1.3.38 released
Heartbleed and LedgerSMB
What follows is a slightly edited version of a post to the email lists. While LedgerSMB does not directly utilize OpenSSL, it is usually deployed on web servers that do. No upgrades of LedgerSMB are required, but you may need to update the security libraries of your web server. Please read further for the sorts of implications this has regarding LedgerSMB and what we would recommend about mitigating and recovering from risks.
- Read more about Heartbleed and LedgerSMB
- Log in or register to post comments
Security advisory (fixed in 1.3.37)
Security Advisory: LedgerSMB < 1.3.36, Improper Logout on Some Browsers
Severity: Low (cvssv2 base score: 3.6, total 0.5)
Remotely Exploitable: No
Complexity of Attack: High
Impact: Relatively low.
Prerequisite for Attack: Physical Access to Previously Logged In Browser, so high complexity in most cases.
Attack Vector: Physical, against client.
Impact: The attacker may gain access unexpectedly to LedgerSMB using the client's previous credentials.
Background
- Read more about Security advisory (fixed in 1.3.37)
- Log in or register to post comments
1.3.37 released
- Read more about 1.3.37 released
- Log in or register to post comments
The LedgerSMB Core Team is proud to release 1.3.36.
This release corrects a significant issue in printing invoices with manually calculated sales tax. This is a significant update, and anyone using 1.3.35 or manually entered sales tax should update relatively quickly.
- Read more about The LedgerSMB Core Team is proud to release 1.3.36.
- Log in or register to post comments
LedgerSMB 1.3.35 released
LedgerSMB 1.3.35 has been released. This release includes a fairly large number of relatively minor fixes, as well as the addition of invoice creation date tracking and a number of fixes for locale-specific requirements. If you are having any issues with the bugs fixed, you should upgrade immediately.
- Read more about LedgerSMB 1.3.35 released
- Log in or register to post comments
LedgerSMB 1.3.34 released
LedgerSMB 1.3.33 released
LedgerSMB 1.3.33 has been released. This release corrects a number of minor issues, the most major one is that format_amount() was not working on the check printing workflows.
LedgerSMB 1.3.32 released
LedgerSMB 1.3.32 has been released. This release adds overlooked functionality, and corrects a number of minor to moderate problems with previous releases. Those who are running 1.3.31 should upgrade sooner rather than later. Others should upgrade after reviewing the 1.3.31 inventory changes.
LedgerSMB 1.3.31 released, significant Inventory changes
LedgerSMB 1.3.31 has been release and includes a rather deep fix to our onhand numbers. We recommend that anyone who is shipping or receiving inventory upgrade when you are able, but also direct questions too us if there are questions or concerns about the upgrade process.