The Joomla! Forum ™



Forum rules


Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Security Checklist
Forum Post Assistant - If you are serious about wanting help, you will use this tool to help you post.



Post new topic Reply to topic  [ 7 posts ] 
Author Message
PostPosted: Fri Jul 20, 2012 11:12 am 
Joomla! Apprentice
Joomla! Apprentice

Joined: Fri Sep 22, 2006 9:06 am
Posts: 24
link from vulnerable ext list to project and joomla version

1) could you add a link from the name of the extension to the project so one knows exactly which project is meant? For example I was not sure if FCKEditor meant the JoomlaFCKEditor=JCK Editor or not
2) will there be a list also for joomla 1.6, 1.7, 2.5 or is it the same one?


Top
 Profile  
 
PostPosted: Fri Jul 20, 2012 11:52 am 
User avatar
Joomla! Master
Joomla! Master

Joined: Mon Mar 20, 2006 1:56 am
Posts: 11642
Location: The Girly Side of Joomla in Sussex
1. could you please provide a link to the item you are on about.
Normally the item name will be the same as the jed listing name or the version to identify it if one has been provided.
2. the list encompasses all versions unless specified.

as stated on the vel list, if in doubt - contact the developer.

_________________
HU2HY- Poor questions = Poor answer
Un requested Help PM's will be added to the foe list and possibly just deleted
{Community.Connect Administrator }{ Showcase & Security Moderator}


Top
 Profile  
 
PostPosted: Mon Jul 23, 2012 7:53 am 
Joomla! Apprentice
Joomla! Apprentice

Joined: Fri Sep 22, 2006 9:06 am
Posts: 24
1. link to the item: do you mean the following?
http://docs.joomla.org/Vulnerable_Exten ... #FCKeditor

JED listing name = Joomla Extension Directory http://extensions.joomla.org/
If I search the string FCKEditor in the JED there is no component listed.
One may still not be sure which extension is meant and may think the vulnerability concerns the JCK Editor (formerly JoomlaFCKEditor).

As suggested by you I asked the developers of JCK Editor and they told me they never had a vulnerability.


Top
 Profile  
 
PostPosted: Mon Jul 23, 2012 8:13 am 
User avatar
Joomla! Master
Joomla! Master

Joined: Mon Mar 20, 2006 1:56 am
Posts: 11642
Location: The Girly Side of Joomla in Sussex
briefly checking the notes from that time
the listing name at the time was correct
i will offer the options that it could be http://sourceforge.net/projects/fckeditor/ as http://extensions.joomla.org/extensions ... tors/12821 has recently been updated.

http://joomlacode.org/gf/project/ckeditor/ was launched post vulnerability report.
Sometimes, when a project is abandoned, the box will stay red. needless to say, if you are happy with the developers assurance then use it

_________________
HU2HY- Poor questions = Poor answer
Un requested Help PM's will be added to the foe list and possibly just deleted
{Community.Connect Administrator }{ Showcase & Security Moderator}


Top
 Profile  
 
PostPosted: Mon Jul 23, 2012 10:39 am 
Joomla! Apprentice
Joomla! Apprentice

Joined: Fri Sep 22, 2006 9:06 am
Posts: 24
As I got confused again, I tried to summarize what we said.

JCK Editor
website: http://www.joomlackeditor.com/
there does not seem to be a joomlacode/sourceforge project site
They state they never had a vulnerability

FCK Editor (according to your information)
website: http://ckeditor.com/
project site: http://sourceforge.net/projects/fckeditor/
This component has the vulnerability

You state http://joomlacode.org/gf/project/ckeditor/ was launched after the vulnerability report, but the logo and the website (http://ckeditor.com/) are identical to the above. I wonder why FCK Editor seems to proceed regardless of the vulnerability listed since May 2011 !!!


Top
 Profile  
 
PostPosted: Tue Jul 24, 2012 7:49 am 
Joomla! Apprentice
Joomla! Apprentice

Joined: Fri Sep 22, 2006 9:06 am
Posts: 24
This is the answer from CKEditor when I asked them about the vulnerability

Hi Michael,

Thank you for getting in touch with us to clarify this.

First of all, let me try to explain the difference between FCKeditor and CKEditor and some other doubts:

1) FCKeditor vs CKEditor

The name "FCKeditor" refers to all releases of FCKeditor, till 2.x. FCKeditor was retired in 2010.
Note that since 2009, the new "V3" version of the editor is available, CKEditor 3.x. Because it has no built-in file browser, it is almost impossible to have a security issue there.
There are no valid security reports for CKEditor, and if eventually one was reported, it would be fixed quickly.

2) What security issue exactly is mentioned in the table?

As stated before, the 2.x version is retired and is no longer maintained since 2010 (the last 2.6.6 release). Well, with a little exception: the last version of FCKeditor, 2.6.7, was released 29 March 2012, where a security issue was fixed soon after getting a report (more related to ASP/IIS6 than PHP, see the release announcement for more details: http://cksource.com/forums/viewtopic.php?t=25112).

So, even for retired version we're fixing security issues, if they look critical, as long as we offer something on the download page.

3) Does the table list FCKeditor (the editor itself) or a Joomla extension that was using FCKeditor?

The table listed here: http://docs.joomla.org/Vulnerable_Exten ... #FCKeditor does not mention neither the version of FCKeditor, which had the security issue, nor the particular security report @ secunia.com, for example. Maybe the issue is fixed already in FCKeditor?

The table is in fact very confusing, because it does not link to any particular vulnerable extension that used FCKeditor.
Did the security issue apply to the Joomla extension that was using FCKeditor, or to FCKeditor in general?

Maybe the security issue was in a component that was using FCKeditor, not in the FCKeditor itself?
Maybe the "unknown extension" was listed as vulnerable, because it did not update FCKeditor to the latest, secure version?

4) The situation in 2012

Afaik FCKeditor is no longer used by any extension. There is even no extension with such name.
At this moment I know two extensions that provide *CKEditor*:

a) The official CKEditor for Joomla integration provided by CKSource:
http://extensions.joomla.org/extensions ... tors/12821

b) JCK Editor
http://extensions.joomla.org/extensions ... editors/90

Again, please be aware that CKEditor is not FCKeditor. Apart from many architectural changes, the major part of server side code that could potentially cause security issues, was removed from CKEditor.

So, to summarize: the mentioned table is outdated and provides misleading information. Feel free to use CKEditor, both extensions are actively maintained, so in case of any security issues, I'm sure they will be fixed immediately.

If you participate in the discussion, feel free to cite me.

Best regards,
Wiktor Walc
CTO, CKSource

Anytime you wish you can view your question online:
http://helpdesk.cksource.com/view.php?t ... s=377q8aFS


Top
 Profile  
 
PostPosted: Tue Jul 24, 2012 7:57 am 
Joomla! Apprentice
Joomla! Apprentice

Joined: Fri Sep 22, 2006 9:06 am
Posts: 24
and here the former answer from the JCK Editor

Dear Michael,

Thank you for your email.

Our editor (JCK Editor) has never been known as the 'FCKeditor' this was in fact a different project!

Before February 2010 the project was called JoomlaFCK, after February 2010 we emitted the ‘F’ from the JoomlaFCK, this coincided with the launch of the new 3.x series, which now runs on a different framework.

To date we have never been listed on the: Joomla Vulnerable Extensions.

I hope this will assure you of our efforts.

Kindest regards,
Paul Franklin and the JCK TEAM


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 7 posts ] 



Who is online

Users browsing this forum: No registered users and 17 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  
Powered by phpBB® Forum Software © phpBB Group