![]() |
|
||||||
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
Hi,
I just got an email from my web host saying that there's a security hole with the WP thumbnailing library. Could you please give me more info on this or if this theme will be upgrated to get rid of that security hole? What do you suggest? (See below). Any help would be appreciated. Thanks in advance. -------------- The security hole exists in a Thumbnailing library, called TimThumb. This library is commonly used in Wordpress themes, and is used to create thumbnails and link images from other photo sharing websites. This security exploit exists in a library that is used in Wordpress themes. It is not part of the core Wordpress. Even if you have your core Wordpress script up-to-date, you may still be vulnerable. It is also important to note that this is not a security issue only with Wordpress. Other scripts may make use of the TimThumb library, but Wordpress is by far the most common use. A lot more information about this is available at our blog at: http://blog.amssupport.info/?p=448 |
|
#2
|
|||
|
|||
|
Hi,
You should get yourself a copy of TimThumb version 2.0 which fixes this security issue. Simply grab the file from here and replace your existing copy of timthumb.php. (The orig file is probably in your theme's "tools" folder.) Actually, I've just realised that the version of timthumb shipped with the classic themes had the external site capability removed (which is where the vulnerability lay in unmodified versions.) I would still advise upgrading the script as I believe the new version is quicker, leaner and meaner. :-)
__________________
Ade Themessence - Studiograsshopper WordPress plugins: Dynamic Content Gallery | Reveal Page Templates | Custom Taxonomies Menu Widget Check out the Genesis and Child Theme tutorials before posting your question - and please provide YOUR URL! Make Andrea happy - read her Firebug tutorial and save yourself loads of time and effort. Last edited by adew; 08-12-2011 at 04:19 AM. |
|
#3
|
|||
|
|||
|
Thanks a lot Abe, that was helpful! But I did have another question. So looking at the higher version of timthumb, it looks a lot different from the old file. Do I have to edit anything or do I just replace exactly how it is? Here's what my old version looks like:
--- PHP Code:
---------------- vs. the new version here: http://timthumb.googlecode.com/svn/trunk/timthumb.php Last edited by SoZo; 08-14-2011 at 11:55 PM. Reason: TAGGED |
|
#4
|
|||
|
|||
|
Version 2.0 was a complete rewrite, therefore the code will look different. You don't have to edit anything - just replace the old timthumb file with the new one.
__________________
Ade Themessence - Studiograsshopper WordPress plugins: Dynamic Content Gallery | Reveal Page Templates | Custom Taxonomies Menu Widget Check out the Genesis and Child Theme tutorials before posting your question - and please provide YOUR URL! Make Andrea happy - read her Firebug tutorial and save yourself loads of time and effort. |
|
#5
|
|||
|
|||
|
|
|
#6
|
|||
|
|||
|
Yeah, I'd stumbled across Mark Maunder's forensics posts talking about what he'd discovered, and while updating a couple client sites, I'd completely forgotten that Lifestyle classic used it, and that I'd added it to a site I'd done with Magazine classic.
So I updated timthumb where needed, and even removed it on a couple of my personal sites, since I'm in mid-update with new themes for those, and will have to run Regenerate Thumbnails when I transition anyway I'm not sure why Mullenweg'd be taking a backhanded swipe at premium themes and the use of timthumb; starting in 2005-6, 4 of the first 7 WordPress websites I ever did were based on mimbo and arthemia, both of which were free at the time, and also used timthumb. Premium themes were barely just coming on the scene back then, and having seen plugins come and go, I was concerned that someone with a premium theme might also become fly-by-night, leaving us in the lurch. The original Revolution themes changed my mind about that, real quick. That said, much love to my Revolution/Studio Press peeps. The websites for my shows wouldn't have been nearly so easy to get going without you guys and gals. |
|
#7
|
|||
|
|||
|
Quote:
__________________
Ade Themessence - Studiograsshopper WordPress plugins: Dynamic Content Gallery | Reveal Page Templates | Custom Taxonomies Menu Widget Check out the Genesis and Child Theme tutorials before posting your question - and please provide YOUR URL! Make Andrea happy - read her Firebug tutorial and save yourself loads of time and effort. |
|
#8
|
|||
|
|||
|
Since this is resolved, I'll close the thread.
__________________
Ade Themessence - Studiograsshopper WordPress plugins: Dynamic Content Gallery | Reveal Page Templates | Custom Taxonomies Menu Widget Check out the Genesis and Child Theme tutorials before posting your question - and please provide YOUR URL! Make Andrea happy - read her Firebug tutorial and save yourself loads of time and effort. |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| lifestyle classic theme home page | divadi | General Discussion | 1 | 05-26-2010 10:26 PM |
| Lifestyle Theme Classic and Genesis | griverss99 | General Discussion | 2 | 05-02-2010 11:38 AM |
© Copyright 2012 Copyblogger Media LLC · StudioPress™ is a trademark of Copyblogger Media LLC
Privacy Policy | Refund Policy | Terms of Service | Affiliate Program | Contact Us