Release Notes
SECURITY [HIGH] Fixed security hole in reset logic to check for proper token length-
Manual Installation
For some users a manual installation of the 1.5.6 Security Patch is a faster process. To manually apply the 1.5.6 Security Patch, upload the following files, replacing the existing files:
/components/com_user/models/reset.php
/changelog.php
/includes/framework.php
/administrator/includes/framework.php
/libraries/joomla/version.php
/libraries/joomla/environment/uri.php
This patch will only update installations of Joomla 1.5.5. If you're using an earlier version, it is recommended you update prior to updating these files.