Register Members List Search Today's Posts Mark Forums Read

Closed Thread
 
Thread Tools
  #1  
Old 05 Mar 2009, 13:10
vB.Org System vB.Org System is offline
 
Join Date: Aug 2007
vBulletin 3.8.1 PL1, 3.7.5 PL1 and 3.6.12 PL1 Released

vBulletin 3.8.1 PL1 / 3.7.5 PL1 / 3.6.12 PL1

An XSS flaw within the editor controls has recently been discovered. This could allow an attacker to carry out an action as a user or obtain access to a user's account. To resolve this issue, it is necessary to release a patch level version of the active versions of vBulletin.

The upgrade process is the same as previous patch level releases - simply download the patch from the Members Area, extract the files and upload to your webserver, overwriting the existing files. There is no upgrade script required.

As with all security-based releases, we recommend that all customers upgrade as soon as possible in order to prevent any potential damage resulting from the flaw being exploited.


Upgrading from 3.8.1, 3.7.5 or 3.6.12

If you are already running the latest version of the 3.6, 3.7 or 3.8 branch, the process you will be required to follow to make your board immune to this flaw is very simple.

There is no need to run an upgrade script if you are already running the latest version.

Visit the Patches section of the vBulletin Members' Area and download the patch for the version you are using, then extract the files from the archive you downloaded, then upload the files to your board via FTP etc., overwriting the existing files. This will update your version to the PL1 release.


Upgrading from an earlier version

If you are not already running the latest version of 3.6, 3.7 or 3.8, you should download the latest version from the Members' Area and perform an upgrade as normal.

Full instructions for upgrading vBulletin are available here.


Download vBulletin 3.8.1 PL1 / 3.7.5 PL1 / 3.6.12 PL1

As usual, the version released today is available for all customers with valid, active licenses to download from the vBulletin Members' Area.

vBulletin Members Area

Please do not use this thread for support questions.

More...

Last edited by Marco van Herwaarden; 05 Mar 2009 at 14:33.
  #2  
Old 05 Mar 2009, 13:51
Jasem's Avatar
Jasem Jasem is offline
 
Join Date: Feb 2006
Location: www.menokia.com
many thanks

Installed!
__________________
games
Forum Nokia

Last edited by Jasem; 05 Mar 2009 at 15:17.
  #3  
Old 05 Mar 2009, 14:19
projectego's Avatar
projectego projectego is offline
 
Join Date: Feb 2006
Location: UK
Real name: Steve
/me goes to upgrade

Fortunately I have the remainder of the evening to myself so I can take my time with this.
__________________
  #4  
Old 05 Mar 2009, 14:51
itsheinz itsheinz is offline
 
Join Date: Feb 2009
Installed! Thanks vbulletin^^
  #5  
Old 05 Mar 2009, 14:54
TNCclubman's Avatar
TNCclubman TNCclubman is offline
 
Join Date: Sep 2008
Downloaded and patched thanks.

(Since this is my first license, just to confirm, when my license expires in 7 months and a patch comes out, is it my understanding then that my board will be vulnerable to hackers if I dont renew my license?)
  #6  
Old 05 Mar 2009, 18:13
Lasthero Lasthero is offline
 
Join Date: Dec 2008
thanks for patch..
  #7  
Old 05 Mar 2009, 19:54
steve1966 steve1966 is offline
 
Join Date: Dec 2007
Thanks
  #8  
Old 06 Mar 2009, 04:09
as7apcool's Avatar
as7apcool as7apcool is offline
 
Join Date: Feb 2009
installed
  #9  
Old 06 Mar 2009, 04:30
Shazz's Avatar
Shazz Shazz is offline
 
Join Date: Jun 2006
Location: Utah
Real name: Shawn
Patches are easily fixed
  #10  
Old 07 Mar 2009, 00:31
Sweeks's Avatar
Sweeks Sweeks is offline
 
Join Date: Jul 2008
Why does it mention the security bug here but not on vbulletin.com at all? Unless im missing it.
  #11  
Old 07 Mar 2009, 04:02
BSMedia BSMedia is offline
 
Join Date: Feb 2009
Thanks, just read this and upgraded!
  #12  
Old 07 Mar 2009, 04:08
KevinL KevinL is offline
 
Join Date: Apr 2005
Originally Posted by Sweeks View Post
Why does it mention the security bug here but not on vbulletin.com at all? Unless im missing it.
Click the "more" in the first post here...it will bring you to the post at .com...
  #13  
Old 09 Mar 2009, 09:25
hvb hvb is offline
 
Join Date: Dec 2006
Hi, We are still on 3.7.0. and I have two questions:
1. Do we need this patch? (I can assume that these editor controls are added after 3.7.0)
2. Where can I find information about this patch? Because between 3.7.0 and 3.7.1.PL2 there are a lot of differences which are not all related to this patch.
I need to know which codelines in the affected files are added to address this XSS flaw.
Who can help me with this?
  #14  
Old 09 Mar 2009, 09:49
Marco van Herwaarden Marco van Herwaarden is offline
 
Join Date: Jul 2004
There have been a few security updates since 3.7.0. You should do a full upgrade to the latest version,
__________________
Marco van Herwaarden
Ex vBulletin.org Coordinator
  #15  
Old 09 Mar 2009, 14:22
hvb hvb is offline
 
Join Date: Dec 2006
Originally Posted by Marco van Herwaarden View Post
There have been a few security updates since 3.7.0. You should do a full upgrade to the latest version,
Thanks for answering Marco, but that is not really an answer to my question.
Is the information that I ask for not available?
Closed Thread



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off


New To Site? Need Help?

All times are GMT. The time now is 15:38.

Layout Options | Width: Wide Color: