DNN Blog

Sep 22

Posted by: Joe Brinkman
9/22/2010 12:31 PM  RssIcon

products2I am happy to announce the release of DotNetNuke 5.5.1.  This release includes many bug fixes for the most critical issues identified in DotNetNuke 5.5.0 which we released last month.  As a result of the recent ASP.Net Padding Oracle Vulnerability, which was discussed by Shaun Walker and Cathal Connolly in their recent blogs, we have added additional checks and upgrade enhancements in this release to ensure that DotNetNuke sites running the latest version are using the recommended CustomErrors configuration.  

As we have noted in many of our recent releases, we continue to increase our Quality Assurance efforts with each release.  Given the critical nature of the ASP.Net vulnerability, we paid extra attention to more than 40 different upgrade scenarios to increase the stability and reliability of the upgrade process, and to ensure that once upgraded your site would be protected.  As always, even for those unfortunate few who have issues upgrading, the community stands ready to assist you with any problems you may encounter.  We highly recommend that everyone upgrade to the DotNetNuke 5.5.1 release as soon as possible.  For those who are unable to upgrade their sites we anticipate having a standalone module which we will make available later this week which provides the same benefits against the padding oracle vunlnerability as the core enhancements made in 5.5.1.

POETYou can find out more information about all of the issues fixed in this release on the changelog.

Major Highlights

  • Added feature to detect if a site is not running the suggested customErrors configuration to mitigate the ASP.Net Padding Oracle Vulnerability.
  • Updated the default web.config to use the recommended customerrors settings to mitigate the ASP.Net Padding Oracle Vulnerability.
  • Fixed Sitemap Provider so it only returns one page when multiple languages are enabled and Content Localization is not enabled.
  • Fixed Telerik File Manager to make files stored using database folders visible to the user.
  • Fixed issue where module developers using custom aspx pages that inherit from basepage and use codeblocks get an exception
  • Fixed issue where the locale was not properly reflecting the querystring and the users browser or portal settings.
  • Fixed issue where users were not granted proper permissions for the Templates folder on install.
  • Fixed issue where missing objectqualifier would cause upgrade script to fail.
  • Updated the url parser to take port 443 and ssl into consideration. its no longer necessary to turn off human friendly or use-port number in web.config
  • Fixed behavior of Language detection when Content Localization is not enabled.
  • Updated update tab logic to take host tabs into consideration.
  • Fixed install template to ensure content localization is defaulted to off for new installs
  • Updated the warnning dialog confirmation box to show the user name and the role that the user is being removed from.
  • Fixed issue where tab hierarchy was not displayed properly when the tab level was changed in the tab hierarchy.
  • Fixed issue where translators were not given the proper edit permissions when content localization was enabled.

Security Fixes

Updated Modules/Providers

The following modules and providers have been updated in the 5.5.1 packages. Please see the specific project pages for notes on what bugs or enhancements were corrected with each release.

Modules

  • Feedback Module 05.00.02

Providers

  • none

NOTE:  As with any release, we recommend you perform a complete file and database backup before performing any upgrade on a production website and that you first conduct a trial upgrade on a staging version of the site.  Following these guidelines will ensure that you are able to recover should any unforeseen problems arise during the upgrade process.

3 comment(s) so far...


Gravatar

Re: DotNetNuke 5.5.1 Released

Fantastic turnaround!

By Leigh Pointer on   9/22/2010 3:38 PM
Gravatar

Re: DotNetNuke 5.5.1 Released

Given that the POET workaround is just a workaround, is there a mechanism for reverting the change to the web.config? Is this feature going to be removed from future versions once a real fix is available from the ASP.NET team?

By Brian Dukes on   9/22/2010 3:39 PM
Gravatar

Re: DotNetNuke 5.5.1 Released

@Brian - In our workaround, we comment out the old customErrors node and add the new node based on the recommendation provided by MS. If customers want to undo this after MS releases an official patch then they can just uncomment their old customErrors node and remove the one that we added in 5.5.1.

By Joe Brinkman (Host) on   9/22/2010 3:41 PM
Attend A Webinar
Free Demo Site
Download DotNetNuke Professional Edition Trial
Have Someone Contact Me
Have Someone Contact Me

Like Us on Facebook Join our Network on LinkedIn Follow DNN Corporate on Twitter Follow DNN on Twitter

Advertisers

Sponsors

DotNetNuke Corporation

DotNetNuke Corp. is the steward of the DotNetNuke open source project, the most widely adopted Web Content Management Platform for building web sites and web applications on Microsoft. Organizations use DotNetNuke to quickly develop and deploy interactive and dynamic web sites, intranets, extranets and web applications. The DotNetNuke platform is available in a free Community and subscription-based Professional and Enterprise Editions with an Elite Support option. DotNetNuke Corp. also operates the DotNetNuke Store where users purchase third party apps for the platform.