Categories
Security & Updates

Updates: Typo3 CMS 6.0.9 and 6.1.4 released

Typo3 New Updates

This release is a combined bug fix and security release. Due to security issues found in the TYPO3 Core, there was a combined release of TYPO3 CMS 6.0.9 and 6.1.4.

Changes Details

Here is a list of what was fixed since 6.0.8:

2013-09-04 [RELEASE] Release of TYPO3 6.0.9 (TYPO3 Release Team)
2013-09-04 [SECURITY] Prohibit accessing storage 0 from backend UI (Steffen Ritter)
2013-09-04 [SECURITY] Identifiers may refer to resources outside the storage (Steffen Ritter)
2013-09-04 [SECURITY] Deny arbitrary code execution possibility for editors (Helmut Hummel)
2013-09-04 [SECURITY] Refactor and fix FAL user permission handling (Helmut Hummel)
2013-09-04 [SECURITY] Add possibility to en-/disable file permission checks (Helmut Hummel)
2013-09-04 [SECURITY] Check permissions in all actions of ResourceStorage (Steffen Ritter)
2013-09-03 [TASK] CGL Cleanup of ResourceStorage (Helmut Hummel)
2013-09-03 [BUGFIX] Storage is offline but is still used (Frans Saris)
2013-09-03 [BUGFIX] Fix fatal error in ExtendedFileUtility (Helmut Hummel)
2013-09-01 [BUGFIX] Faulty check for missing SMTP port (Tomita Militaru)
2013-08-31 [BUGFIX] Backend Layout Grid Wizard not fully visible in Mac Firefox 22 (Roland Schenke)
2013-08-30 [BUGIFX] Missing argument in EM List view VH (Francois Suter)
2013-08-29 [BUGFIX] Only log file/directory actions which were done (Helmut Hummel)
2013-08-29 [BUGFIX] Sprite manager cache improvement (Christian Kuhn)
2013-08-29 [BUGFIX] TCA ‘group’ selectedListStyle with ‘width’ breaking layout (Ernesto Baschny)
2013-08-29 [BUGFIX] Database integrity check fatal error (Stefan Fürst)
2013-08-29 [BUGFIX] Cast autoload and classAliasMap to Array (Michel Georgy)
2013-08-29 [BUGFIX] Add missing API method FileInterface::getNameWithoutExtension (Ernesto Baschny)
2013-08-28 [BUGFIX] Exclude empty passwords from password hashing check (Nicole Cordes)
2013-08-27 [TASK] Make the extension titles link to the configuration (Nicole Cordes)
2013-08-27 [BUGFIX] Hide translations in categories selector (Francois Suter)
2013-08-27 [BUGFIX] Tests in Localization\Parser\LocallangXmlParserTest fail (Nicole Cordes)
2013-08-27 [BUGFIX] Escape title tag of image links (Alexander Stehlik)
2013-08-27 [BUGFIX] Page tree filtering broken in IE7 & IE8 (Aske Ertmann)
2013-08-25 [BUGFIX] Ignore permission checks for processed files (Helmut Hummel)
2013-08-20 [BUGFIX] No version overlay should be done for sys_language (Lienhart Woitok)
2013-08-20 [BUGFIX] Files with unclean path indexed multiple times (Stefan Neufeind)
2013-08-18 [TASK] FilesContentObject::stdWrapValue(): only execute stdWrap once (Stefan Neufeind)
2013-08-18 [BUGFIX] Language-module icons need to display in correct size (Stefan Neufeind)
2013-08-17 [BUGFIX] TCA: subtypes_addlist not processed (Benjamin Mack)
2013-08-17 [BUGFIX] Query parameters of external link may get altered (Stanislas Rolland)
2013-08-16 [TASK] Disable scheduler-tests if EXT:scheduler not loaded (Anja Leichsenring)
2013-08-16 [BUGFIX] Fix file permission methods in BackendUserAuthentication (Helmut Hummel)
2013-08-16 [BUGFIX] Fix inconsistencies in getTSConfig in BackenuserAuth (Helmut Hummel)
2013-08-16 Revert “[BUGFIX] Fix inconsistencies in getTSConfig in BackenuserAuth” (Helmut Hummel)
2013-08-16 Revert “[BUGFIX] Fix file permission methods in BackendUserAuthentication” (Helmut Hummel)
2013-08-15 [BUGFIX] Fix inconsistencies in getTSConfig in BackenuserAuth (Helmut Hummel)
