1.2

1.2.25 Released

Submitted by Chris Travers on Mon, 08/22/2011 - 00:00

Hi all;

LedgerSMB 1.2.25 has been released. This code has been reviewed for a
the type of SQL injection issues recently reported and all
questionable cases addressed. While some cases are believed to be
exploitable, others have been fixed as a mere precaution.

SQL injection issues on 1.2.x should generally be presumed to be
severe unless we offer reasons otherwise.

Users 1.2.x are advised to upgrade as soon as possible.

Best Wishes,
Chris Travers

1.2.21 Available for Download

Submitted by Chris Travers on Wed, 03/17/2010 - 18:02

LedgerSMB 1.2.21 has been released. The complete changelog is as follows:

Changelog for 1.2.21
* Corrected a number of templates with HTML issues (Luke)
* AR/AP Aging Report fixed, ignores payment after report date (Chris T)
* Minor documentation updates (Chris T)
* Fixed bug saving SIC (Adam T)

1.2.21-rc1 available

Submitted by Chris Travers on Thu, 03/11/2010 - 22:40

his release is a maintenance/bugfix release. The complete changelog
is as follows:

Changelog for 1.2.21
* Corrected a number of templates with HTML issues (Luke)
* AR/AP Aging Report fixed, ignores payment after report date (Chris T)
* Minor documentation updates (Chris T)
* Fixed bug saving SIC (Adam T)

1.2.19 and 1.3.0 beta 2 released

Submitted by Chris Travers on Mon, 02/08/2010 - 00:00

LedgerSMB 1.2.19 has been released today which includes a number of
important fixes including the security hotfixes available. It also
includes a fix for a (rather rare) sales tax rounding bug where the
tax is sometimes rounded improperly when discounts are applied at the
same time. The complete changelog is:

Why is Column DBpasswd in users_conf table is not encrypted?

Submitted by Anonymous (not verified) on Tue, 01/05/2010 - 10:57

This content is outdated and kept here for reference only!

Versions affected: LedgerSMB 1.2.x

The decision was made because there is no way to hide this information from the web server, since it needs to log into the database. It is better not to have a false sense of security. SQL-Ledger obfuscates this information but does not truly encrypt it.

Anyway, this problem is going away because 1.3 changes the way db passwords are handled.

[originally submitted by fling]

How do I get admin.pl to work? (./Build test errors)

Submitted by Anonymous (not verified) on Mon, 11/02/2009 - 06:46

This content is outdated and kept here for reference only!

(admin.pl is replaced with setup.pl in LedgerSMB v. 1.3.x and upwards)

I am trying to install ledgerSMB on SuSE 11.1 and have followed the INSTALL and README documents to do so, and have also installed all dependencies.

When I get to the following instruction I get some errors.

$ ./Build test

The errors are seen in the last few lines of output following the instruction. I list them below. Note that prior to these last few lines are many lines starting with "BEGIN failed--compilation aborted ..."