WordPress 2.6.2 Release

As most of you have probably already seen in your Dashboard, yesterday afternoon saw the official WordPress 2.6.2 Release. And as mentioned in the comments on my intitial news break on the 2.6.2 Beta, the focus is on two security patches to cover weaknesses in PHP’s random number generation (which affects password encryption strength), and in MySQL’s field length checking. These weren’t (technically) security bugs in WordPress, per se, but in the underlying PHP/MySQL stack. Fortunately, we’re able to route around them. This is mainly a problem if your site allows users to register for a user login, however, I would still recommend this upgrade for all users, just to be on the safe side.

For those of you who are PHP/MySQL developers yourselves, I highly recommend reading Stefan Esser’s explanation of the PHP mt_srand() bug and the MySQL SQL Column Truncation issue. He provides some really good detail of the problems. Stefan is also the developer of the PHP Suhosin module, which provides extra security-related features and protections to PHP.

It’s also important to note that these problems don’t just affect WordPress — many other PHP/MySQL applications could be vulnerable to future problems if they don’t examine and patch their code.

Stumble It!
WordPress 2.6.2 Release

Related posts:

  1. WordPress 1.5.2 Security FUD
    " There is some misleading FUD going around about a vulnerability in WordPress 1.5.2. Let’s get this out of the way plainly: There is not..."
  2. WordPress 2.0 Release imminent
    " Just three hours ago, Matt posted this on the wordpress-hackers mailing list: Subject: [wp-hackers] 2.0 Release Wednesday or Thursday, depending on the phase of..."
  3. WordPress 2.0.4
    " All WordPress users are encouraged to upgrade to the newest release, WordPress 2.0.4. The new release contains several important security updates, so you are..."
  4. WordPress 2.2.2 Released
    " There is a new security & bugfix release: WordPress 2.2.2. There are no new features in this version. Since it is a security release,..."
  5. Important: Upgrade to WordPress 2.1.2
    " In the interest of getting the word out as quickly and as widely as possible, a brief word about a new WordPress release: If..."
This entry was posted in Announcements, Community, WordPress and tagged , , , , , , , , , , . Bookmark the permalink. Post a comment or leave a trackback: Trackback URL.

7 Comments

  1. Jonathan jonathanboettcher.com
    Posted September 11, 2008 at 11:38 am | Permalink

    Hey, did someone change up the post editor? It seems like its missing a whole bunch of stuff now that I’ve upgraded. For instance – where is my add link button gone? I’ve got these nice drop down menus for some things like font size etc, but no linky linky!!!!

  2. farshad kar20.ir
    Posted September 12, 2008 at 7:02 am | Permalink

    Hey, did someone change up the post editor?

  3. Riman rimanos.com
    Posted September 17, 2008 at 4:46 am | Permalink

    I try this version and it’s nice :)

  4. Sowin sowin.info
    Posted September 23, 2008 at 4:51 am | Permalink

    I still wait for better wersion but this is almost great :)

  5. Kazir kazir.info
    Posted September 24, 2008 at 6:56 am | Permalink

    Wordpress is my love :) it’s great cms – I always wait for new version

  6. MikeMech rechtsanwalt-blawg.de
    Posted September 30, 2008 at 9:52 am | Permalink

    You’re quite faster then my Drupal security news :-)
    Think it’s about time to switch some of my Drupal sites back to WordPress now…

  7. Flug ticketpoint.de
    Posted October 16, 2008 at 11:40 am | Permalink

    The new version is great. Not only the security updates, that like we all know have been more than neccessary, but especially the design options are great.

One Trackback

  1. By Wordpress 2.6.2 Upgrade | Prasys' Blog on September 10, 2008 at 11:43 am

    [...] For those of you who are geeky and would like to read the changelog (aka the upgrades) , you may want to click here (WordPress 2.6.2 Release) [...]

Post a Comment

Your email is never published nor shared.

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Subscribe without commenting