vBulletin

Thank you for visiting. This is our website archive. Please visit our main website by clicking the banner above.
vBulletin FAQ is dedicated to helping the forum owner build, manage and profit from his vBulletin Forum
vBulletin Web Hosting - Free skins and styles for your vBulletin - Search Engine Optimization




vBulletin released additional update for 3.6.7

Joeychgo
05-16-2007, 11:31 AM
It would appear that the XSS that necessitated the release of 3.6.7 extends to another system we did not appreciate at the time of the release.

Therefore, here are a further set of patches and plugins for you to apply.

Here are your options, depending on the version of vBulletin you are currently running.

Currently running vBulletin 3.6.7
Either:
Download the patch for 3.6.7 from the members' area (http://members.vbulletin.com/patches.php) (or this thread - 367_patch.zip) and upload the contents to your forum directory
Apply the plugin vb_367_xss_fix_plugin.xml attached to this threadThose using vBulletin 3.6.7 can make use of the new Patch Level release system, which allows the correct version number to be displayed in the admin control panel - with the patch applied, your version number in the ACP will reflect the fact that you are now running 3.6.7 PL1.

Currently running vBulletin 3.6.4, 3.6.5 or 3.6.6
Either:
Upgrade to the new vBulletin 3.6.7 package available in the members' area (http://members.vbulletin.com/)
Download the patch for 3.6.6 available in the members' area (http://members.vbulletin.com/patches.php) (or this thread - 366_patch.zip) and upload the contents to your forum directory
Apply the plugin vb_366_xss_fix_plugin.xml attached to this threadCurrently running vBulletin 3.6.x older than 3.6.4
Either:
Upgrade to the vBulletin 3.6.7 package available in the members' area (http://members.vbulletin.com/)
Apply the plugin vb_366_xss_fix_plugin.xml attached to this threadOnce again, we are sorry that this latest problem has occurred. We are looking into ways to ensure that this sort of thing does not happen again.

Please see the original announcement for the patch files: http://www.vbulletin.com/forum/showp...10&postcount=6 (http://www.vbulletin.com/forum/showpost.php?p=1355810&postcount=6)


More... (http://www.vbulletin.org/forum/showthread.php?t=147395&goto=newpost)

Peggy
05-16-2007, 11:54 AM
Oh for the love of Pete....... :rolleyes:

Joeychgo
05-16-2007, 11:55 AM
Told ya so... :) Im still expecting another update..

Peggy
05-16-2007, 11:56 AM
One more I told ya so and yer gonna get it Pal.... :mad:

Hell³
05-16-2007, 12:10 PM
Ok, for the moment, I used the plugin, which is a product, by the way. Use the product manager to upload it.

That's my only gripe, if they named the darned things, then at least they should use the appropriate names.

Joeychgo
05-16-2007, 12:46 PM
Ok, for the moment, I used the plugin, which is a product, by the way. Use the product manager to upload it.

That's my only gripe, if they named the darned things, then at least they should use the appropriate names.


I noticed that myself. Where's Paul? I wanna point that out to him :)

Peggy
05-16-2007, 12:58 PM
He knows... I think it was he that said something about it on .com
Then again, maybe not. Hell who knows. These upgrades have my head spinning...

Big Dan
05-16-2007, 03:16 PM
I think I'm gonna rip my hair out or someone elses' :D

At least this one was painless, I did it all from the command line.

Peggy
05-16-2007, 04:09 PM
I think I'm gonna rip my hair out or someone elses' :D

At least this one was painless, I did it all from the command line.
I've done 7 of them, so far... :)

Mike54
05-16-2007, 04:23 PM
Just keep telling yourselves it is better to invest a few minutes of time to have a secure forum, rather than have Jelsoft ignore a vulnerability.

Of course throwing things across the room in frustration is allowed, as well.

(Peggy, I would certainly appreciate you not pointing out that I had made earlier comment about what today might hold in the way of upgrades. :innocent: Just in case, I think I'll be going for my coat now. )

Hell³
05-16-2007, 04:46 PM
Pegs said she would do next day's upgrade with a smile... I hope she's complying ;)

Mike54
05-16-2007, 04:55 PM
Pegs said she would do next day's upgrade with a smile... I hope she's complying ;)
That's right, she did say that.

That's me, hiding Peggy's coat! :p

Peggy
05-16-2007, 09:13 PM
How would you two like a spanking?!?

Joeychgo
05-16-2007, 09:45 PM
http://www.cowboyscentral.com/bb/images/smilies/spanking.gif



Ill just watch..

Peggy
05-16-2007, 09:48 PM
yeah yeah, you keep it up with the "I told ya so's" and you're liable to get one too, mister.


Oh wait, you'd probably enjoy it. Gotta think of something else.... :rolleyes:

Hell³
05-17-2007, 12:32 AM
whew... after three vbulletin, one mybb, and one wordpress upgrades on the last 5 days... I'm beat.

Dave A
05-17-2007, 01:12 AM
This makes you wonder about the download manager problem. Perhaps vB stopped downloads because there were still issues to resolve. About the only way to handle it, I think.

Now if I've got this right, I need to uninstall the old 3.6.7 patch and install the new one.

Joey's sit-tight policy is starting to look well and truly justified. I used to do the same myself, but the run through from 3.6.0 to 3.6.5 was reasonably "unbuggy", so this time I took the plunge straight away.

I must say in defence of vB, I don't think my members have been affected by any issues as a result of this upgrade drama. And I'm so pleased we can solve the issues with the product manager.

Lessons learnt all round, I'm sure.

Mike54
05-17-2007, 04:08 AM
Ill just watch..
She's liable to get a cover charge. :D

Peggy
05-17-2007, 04:08 AM
Nope you do not need to uninstall the patch! The upgrade deletes, or overwrites, it.

Peggy
05-17-2007, 04:09 AM
She's liable to get a cover charge. :D
at least I get the sweet "end" of the deal in both cases ;)


vBulletin

seo book

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35

EZ Archive Ads Plugin for vBulletin Copyright 2006 Computer Help Forum