News

LedgerSMB 1.3.24 released, FCGI and PSGI support

Submitted by hasorli on

The LedgerSMB development team is proud to release 1.3.24. This release contains a fairly large number of polishing bug-fixes, but also important Plack-related fixes for folks wanting to use LedgerSMB in FCGI and PSGI environments. These fixes ensure that LedgerSMB can be run caching some of the dependencies and thus will be far more responsive than when run as a simple CGI application.

LedgerSMB 1.3.23 released

Submitted by hasorli on

LedgerSMB 1.3.23 has been released. This release includes a number of bugfixes, some of which affect the ability to deploy LedgerSMB in new environments. Most of these bugfixes are relatively minor but they do impact upgrades from 1.2.x for some users. Additionally most of the changes are ones which allow us to present a more polished product to the user.

This also corrects some i18n issues and a few other issues. The complete changelog is below.

LedgerSMB 1.3.22 released

Submitted by hasorli on

We have released LedgerSMB 1.3.22 in response to significant installation issues with new databases under 1.3.21. If you are planning on setting up additional companies, you should probably upgrade.

This release also corrects an issue with midsized databases where certain screens are slow. This was caused by the selection for all years being slow due to a missing index. If the AR/AP transaction screens are very slow, try upgrading here.

The complete changelog is below.

Best Wishes,
Chris Travers

Security: Denial of Service Vulnerability in 1.3.20 and below

Submitted by Chris Travers on

A security oversight has been discovered in LedgerSMB 1.3 which could allow a malicious user to cause a denial of service against LedgerSMB or otherwise affect the way in which certain forms of data would get entered.  In most cases we do not believe this to be particularly severe in the presence of internal process controls.  Users in some jurisdictions however may need to take this more seriously (see full details below).

Basic vulnerability characteristics

LedgerSMB 1.3.20 has been released

Submitted by Chris Travers on

The LedgerSMB core team is pleased to announce the release of LedgerSMB 1.3.20. As time has progressed, bug reports have slowed as expected, and so we have an opportunity to address issues more rough edges. This process will continue as more people continue to discuss with us what would be needed to make their lives easier with the software.

LedgerSMB 1.3.19 has been released

Submitted by Chris Travers on

LedgerSMB 1.3.19 has been released. This release corrects two
significant issues and makes the application generally easier to use.
The two significant issues it fixes is that voided transactions were
including the original payments again, and that CSV exports had no
data. A large number of more minor problems were fixed including the
fact that some reports were requiring that the date be set in ISO
format, and fixed an encoding issue that caused corruption on
retrieval of some attached files (the files were stored correctly so

LedgerSMB 1.3.18 released

Submitted by Chris Travers on

This release corrects a few bugs that are specific to 1.3 and a few bugs which have been longstanding since before the fork. Additionally pricelists are now exported in ODS format. XLS output which has been broken for some time was removed.

The most important bugfixes are that ODS output now works, and selecting from the year and month dropdowns doesn't result in bogus dates being printed at the top of the report. Additionally an internal server error when running monthly requirements reports was corrected.

LedgerSMB has been accepted into Debian!

Submitted by Chris Travers on

Robert James Clay just wrote the -users list to make the following announcement:

The 1.3.15-2 package for LedgerSMB has been accepted into Debian
unstable. I expect that version of the package to migrate to Debian
testing (wheezy) by the end of this month.

LedgerSMB Debian source package page:

https://packages.qa.debian.org/l/ledgersmb.html

LedgerSMB 1.3.17 released

Submitted by Chris Travers on

This release corrects the internal server error on tax lookup issue, and it also corrects an issue that was found in file uploads. Additionally for those running the latest Math::BigInt and Math::BigFloat packages, one is_zero issue was found and fixed. A number of more minor bugfixes are included as well.

LedgerSMB 1.3.16 has been released.

Submitted by Chris Travers on

This release corrects a number of issues regarding international support, including an issue with UTF-8
characters not showing up properly in HTML invoices, some corrections in the aging report so that invoices are clustered by currency (with subtotals per currency), new user screen not respecting default country, and some enhancements for local tax rules support.

Please see the changelog below for more details.

Best Wishes,
Chris Travers

Changelog for 1.3.16