2013-08-15 [BUGFIX] Fix file permission methods in BackendUserAuthentication (Helmut Hummel)
2013-08-14 [BUGFIX] Avoid usage of subheader in mailform (Francois Suter)
2013-08-12 [BUGFIX] Typing after abbr or acronym tag is difficult (Stanislas Rolland)
2013-08-12 [BUGFIX] FAL: Image Processing doesn’t respect GFX “thumbnails_png” (Benjamin Mack)
2013-08-12 [BUGFIX] Allow reading files if storage is not browsable (Helmut Hummel)
2013-08-11 [BUGFIX] Take into account all file and folder permissions (Helmut Hummel)
2013-08-11 [BUGFIX] Failing tests in Resource\Driver\LocalDriverTest on Windows (Nicole Cordes)
2013-08-11 [BUGFIX] Missing \TYPO3\CMS\Core\Utility\ in ResourceFactory (Wouter Wolters)
2013-08-11 [TASK] Add signal in ResourceFactory for storage creation (Helmut Hummel)
2013-08-11 [BUGFIX] LocalDriver: Recursive file listing is broken (Andreas Wolf)
2013-08-11 [BUGFIX] rtehtmlarea acronym error with static_info_tables 6.0+ (Stanislas Rolland)
2013-08-08 [BUGFIX] Reports module tries to load not-installed extension (Wouter Wolters)
2013-08-08 [BUGFIX] number_format() expects parameter 1 to be double (Wouter Wolters)
2013-08-07 [BUGFIX] Ignore case in file extension filter (Alexander Stehlik)
2013-08-07 [BUGFIX] Correctly set user storage permissions (Helmut Hummel)
2013-08-07 [TASK] Introduce AbstractHierarchicalFilesystemDriver (Steffen Ritter)
2013-08-07 [BUGFIX] Failing Resource\FactoryTest on Windows systems (Nicole Cordes)
2013-08-07 [BUGFIX] Indexing of external files does not work in indexed_search (Wouter Wolters)
2013-08-07 [BUGFIX] Callback in CrawlerHook of indexed_search sysext buggy (Marius Büscher)
2013-08-07 [BUGFIX] Backup singletons in unit tests prior to other setUp operations (Nicole Cordes)
2013-08-06 [BUGFIX] Fix EmConfUtility::fixEmConf conflicts generation (Sascha Egerer)
2013-08-06 [BUGFIX] Incorrect check for empty folder (Philipp Gampe)
2013-08-06 [TASK] Use magic __CLASS__ in getInstance()-methods (Stefan Neufeind)
2013-08-06 [BUGFIX] Fix empty href parameter (Anja Leichsenring)
2013-08-06 [BUGFIX] Fix failing test in StorageRepositoryTest (Anja Leichsenring)
2013-08-06 [BUGFIX] Fatal error: “enableFields on non-object” in extension manager (Ernesto Baschny)
2013-08-04 [BUGFIX] MySQL: Use ENGINE (not TYPE) for storage-engine (Stefan Neufeind)
2013-08-01 [BUGFIX] selected = 1 doesn’t work in FormContentObject (Wouter Wolters)
2013-08-01 [BUGFIX] Suppress double page entry in temporary mounted pagetree (Frank Frewer)
2013-07-31 [TASK] Provide information about import action in TCEmain to hooks (Stefan Galinski)
2013-07-31 [BUGFIX] RTE wizard can’t “save document and view page” (Stanislas Rolland)
2013-07-30 [TASK] Set TYPO3 version to 6.0.9-dev (TYPO3 Release Team)

Changes Details

Typo3 Release Notes  (Official Website – External link)
http://wiki.typo3.org/TYPO3_6.0.9

Typo3 Security Bulletin (Official Website – External link)
http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2013-003

More Information

  • Try Online Demo:
    Typo3 Demo (Official Website external link)
  • Start Typo3:
    In order to use Typo3 you need a domain name (ex. yoursite.com) and web hosting service.
    If you don’t have a domain name Register a Domain Name.
    To install Typo3 choose one of our hosting plans. (all our packages includes Softaculous).
  • Hosted Typo3
    Contact us if you don’t need a domain or hosting service, and want to use Typo3 anyway.
[otw_is sidebar=otw-sidebar-7]

[otw_is sidebar=otw-sidebar-8]

 

Blog: News & Updates

[otw_is sidebar=otw-sidebar-5] [otw_is sidebar=otw-sidebar-6]

[otw_is sidebar=otw-sidebar-9]