Try the Demo

Magento Forum

   
1.5.0.1 deployment question
 
mrichardson
Jr. Member
 
Total Posts:  2
Joined:  2012-07-06
 

Hi, I hope this is the right forum for my question.

We have been working on a Magento implementation for about a year. We’re on version 1.5.1.0 rather than the latest and greatest, as that was the current release back when development started.

We’re ready to go live with 1.5.1.0, with a view to possibly upgrading at a later date, but first I wanted to make sure the current release of 1.5.1.0 does not have any known security vulnerabilities that were fixed in later editions. (My presumption is this is not the case)

Judging by the security blog (http://www.magentocommerce.com/blog/category/security-updates/), there has only been one security issue identified since 2009, and there is a patch available for it (although the patch does not seem to have made itself into the actual 1.5 download package, which I also grabbed today to compare with our version).

Assuming I apply this patch to our version of 1.5.1.0, are we good to go live with no risk of getting exploited?

Thanks

 
Magento Community Magento Community
Magento Community
Magento Community
 
kab8609
Enthusiast
 
Avatar
Total Posts:  775
Joined:  2009-04-07
Cleveland
 
mrichardson - 06 July 2012 08:17 AM

Hi, I hope this is the right forum for my question.

We have been working on a Magento implementation for about a year. We’re on version 1.5.1.0 rather than the latest and greatest, as that was the current release back when development started.

We’re ready to go live with 1.5.1.0, with a view to possibly upgrading at a later date, but first I wanted to make sure the current release of 1.5.1.0 does not have any known security vulnerabilities that were fixed in later editions. (My presumption is this is not the case)

Judging by the security blog (http://www.magentocommerce.com/blog/category/security-updates/), there has only been one security issue identified since 2009, and there is a patch available for it (although the patch does not seem to have made itself into the actual 1.5 download package, which I also grabbed today to compare with our version).

Assuming I apply this patch to our version of 1.5.1.0, are we good to go live with no risk of getting exploited?

Thanks

Every release since 1.5.0.1 has identified security issues. Please read the release notes http://www.magentocommerce.com/download/release_notes

Look for things like: Fixed: Several potential security vulnerabilities

So to answer your question, you are at risk of getting exploited. If you correctly coded your site, including best practices like not overriding core code, theming correct, etc. An upgrade to 1.7.0.2 would take 8-20 hours including debugging time.

Just from my experience, i’ve had upgrades take 80 hours (the sites were poorly coded, many overwrites, files missing, etc) and i’ve had upgrades take just 3 hours. I do them every week. However it is urgent that you create a update plan. You should never be more then 1-2 updates behind (your 7 updates behind).

 Signature 

Kris Brown
Magento Certified Developer

I work at Briteskies, a Magento Solutions Partner.

Magento CE Sites Built to Date for Clients: 26
Magento EE Sites Built to Date for Clients: 5
Magento Extensions Built to Date for Clients: 13

Don’t edit core code...

 
Magento Community Magento Community
Magento Community
Magento Community
 
anhnongcuasao
Jr. Member
 
Total Posts:  2
Joined:  2012-07-11
 

Thank for share

 Signature 

Anh nong, Bang gia ve may bay, ceo, phan mem crack, http://www.vemaybayword.com/, http://www.cameraquansatword.com/

 
Magento Community Magento Community
Magento Community
Magento Community
 
denlednw01
Jr. Member
 
Total Posts:  3
Joined:  2012-10-08
 

Thanks for share
This post is useful for me

 Signature 

Tencel Shop- phân phối, bán buôn bán lẻ các loại chăn ga gối đệm chất liệu Tencel, Cotton và các chất liệu cao cấp khác: Chăn ga gối đệm
Công ty Megaman.vn chuyên cung cấp bóng đèn tiết kiệm, đèn led, đèn trang trí, bóng tiết kiệm các loại: Đèn led trang trí

 
Magento Community Magento Community
Magento Community
Magento Community
Magento Community
Magento Community
    Back to top