OpenSimulator,,, now released

classic Classic list List threaded Threaded
1 message Options
Reply | Threaded
Open this post in threaded view

OpenSimulator,,, now released

Hi folks,

As notified in yesterday's pre-release announcement, OpenSimuator security update versions,, and are now available.  These can be downloaded from the usual place [1].  Release notes are at [2], [3], [4] and [5].

There is only one change in these releases.  This is to fix an issue where llRemoteLoadScriptPin() does not treat the
pin '0' as an unset pin.  By default, all prims have a pin set to 0.  Therefore, this bug allows llRemoteLoadScriptPin()
to specify a 0 pin to load scripts into owned prims with no pin set where this should not be possible.

Unless you are very sure that no user will run a script from an untrusted source, we would advise you to update as soon
as possible.  There are no database migrations or config changes in this release compared to the previous in the series,
so all config files can be used without alteration.

This bug was introduced more than 6 years ago with the original llRemoteLoadScriptPin() implementation and so affects
all versions of OpenSimulator at least from 0.4.  If you are using a version of OpenSimulator older than 0.7.4 (which
was released in August 2012) then you will need to upgrade or apply the patch in commit 5aa8ba1 manually.

Many thanks to Tranquility Dexter of Inworldz for pointing out the bug and the fix.


Justin Clark-Casey (justincc)
OSVW Consulting
Opensim-users mailing list
[hidden email]