Debian CVE-2011-2483 PHP upgrade breaks SimpleInvoices reports?
  • mig5mig5 January 31

    Since this Debian security advisory (http://lists.debian.org/debian-security-announce/2012/msg00023.html), I get this error when viewing any Sales reports:


    Fatal error: Class 'PHPReport' not found in /var/www/simpleinvoices.2011.1/library/phpreports/PHPReportMaker.php on line 284

    Note the SA includes this note:

    NOTE: the fix for CVE-2011-2483 required changing the behaviour of this
    function: it is now incompatible with some old (wrongly) generated hashes
    for passwords containing 8-bit characters. See the package NEWS entry
    for details. This change has not been applied to the Lenny version of PHP.

    Not sure if that's related. But I know that the sales report worked immediately before I upgraded my PHP5 instance.

    I am on the latest release of SimpleInvoices, but it also affects previous releases.

  • modirmodir January 31

    Could you please report this here: http://code.google.com/p/simpleinvoices/issues/list We can then check with the authors of this library.

  • mig5mig5 January 31

    After this overnight regression announcement, it works again for me:
    http://lists.debian.org/debian-security-announce/2012/msg00024.html

    Sorry for the noise

Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!

Sign In Apply for Membership

Categories