<?xml version="1.0" encoding="utf-8"?>


<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
    xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
    xmlns:admin="http://webns.net/mvcb/"
    xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
    xmlns:content="http://purl.org/rss/1.0/modules/content/">
    <channel>
    <title>Magento Blog</title>
    <link>http://www.magentocommerce.com/blog/</link>
    <description></description>
    <dc:language>en</dc:language>
    <dc:creator>RoyRubin</dc:creator>
    <dc:rights>Copyright 2008</dc:rights>
    <dc:date>2008-05-12T21:07:00-08:00</dc:date>
    <admin:generatorAgent rdf:resource="http://expressionengine.com/" />

    <item>
      <title>Patch For Magento Release 1.0.19700</title>
      <link>http://www.magentocommerce.com/blog/patch-for-magento-release-1019700/</link>
      <guid>http://www.magentocommerce.com/blog/patch-for-magento-release-1019700/#When:22:41:00Z</guid>
      <description><![CDATA[<p>The latest Magento release included a bug that was found today.
</p>
<p>
The bug will cause products to be deleted completely from the system when a frontend customer adds items to compare products and then clears all selections.
</p>
<p>
This bug was found in the latest Magento release, Version 1.0.19700, and is not known to affect version 1.0.
</p>
<p>
It is high priority for all people using Magento 1.0.19700, or who have upgraded to Magento 1.0.19700, to install this Patch.
</p>
<p>
Installing the patch:
</p>
<p>
1. Download either the zip file: <a href="http://www.magentocommerce.com/downloads/assets/1.0.19700/patch1_1.0.19700.zip" title="patch1_1.0.19700.zip">patch1_1.0.19700.zip</a> or the tar.gz file <a href="http://www.magentocommerce.com/downloads/assets/1.0.19700/patch1_1.0.19700.tar.gz" title="patch1_1.0.19700.tar.gz">patch1_1.0.19700.tar.gz</a>
</p>
<p>
2. Extract and upload the file CompareController.php or extract directly the archives to  app/code/core/Mage/Catalog/controllers/Product/ 
<br />

</p>]]></description>
      
      <dc:subject>News, Updates, Magento Community</dc:subject>
      <dc:date>2008-05-01T22:41:00-08:00</dc:date>
    </item>
 


    <item>
      <title>Comment by ArthurDent</title>
      <link>{url_as_title}</link>
      <description><![CDATA[<p>@Ross: o.k. my fault. I just forgot that I  upgraded from 1.0 to 1.0.970 with a full distribution set and lateron applied that patch file already.
</p>]]></description>
    <dc:date>2008-05-12 T;21:07:00-08:00</dc:date>
    </item>

    <item>
      <title>Comment by Ross</title>
      <link>{url_as_title}</link>
      <description><![CDATA[<p>@ArthurDent - There is no &#8216;patch from 1.0 to 1.0.19700&#8217;.&nbsp; The 2 files linked above are the same patch, just one is .zip and the other is .tar.gz (for convenience, as windows users prefer .zip, while UNIX users prefer .tar.gz).&nbsp; Sorry if I have misunderstood you.
</p>]]></description>
    <dc:date>2008-05-12 T;21:07:00-08:00</dc:date>
    </item>

    <item>
      <title>Comment by ArthurDent</title>
      <link>{url_as_title}</link>
      <description><![CDATA[<p>@Ross: the point thats confusing me is that the patch from 1.0 to 1.0.19700 has the same file name than the patch mentioned above. I also compared the file, which is in the to patches, and they are identical. So I supposed the patch file linked above is the old one (patch from 1.0 to 1.0.9700). Otherwise it would make no sense to apply idential files twice.
</p>]]></description>
    <dc:date>2008-05-12 T;21:07:00-08:00</dc:date>
    </item>

    <item>
      <title>Comment by Ross</title>
      <link>{url_as_title}</link>
      <description><![CDATA[<p>@ArthurDent - the patch available above is a small amount of code that fixes the problem in version 1.0.19700.
</p>
<p>
the &#8216;patch&#8217; does not apply to version 1.0 or 1.0.19870, nor does it change the version of the installation it is applied to.
</p>
<p>
If you would like to upgrade from v1.0.19700 to 1.0.19870 please read the Wiki article on upgrading:
<br />
<a href="http://www.magentocommerce.com/wiki/upgrading_magento">http://www.magentocommerce.com/wiki/upgrading_magento</a>
</p>]]></description>
    <dc:date>2008-05-12 T;21:07:00-08:00</dc:date>
    </item>

