Hi all,

phpBB Group announces the release of phpBB 2.0.13, the "Beware of the furries" edition. This release addresses two recent security exploits, one of them critical. They were reported a few days after .12 .Fortunately both fixes are easy and in each case just one line needs to be edited.

The first issue is critical (session handling allowing everyone gaining administrator rights) and we urge you to fix it on your forums as soon as possible.

A second minor issue reported to bugtraq several days ago was the path disclosure bug in viewtopic.php

For those who has phpbb version <2.0.12 please upgrade your forum and who already have upgraded to 2.0.12 can edit the two files manually to fix those threats, if you realy dont want to upgrade to 2.0.13.

On what files to be edited and how on phpbb 2.0.12 please visit :

http://linuxjunkies.org/forum/viewtopic.php?t=600

----