vBulletin

Thank you for visiting. This is our website archive. Please visit our main website by clicking the banner above.
vBulletin FAQ is dedicated to helping the forum owner build, manage and profit from his vBulletin Forum
vBulletin Web Hosting - Free skins and styles for your vBulletin - Search Engine Optimization




vBulletin 3.6.5 Released

Joeychgo
03-01-2007, 08:00 AM
vBulletin 3.6.5

This morning, an exploit was reported, which affects vBulletin versions 3.5.x and 3.6.x. Although the report is inaccurate and the published exploit does not work as claimed unless a highly unlikely set of circumstances exist, it has highlighted a potential security issue in these vBulletin versions.

Therefore, we have decided to release updated versions, these being vBulletin 3.5.8 and 3.6.5. We recommend that all customers running vBulletin 3.5.x or 3.6.x upgrade to the appropriate version or apply the supplied patch as soon as possible.

It is worth noting that in order to exploit the problem highlighted by the report, the attacking user must satisfy the following conditions:
Must already have moderator privileges
Must share the same IP address (or the number of IP octets specified in the Admin Control Panel for IP address matching) with an existing administrator who is currently logged in to the Admin Control Panel
Must know the Alt-IP and user agent (exact browser identification) of the administrator
OR must know the license number of the site being attackedGiven these requirements, the privilege escalation exploit claimed by the report is almost impossible to achieve.



Bugs Fixed in vBulletin 3.6.5

The Security FlawThe reported security flaw described in this announcement, which could potentially allow a SELECT query to be hijacked, has been addressed.Safari CookiesA problem where users of the Apple browser Safari would be logged off the system prematurely when vBulletin runs on specific servers has been resolved.
More info... (http://www.vbulletin.com/forum/bugs36.php?do=view&bugid=1116)Internet Explorer 7 CompatabilityMuch has been said about Microsoft's decision to make the Javascript prompt() function throw a security warning whenever it is called. This change resulted in vBulletin's text editor system throwing security warnings whenever a user tried to insert an image or an email link. The use of prompt() for Internet Explorer 7 users has now been discontinued in favour of an alternative method of collecting user input.
More info... (http://www.vbulletin.com/forum/bugs36.php?do=view&bugid=1263)

Additionally, improvements in Internet Explorer 7 mean that certain aspects of the vBulletin pop-up menu system, which were previously required to circumvent rendering issues, can now be bypassed. Most notable amongst these is the code that hides all elements that would intersect with the menu when opened.Fix for Infractions BugA problem where infraction expiration was not cleaned-up properly has been addressed.
More info... (http://www.vbulletin.com/forum/bugs36.php?do=view&bugid=1448)Workaround for a FreeBSD Regular Expression Error on LoginSome users running recent versions of PHP running on FreeBSD have encountered a bug in the regular expression engine that caused an error to be shown when logging in. We have worked around this problem. However, it may still appear in other areas, so we are trying to find a proper fix for the issue.

Updating your vBulletin to Fix the Potential Exploit

There are two ways in which you can fix the potential exploit in your version of vBulletin:
Full Upgrade: The best way to fix the problem is to perform a full upgrade by downloading the complete 3.6.5 package from the vBulletin Members' Area (http://members.vbulletin.com/) and following the regular upgrade instructions (http://www.vbulletin.com/docs/html/upgrade?manualversion=30602500).
Patch: A second option is to download the patch files discussed in this thread and upload them to your web server, overwriting the existing files. The patch is available from the Members' Area patch page (http://members.vbulletin.com/patches.php) or you can find it attached to this thread.Please note that vBulletin 3.6.5 requires at least PHP 4.3.3 and MySQL 4.0.16 or later.



A Note Regarding vBulletin 3.6.6

The publication of this exploit has required a swift release of an updated version to fix the published problem. The original intention for vBulletin 3.6.5 had been to include a number of other bug fixes and improvements that have been reported since 3.6.4.

Unfortunately, the necessity of bringing out a version quickly to fix the exploit has meant that many of these fixes have not had sufficient time to be fully tested to the extent that we would like and have therefore been kept back for vBulletin 3.6.6.

We understand that this may be frustrating to our customers, and in order to minimize the inconvenience, we have ensured that this vBulletin 3.6.5 release contains no template or phrase changes, which will hopefully make upgrading as painless as possible.


More... (http://www.vbulletin.com/forum/showthread.php?t=221905&goto=newpost)

dakar
03-01-2007, 08:24 AM
I was just renewing my license and noticed it said latest was 3.6.5.... caught me off gaurd since VB's mailing list apparently hasn't been run through yet.

Peggy
03-01-2007, 09:42 AM
I just got home and found this in my email. I'll be upgrading here shortly.

Hell³
03-01-2007, 10:04 AM
no template changes? that's my kind of upgrade...

PoorMsJac
03-01-2007, 02:50 PM
no template changes? that's my kind of upgrade...

Ha! I hear ya - ALSO thanx to vB-FAQ for the notification.
Gonna upgrade right now ;)

Jacquii.

Joeychgo
03-01-2007, 03:01 PM
Yeah, vB isnt very good at notifying about these things, so I try to send an email out as soon as I hear about an upgrade.

Loco.M
03-03-2007, 09:38 PM
I just applied the patch on my sites.. There will be another upgrade shortly to 3.6.6

Peggy
03-03-2007, 11:02 PM
Agreed, that's why I haven't upgraded either. They're aleady talking about another upgrade..

mrsmac1974
03-04-2007, 12:11 PM
They're aleady talking about another upgrade..
:p Well ... I'll just say it was a good learning experience for me. My first upgrade (which forced me to do my first manual backup) ... and the board survived. Me? If I were a drinker, I'd have had one or two after it all. :raisin: :D

Peggy
03-04-2007, 12:36 PM
LOLOL... I hear that alot. "Pass me a drink"! haha
I've changed my AV to celebrate your achievement! :D

mrsmac1974
03-04-2007, 02:53 PM
Here's back atcha! http://spatulagraphics.com/smilies/kwine.gif

Hell³
03-05-2007, 02:12 AM
Theres really no reason to not doing a full upgrade, it was fairly straightforward since there are no template updates. So it's juts a matter of personal preference.

Peggy
03-05-2007, 04:33 AM
I went ahead and did the upgrade... my two sites and 5 other sites :rolleyes:
Took longer to upload the package than it did to run the script.

Went smoooooooooooth as a baby's tooshie :D

mrsmac1974
03-05-2007, 11:05 AM
Way to go, Peggy!

It's still morning, so I'll hoist my coffee cup atcha for a job well done. :)

Peggy
03-05-2007, 11:10 AM
Thank ya!

It's 2pm here and I'm still drinking coffee, lol


vBulletin

seo book

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35

EZ Archive Ads Plugin for vBulletin Copyright 2006 Computer Help Forum