Zen Cart Logo
Forums / General Questions / Version 1.3X is it secure enough?

Version 1.3X is it secure enough?

Views: 791

Results 1 to 4 of 4
19 Feb 2012, 9:14 PM
#1
awk_grep avatar

awk_grep

New Zenner

Join Date:
Dec 2006
Location:
Dallas,TX
Posts:
98
Plugin Contributions:
0

Version 1.3X is it secure enough?

I am In 1.3x version of Zancart. I have been away for almost a year, but now, I am loading items again.Question is , how secure is 1.3X? is it a reliable version? Or Am I asking for it?

All the best.
-awk

19 Feb 2012, 9:35 PM
#2
fairestcape avatar

fairestcape

Totally Zenned

Join Date:
Mar 2008
Location:
Cape Town & London (depends on the season)
Posts:
2,957
Plugin Contributions:
0

Re: Version 1.3X is it secure enough?

1.3.x encompasses a LOT of supplementary versions. You have to be much more specific. There is no version titled "1.3.x".

The "x" relates to a supplementary version number, and the most recent in the 1.3 series is 1.3.9h

In your ADMIN PANEL, go to TOOLS and look up SERVER / VERSION INFO and let us know what proper version you are using.

20 Feb 2012, 12:14 AM
#3
awk_grep avatar

awk_grep

New Zenner

Join Date:
Dec 2006
Location:
Dallas,TX
Posts:
98
Plugin Contributions:
0

Re: Version 1.3X is it secure enough?

ok.. here what I have:

(You are presently using: v1.3.9g)

Server OS: Linux 2.6.18-238.19.1.el5PAE
Database: MySQL 5.0.91-log Server Date: 02/19/2012 17:07:37
Database Date: 02/19/2012 17:07:37

20 Feb 2012, 1:54 AM
#4
schoolboy avatar

schoolboy

Totally Zenned

Join Date:
Jun 2005
Location:
Cumbria, UK
Posts:
10,327
Plugin Contributions:
0

Re: Version 1.3X is it secure enough?

1.3.9g had some irritating little bugs (one was in the HTML editor feature) so you should at the very least upgrade to 1.3.9h . There is no database upgrade needed from g to h ... only a few code files.

And - in general - when a new version is released, one should go about the procedures for an upgrade. Just what these "procedures" are depends to a large extent on the nature of the add-ons which are operating in your installation.

There are still several add-ons that are not yet compatible with 1.5, so if you use those not-yet-converted addons, you have a choice at this point:

  1. remove the incompatible add-ons and upgrade to 1.5
  2. wait for upgrades to your add-on (or re-code them yourself)

1.3.9h remains a stable release, with no known (or serious) vulnerabilities. 1.5 was built to introduce a range of strict security situations that are now required for PCI/DSS and PCA/DSS compliance. The nature of these measures has resulted in some significant alterations to the way the ADMIN area operates - and it is this main area where some add-ons fail.

You can (reasonably safely) maintain your 1.3.9h version for a while yet... but there ought to be a strategy in place for you to upgrade.