giovedì 23 settembre 2010

Rilasciato DotNetNuke 5.5.1

E' stato rilasciato oggi  DotNetNuke versione 5.5.1 con l'importante fix per la vulnerabilità segnalata nei giorni passati sui siti con ASP.NET.


Di seguito riporto il changelog:




Major Highlights

  • Added feature to detect if a site is not running the suggested customErrors configuration to mitigate the ASP.Net Padding Oracle Vulnerability.
  • Updated the default web.config to use the recommended customerrors settings to mitigate the ASP.Net Padding Oracle Vulnerability.
  • Fixed Sitemap Provider so it only returns one page when multiple languages are enabled and Content Localization is not enabled.
  • Fixed Telerik File Manager to make files stored using database folders visible to the user.
  • Fixed issue where module developers using custom aspx pages that inherit from basepage and use codeblocks get an exception
  • Fixed issue where the locale was not properly reflecting the querystring and the users browser or portal settings.
  • Fixed issue where users were not granted proper permissions for the Templates folder on install.
  • Fixed issue where missing objectqualifier would cause upgrade script to fail.
  • Updated the url parser to take port 443 and ssl into consideration. its no longer necessary to turn off human friendly or use-port number in web.config
  • Fixed behavior of Language detection when Content Localization is not enabled.
  • Updated update tab logic to take host tabs into consideration.
  • Fixed install template to ensure content localization is defaulted to off for new installs
  • Updated the warnning dialog confirmation box to show the user name and the role that the user is being removed from.
  • Fixed issue where tab hierarchy was not displayed properly when the tab level was changed in the tab hierarchy.
  • Fixed issue where translators were not given the proper edit permissions when content localization was enabled.

Security Fixes

Updated Modules/Providers

The following modules and providers have been updated in the 5.5.1 packages. Please see the specific project pages for notes on what bugs or enhancements were corrected with each release.

Modules

  • Feedback Module 05.00.02

Providers

  • none