    <item>
      <title>Comment by ArthurDent</title>
      <link>{url_as_title}</link>
      <description><![CDATA[<p>It seems to be the patch file for 1.0 to 1.0.9700.
<br />
Where can we find the one for 1.0.9700 to 1.0.9870
</p>]]></description>
    <dc:date>2008-05-12 T;21:07:00-08:00</dc:date>
    </item>

    <item>
      <title>Comment by glaDiator</title>
      <link>{url_as_title}</link>
      <description><![CDATA[<p>great work........keep it up Guys.
</p>]]></description>
    <dc:date>2008-05-12 T;21:07:00-08:00</dc:date>
    </item>

    <item>
      <title>Comment by B00MER</title>
      <link>{url_as_title}</link>
      <description><![CDATA[<p>mysql -u root -p magento_db &gt; backthissuckerup.sql
</p>]]></description>
    <dc:date>2008-05-12 T;21:07:00-08:00</dc:date>
    </item>

    <item>
      <title>Comment by YoavKutner</title>
      <link>{url_as_title}</link>
      <description><![CDATA[<p>@Bloomland  - Can you list the steps you did. I don&#8217;t see how applying the patch can cause this.
</p>
<p>
Thanks
</p>
<p>
yoav
</p>]]></description>
    <dc:date>2008-05-12 T;21:07:00-08:00</dc:date>
    </item>

    <item>
      <title>Comment by Proleter</title>
      <link>{url_as_title}</link>
      <description><![CDATA[<p>That&#8217;s not a bug. We are talking about ten-head dragon. 
<br />
Notified.
<br />
Updated..
<br />
All went well&#8230;
</p>
<p>
Thanks for the info.
</p>]]></description>
    <dc:date>2008-05-12 T;21:07:00-08:00</dc:date>
    </item>

    <item>
      <title>Comment by beau</title>
      <link>{url_as_title}</link>
      <description><![CDATA[<p>Thanks for all your incredible efforts. I continue to be impressed by the work you guys are doing, for free no less, and always trying to provide a great product. Thank you!!!
</p>]]></description>
    <dc:date>2008-05-12 T;21:07:00-08:00</dc:date>
    </item>

    <item>
      <title>Comment by l0st</title>
      <link>{url_as_title}</link>
      <description><![CDATA[<p>Great. I updated this!
</p>]]></description>
    <dc:date>2008-05-12 T;21:07:00-08:00</dc:date>
    </item>

    <item>
      <title>Comment by Bloomland</title>
      <link>{url_as_title}</link>
      <description><![CDATA[<p>When I updated Magento, I had to restart everything almost from scratch. All the images of my products and categories were simple gone. Will there be an easy-to-use update patch in further versions?
</p>]]></description>
    <dc:date>2008-05-12 T;21:07:00-08:00</dc:date>
    </item>

    <item>
      <title>Comment by Ederon</title>
      <link>{url_as_title}</link>
      <description><![CDATA[<p>Does downloadable 1.0.19700 still contain this bug?
</p>]]></description>
    <dc:date>2008-05-12 T;21:07:00-08:00</dc:date>
    </item>

    <item>
      <title>Comment by YoavKutner</title>
      <link>{url_as_title}</link>
      <description><![CDATA[<p>@Did - one of the improvements we were going to add down the road (and it might be done sooner then later) is an RSS notifier that will be present in the admin panel for urgent messages.
</p>
<p>
Thanks
</p>
<p>
yoav
</p>]]></description>
    <dc:date>2008-05-12 T;21:07:00-08:00</dc:date>
    </item>

    <item>
      <title>Comment by Did</title>
      <link>{url_as_title}</link>
      <description><![CDATA[<p>As previously said, you should considered for the coming releases to have the whole magento project as pear packages + security notification in MagentoConnect, or even better as it&#8217;s a critical security info, on the Dashboard.
</p>]]></description>
    <dc:date>2008-05-12 T;21:07:00-08:00</dc:date>
    </item>

