp-content/plugins/sociofluid/images/twitter_48.png
Tags: , ,

Related Articles

One Response to “Security Release: Joomla! 1.5.9 Is Ready For Free Download”

  1. Web Developer Blog - Downloadtube.com » Blog Archive » Custom HTML Code Management In Joomla! Says:

    [...] Starting with version 1.5.8, as a security measure a default filtering rule for custom code content was implemented to prevent possible XSS attacks. As a consequence, if you are using certain HTML tags or JavaScript code into the published articles, the resulting browser output could not be always the expected result because of the default Blacklist filter. (related article: Security Release: Joomla! 1.5.9 Is Ready For Free Download) [...]

Leave a Reply