1.4.0 released

Submitted by ehu on
Open source ERP system introduces numerous new features and improvements that increase IT landscape integration options and reduce the need for customization.

15 September 2014, London. The LedgerSMB project - all-volunteer developers and contributors - today announced LedgerSMB 1.4.0.

1.3.42 released

Submitted by Chris Travers on

The LedgerSMB team is proud to release version 1.3.42.  This release corrects a couple of significant issues and a number of more minor issues.

Most significantly this corrects an issue which prevented posting of foreign currency payments when certain conditions regarding rounded, converted amounts were present.  Also this corrects an issue where invoices with ship-to addresses were sometimes linked to incorrectly in the reports.

A number of more minor fixes were included as well.

The complete changelog is below:

1.3.41 released

Submitted by ehu on

LedgerSMB 1.3.41 has been released.

It includes a single fix to the single payment workflow which caused an error in some cases while paying invoices.

1.3.40 released

Submitted by ehu on

This release has a couple of sales tax fixes, a database schema fix and a couple of others. Highly recommend upgrading at earliest opportunity.


Changelog for 1.3.40

1.3.39 released

Submitted by ehu on
March 31st, 2014 -- Announcement of the 1.3.39 release.
 
We've released LedgerSMB 1.3.39.  This provides a number of fixes.  Users of 1.3.38 are urged to upgrade as soon as possible, due to a bug inadvertently introduced in that release, which causes difficulty posting AR and AP transactions.
 
Changelog for 1.3.39

1.3.38 released

Submitted by ehu on
February 25th, 2014, Announcement of the release of 1.3.38.
 
Several of the bugs fixed in this release probably go all the way back to 1.2 and beyond. 
 
Changelog for 1.3.38

Heartbleed and LedgerSMB

Submitted by Chris Travers on

What follows is a slightly edited version of a post to the email lists.  While LedgerSMB does not directly utilize OpenSSL, it is usually deployed on web servers that do.  No upgrades of LedgerSMB are required, but you may need to update the security libraries of your web server.  Please read further for the sorts of implications this has regarding LedgerSMB and what we would recommend about mitigating and recovering from risks.

Security advisory (fixed in 1.3.37)

Submitted by Chris Travers on

Security Advisory: LedgerSMB < 1.3.36, Improper Logout on Some Browsers

Severity:  Low (cvssv2 base score: 3.6, total 0.5)
Remotely Exploitable: No
Complexity of Attack:  High
Impact:  Relatively low.
Prerequisite for Attack:  Physical Access to Previously Logged In Browser, so high complexity in most cases.
Attack Vector:  Physical, against client.
Impact:  The attacker may gain access unexpectedly to LedgerSMB using the client's previous credentials.

Background

1.3.37 released

Submitted by Chris Travers on
LedgerSMB 1.3.37 has been released.  This is a significant release with a number of important fixes including two security fixes (please stay tuned for security advisories on these two usually-minor security issues).