    <item>
      <title>Comment by Tesla</title>
      <link>{url_as_title}</link>
      <description><![CDATA[<p>Ahahahahahahahahah! 
<br />
&#8220;The bug will cause products to be deleted completely from the system when a frontend customer adds items to compare products&#8221; That is what I call a bug!
</p>]]></description>
    <dc:date>2008-05-12 T;21:07:00-08:00</dc:date>
    </item>

    <item>
      <title>Comment by Moshe</title>
      <link>{url_as_title}</link>
      <description><![CDATA[<p>@cfs: If you have installed Magento not though MagentoConnect downloader or command line ./pear , then MagentoConnect does not have any indication of what was installed, and re-installs all dependencies for MagentoConnect extension.
</p>]]></description>
    <dc:date>2008-05-12 T;21:07:00-08:00</dc:date>
    </item>

    <item>
      <title>Comment by cfs</title>
      <link>{url_as_title}</link>
      <description><![CDATA[<p>Please, notice that if you install a fresh 1.0.19700, install the patch and then run MagentoConnect to install whatever module, you must install the patch again. Magento connect overwrites the patch. I don&#8217;t know why MagentoConnect reinstall the 1.0.19700 core modules as it was an update, although I installed the latest version.
</p>]]></description>
    <dc:date>2008-05-12 T;21:07:00-08:00</dc:date>
    </item>

    <item>
      <title>Comment by space</title>
      <link>{url_as_title}</link>
      <description><![CDATA[<p>@Ross I agree, but I think we should take it at a step further and have the whole magento project as pear packages, then we could think about setting up auto / or manual updates for critical security issues. This feature will be helpful if you have hundreeds magento to manage et keep them  up to date and avoid spending  hours to apply patches.
</p>]]></description>
    <dc:date>2008-05-12 T;21:07:00-08:00</dc:date>
    </item>

    <item>
      <title>Comment by salsasepp</title>
      <link>{url_as_title}</link>
      <description><![CDATA[<p>From a management viewpoint, everything went smooth here. Something happened, impact was analyzed, swift and proper action was taken and communicated. That&#8217;s one of the reasons why I like Varien: Company and product seem to be managed properly, that&#8217;s my impression here (also after attending the German Meetup). 
</p>
<p>
Management-followup:
<br />
a) Improve the &#8220;action&#8221; part (see suggestions above)
<br />
b) Dig deeper and analyze why this bug has made it into a release and fix the process
</p>
<p>
Cheers!
</p>]]></description>
    <dc:date>2008-05-12 T;21:07:00-08:00</dc:date>
    </item>

    <item>
      <title>Comment by joolsr</title>
      <link>{url_as_title}</link>
      <description><![CDATA[<p>Yes, totally agree with you Ross.
</p>
<p>
Imagine the consequences of the current bug. You are a competitor to a store running Magento. you can anonymously remove most of the items from their store !
</p>
<p>
I guess Magento are considering ways to improve online reporting of updates, most software will do just this. But I think a case like this, where its just sooo easy to do some so damaging, even by accident to your own store really needs highlighting in a major way
</p>]]></description>
    <dc:date>2008-05-12 T;21:07:00-08:00</dc:date>
    </item>

    <item>
      <title>Comment by Ross</title>
      <link>{url_as_title}</link>
      <description><![CDATA[<p>I think it would be good to have important patches like this available in Magento Connect, also they should probably be highlighted with a message upon login to the admin section, e.g.: 
<br />
&#8220;Important security update available, please update your system.&#8221;  
</p>
<p>
This is primarily about communicating to the users who are affected - not everyone is going to be checking the blog frequently.
</p>
<p>
While it is not nice to have to promote defects, with this kind of thing it&#8217;s the better option.
</p>]]></description>
    <dc:date>2008-05-12 T;21:07:00-08:00</dc:date>
    </item>

    <item>
      <title>Comment by joolsr</title>
      <link>{url_as_title}</link>
      <description><![CDATA[<p>But yes, this is EXTREMELY serious IMHO.
</p>
<p>
ok, its not a method of defrauding someone&#8217;s ecommerce shop, but the ease of use to do something damaging - is ridiculously easy !
</p>]]></description>
    <dc:date>2008-05-12 T;21:07:00-08:00</dc:date>
    </item>

