We have released a new version of Movable Type, version 2.65, to fix this problem.
Movable Type 2.65 が出ました。
・mt-send-entry.cgi のセキュリティホール修正
・XMLRPCServer.pm のセキュリティーホール修正
・デフォルトテンプレートに Atom syndication template
という内容です。XMLRPCServer.pm の脆弱性は結構深刻ですので、バージョンアップした方がいいでしょう。ただし、修正としてはあまり大きくないので、
If you'd rather just fix the XML-RPC security issue, you can just replace lib/MT/XMLRPCServer.pm on your server with the new version of XMLRPCServer.pm (this is a ZIP file--extract it and upload the version of XMLRPCServer.pm within to your server in ASCII mode).
とある通り XMLRPCServer.pm だけ 2.65 のそれと入れ替えるだけで対処しても良さそうです。Atom フィードのテンプレートも別途配布されていますし。
XMLRPCServer.pm ですが、Kung-Log などの XML-RPC API クライアントを、EUC-JP パッチを当てた MT でも使えるように、以前パッチを書きました。('Kung-Log を EUC-JP パッチを当てた MT でも使えるように' 参考) 今回の件でオリジナルの XMLRPCServer.pm に変更があったので、2.65 XMLRPCServer.pm 用のパッチを書きました。
movabletype.org から 2.65 の XMLRPCServer.pm をダウンロードして、このパッチを当てると EUC-JP な MT でも Kung-Log などが使えるようになります。
[naoya@mary naoya]$ ls -la XMLRPCServer.pm -rw-r--r-- 1 naoya naoya 22870 12月 22 18:45 XMLRPCServer.pm [naoya@mary naoya]$ patch -p0 < XMLRPCServer_2.65_euc.patch patching file XMLRPCServer.pm [naoya@mary naoya]$ ls -la XMLRPCServer.pm -rw-r--r-- 1 naoya naoya 23560 12月 23 00:00 XMLRPCServer.pm
みらのさんに、2.65 パッチを作るときは取り込んでもらえるよう、連絡しておきます。
MT2.65を使っています。
EUC-JPでmoblogをすると文字化けするので、
UTF-8に変えました。すると携帯からの文字化けは
解消したのですが、Mac(OS X)から投稿しようと
した時に、カテゴリーとか公開/下書きのプルダウン
メニューが表示されません。(選択すると表示される)
それ以外は大丈夫なんですが・・・。
EUC-JPではMacでそんなことは起こりません。
もちろん、Winではどっちも問題ありません。
できれば、EUC-JPでmoblogしたい(Macユーザもいる
もので)ので、naoya様のXMLRPCServer.pmパッチを
当ててみたいのですが、どうやるのでしょうか?
基本的な質問で申し訳ありません。上記アドレスに
お返事頂けると幸いです。かしこ。
Wow, the spam on your page has gotten out of controll. I don't even know if you'll get this comment or not, but I guess I'll try posting it for the heck of it...They say there's strength in numbers, so I get a couple of others I know to come here and comment, too. Consequentialism is probably the best way to go. If you think about what WILL happen, not what might happen, you can essentially get a better view of what you are dealing with. The problem is, people tend to believe in fate or some sort of predestined life, which is the cornerstone of religious faith. What do you think?
[3] Posted by: Archies Blog Online at February 14, 2004 08:51 AM [返信]Does Bobo like this page? Sure he does, :) Thanks for your interesting point of view. I share the sentiments, althought I differ with respect to the thought that all conclusions are precluded by the initiating thought. In simple terms, I believe that since we can't know the future, it's better not to conclude a certain fate but rather chose a direction...
[4] Posted by: Bo Bos Blog By Me Bobo at February 14, 2004 08:51 AM [返信]The General News Blog.us, the place for yep, you guessed it, GENERAL NEWS! Well its kinda more than that, its general news with a liberal twist. Sorry for any conservatives out there in the blogosphere, but if it weren't for the liberals, we'd still be in the stone age...Ok so that's an exaggeration, but you get what I mean. I Hope.
[5] Posted by: General News Blog at February 14, 2004 08:51 AM [返信]Hank is here, Hank is cool, Hank has fun, Hank's no fool....Hahaha, this and other rhymes can be found at my great blog. But on a more serious note, one just has to consider the political environment in the States right now. We POSSIBLY have a lying President, re weapons of mass destruction not being in IRAQ, but then again we also have two cowboy democrats Dean and Kerry running for the presidency... It is crucial at this time that we vote correctly...George W know's it, but he won't be in office to worry about that much longer:)
[6] Posted by: Hanks blog at February 14, 2004 08:52 AM [返信]SIke's blog, rants and pissed off messages of Ike.
[7] Posted by: ikes online blog at February 14, 2004 08:52 AM [返信]Extra, Extra, Get the latest news here, at NEWS BLOG!
[8] Posted by: news blog and more blog at February 14, 2004 08:53 AM [返信]THe QWERTY Blot, the first 44 letters of the keyboard are the best! Like that old drink, Five Alive....For those of you from the 440's generation....
[9] Posted by: qwerty blot blog at February 14, 2004 08:53 AM [返信]Tom's Blog: The answer to the bleeding hearts, the liberals, the tree-huggers, and those who prefer Soy to Whole Milk....Sorry, I guess it's pretty obvious what my sentiments are, but joking a part, yes I think it's time for a reality check and such a check takes the form of a little conservativism...and there's nothing wrong with that, let me assure you.
[10] Posted by: toms big bad blog at February 14, 2004 08:53 AM [返信]