I’ve got two Magento stores and read that there is an important security problem that has been revealed.
I have downloaded the patch files, but cannot seem to understand how to patch the files properly, one store has hosting with SSH access – but the other doesn’t.
How can I patch the files properly on each machine?
Source. http://www.magentocommerce.com/blog/comments/important-security-update-zend-platform-vulnerability/
There are a couple of ways you can go about fixing your issue,
For your server with SSH
Here is an example as to how to apply the patch file via SSH for a 1.4 store
Here are the URLs for each patch,
For your server WITHOUT SSH
We have downloaded all the installations and pre-patched the files for people that don’t have access to command line or the
patchapplication. The contents of the files are far too big to post on here, but you can download them direct from our siteCommunity Edition 1.4.0.0 through 1.4.1.1
Community Edition 1.4.2.0
Community Edition 1.5.0.0 through 1.7.0.1
For more information
We’ve posted an explanation about the issue and a solution on our own website, http://www.sonassi.com/knowledge-base/magento-kb/important-magento-security-update-zend-platform-vulnerability/