Open Source digg-clone Pligg plugs security holes | Internet News

Open Source digg-clone Pligg plugs security holes

Dec 1, 2009
1 minute read

pligg_small.gif

From the

Web Apps at Risk

files:

Pligg, which is an open source attempt at a Digg-like social networking voting site application is being updated this week for some serious security vulnerabilities.

As opposed to many other vendors/projects which typically release an update alongside security advisories, that’s not the case with the new Pligg 1.0.3 release. The full security advisory isn’t coming out until tomorrow (Dec 2) giving Pligg users (and there are a whole lot of them) a running head start on potential attacks.

Security researchers from firms big and small have been saying for the
last few years that it is web applications that pose the greatest
security risk to users.  That’s because an attacker only need take
advantage of one site to infect potentially thousands of the infected
site’s users.

“Shortly after the 1.0.2 release we were alerted to a vulnerability reported by Secunia and third party researcher Russ McRee,” the Pligg blog states.

I think fixing before advising is the right approach both for Pligg and quite frankly for all applications. It’s always a race between hackers and users whenever a patch comes out at the same time as an advisory.

Internet News Logo

InternetNews is a source of industry news and intelligence for IT professionals from all branches of the technology world. InternetNews focuses on helping professionals grow their knowledge base and authority in their field with the top news and trends in Software, IT Management, Networking & Communications, and Small Business.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.