CodeIgniter 한국사용자포럼 BETA
빠르고, 유연한 PHP Framework!

CI 뉴스


1.7.2 보안패치      
웅파 1 3,264 0 0 2010-07-14 16:50:41

CodeIgniter 1.7.2 Security Patch

A fix has been implemented for a security flaw in CodeIgniter 1.7.2.  You may obtain the fix either by downloading a fresh copy of CodeIgniter, or downloading this standalone patch.  All applications using the File Upload class should install the patch to ensure that their application is not subject to a vulnerability.

While fixing this bug, we took the opportunity to make an improvement to the Upload class’s ability to allow a file name override.  Previously, you needed to do a little dance in your controller to remove the extension from the file name if you were starting from user input; neither could you override the file extension.  Now when using the “file_name” config override, you will supply the full file name, including the extension, truly overriding the file name provided by the client user agent.

After applying the patch, you will need to adjust your code accordingly if you are using the ‘file_name’ override in the Upload class.  While we are not in the habit of making code changes within a version that has the potential to break compatibility, this change was necessary as part of the security fix.

If you are using CodeIgniter from the Mercurial repository at BitBucket, please make sure you pull the latest files.  Version 1.7.2 has been branched and retagged to include this fix.

We’d like to thank CodeIgniter user alexaholic for bringing this to our attention.  Security is always a top priority for our products, and we make ourselves available to be directly contacted for any security concerns.

Posted by Derek Jones on July 12, 2010

업로그 클래스 부분 패치입니다.
기존 사용자는
standalone patch 을 다운받아서 덮어 쓰면 됩니다.

  목록  

번호 제   목 글쓴이 날짜 조회 추천수
20 ci 2.1.0 한글매뉴얼 doc 파일 [15] 웅파 2011-12-16 2604 2
18 2.1.0 버전 [1] 웅파 2011-11-15 3919 0
13 codeigniter 2.0.3 버전 올라왔네요. [4] 웅파 2011-08-22 1949 0
11 2.0.1 일본어 매뉴얼 번역판 [1] 웅파 2011-04-04 2024 0
10 2.0.1에서 바뀐 점 [0] 웅파 2011-04-04 2945 0
8 CodeIgniter 2.0.0 Released (.. [1] KangMin 2011-01-31 3855 0
6 1.7.2 보안패치 [1] 웅파 2010-07-14 3264 0
3 1.7.2 버전 다운로드 [2] 웅파 2010-05-28 3066 0
2 CodeIgniter v1.7.2 Released [0] jois 2009-09-12 3329 0
1 CodeIgniter 1.7.1 Released [0] 웅파 2009-07-19 2524 0