?
avatar htmgarcia
htmgarcia
18 Jan 2017

Envato reported this vulnerability:
screen shot 2017-01-17 at 10 06 05 pm

Update to PHPMailer 5.2.22

Already reported from: https://developer.joomla.org/security-centre/668-20161205-phpmailer-security-advisory.html

Just posting here to make it a higher priority.

avatar htmgarcia htmgarcia - open - 18 Jan 2017
avatar joomla-cms-bot joomla-cms-bot - change - 18 Jan 2017
Labels Added: ?
avatar joomla-cms-bot joomla-cms-bot - labeled - 18 Jan 2017
avatar zero-24
zero-24 - comment - 18 Jan 2017

Hmm did you read the report from the JSST?
The Joomla Core is not affected by this issue and the next update is going to fix that see: https://github.com/joomla/joomla-cms/blob/staging/libraries/vendor/phpmailer/phpmailer/VERSION

Or do i miss something?

avatar mbabker
mbabker - comment - 18 Jan 2017

Or do i miss something?

Nope. Pretty normal "hey, these guys issued a security release, you should do something" issue report. Happens with most repos.

Closing though. No action required, core has already updated the library.

avatar mbabker mbabker - close - 18 Jan 2017
avatar mbabker mbabker - change - 18 Jan 2017
Status New Closed
Closed_Date 0000-00-00 00:00:00 2017-01-18 13:26:06
Closed_By mbabker
avatar htmgarcia
htmgarcia - comment - 18 Jan 2017

Thanks @zero-24!
I missed that. Checked 3.7.0 alpha1 and didn't saw that update.

@ot2sen thanks! That's a good point to consider.

@mbabker it will be included with Joomla 3.7.0?

avatar mbabker
mbabker - comment - 18 Jan 2017

Alpha 1 was tagged before the PHPMailer vulnerabilities were disclosed/patched, kinda hard to include something from the future ?

avatar htmgarcia
htmgarcia - comment - 18 Jan 2017

@mbabker I value the time you take to answer my "silly" questions; however may you try to be a little humble when replying?

This part wasn't necessary.

kinda hard to include something from the future

Add a Comment

Login with GitHub to post a comment