    <item>
      <title>Comment by joolsr</title>
      <link>{url_as_title}</link>
      <description><![CDATA[<p>@Yoav, was I the person who reported it to you first? Bug report 4639, from 18.00 GMT
</p>
<p>
Even though, I lost a few products, at least I can feel good that I help magento in a fairly major way ... <img src="http://www.magentocommerce.com/images/smileys/grin.gif" width="19" height="19" alt="grin" style="border:0;padding:0;" />
</p>]]></description>
    <dc:date>2008-05-12 T;21:07:00-08:00</dc:date>
    </item>

    <item>
      <title>Comment by space</title>
      <link>{url_as_title}</link>
      <description><![CDATA[<p>@Yoav :&nbsp; Hello, following this kind  of issues  I have two questions : 
</p>
<p>
Is there any plan to provide us a svn branch &#8220;latest Release + bug fixes only &#8220;  ? 
<br />
   then we could automatise the process ( svn update and deploy all changes )
<br />
        
<br />
When I&#8217;m using the svn 1.0-trunk (  <a href="http://svn.magentocommerce.com/source/branches/1.0-trunk/">http://svn.magentocommerce.com/source/branches/1.0-trunk/</a> ), it seems that we have the revision 19722. but svn log  is empty. And this patch has not been deploy into this &#8220;branch&#8221; :
</p>
<p>
# diff CompareController.php CompareController.php.new
<br />
118c118,123
<br />
&lt;         $items-&gt;walk(&#8217;delete&#8217;);
<br />
---
<br />
&gt;         //$items-&gt;walk(&#8217;delete&#8217;);
<br />
&gt;         $compareItem = Mage::getModel(&#8217;catalog/product_compare_item&#8217;);
<br />
&gt;         foreach ($items as $item) &#123;
<br />
&gt;             $compareItem-&gt;setId($item-&gt;getCatalogCompareItemId())
<br />
&gt;                 -&gt;delete();
<br />
&gt;         &#125;
</p>
<p>
Is there any plan to have any kind of comments available for us ?&nbsp; That could be helpful <img src="http://www.magentocommerce.com/images/smileys/smile.gif" width="19" height="19" alt="smile" style="border:0;padding:0;" />
</p>
<p>
Thank you
</p>]]></description>
    <dc:date>2008-05-12 T;21:07:00-08:00</dc:date>
    </item>

    <item>
      <title>Comment by YoavKutner</title>
      <link>{url_as_title}</link>
      <description><![CDATA[<p>@Mootrealm - patches should be applied manually. Between minor releases as soon as a number of patches and/or bug fixes accumulate we will release another revision to an existing minor release.
</p>
<p>
Thanks
</p>
<p>
yoav
</p>]]></description>
    <dc:date>2008-05-12 T;21:07:00-08:00</dc:date>
    </item>

    <item>
      <title>Comment by Mootrealm</title>
      <link>{url_as_title}</link>
      <description><![CDATA[<p>@WebAddict - I wouldn&#8217;t call it a security hole. 
</p>
<p>
@YoavKutner - this patch can only be applied manually and not through the admin with a pear update?
</p>]]></description>
    <dc:date>2008-05-12 T;21:07:00-08:00</dc:date>
    </item>

    <item>
      <title>Comment by YoavKutner</title>
      <link>{url_as_title}</link>
      <description><![CDATA[<p>@WebAddict - We are constantly testing Magento and look into community reported bugs, and so far this was the only major bug found. 
</p>
<p>
Thanks
</p>
<p>
yoav
</p>]]></description>
    <dc:date>2008-05-12 T;21:07:00-08:00</dc:date>
    </item>

    <item>
      <title>Comment by WebAddict</title>
      <link>{url_as_title}</link>
      <description><![CDATA[<p>That&#8217;s a pretty serious bug&#8230; I hope there are no other security holes like this.
</p>]]></description>
    <dc:date>2008-05-12 T;21:07:00-08:00</dc:date>
    </item>


</channel>
</rss>