Register Members List Search Today's Posts Mark Forums Read

Closed Thread
 
Thread Tools
  #1  
Old 18 Aug 2008, 10:30
vB.Org System vB.Org System is offline
 
Join Date: Aug 2007
vBulletin 3.7.2 PL2 and 3.6.10 PL4 Released

vBulletin 3.7.2 PL2 / vBulletin 3.6.10 PL4

An XSS flaw related to JavaScript escaping has been identified. This could allow an attacker to carry out an action as a user or obtain access to a user's account. To resolve this issue, it is necessary to release patch level versions of vBulletin 3.7.2 and 3.6.10.

This flaw was discovered by Federico Muttis.

The upgrade process is the same as previous patch level releases - simply download the patch from the Members Area, extract the files and upload to your webserver, overwriting the existing files. There is no upgrade script required.

As with all security-based releases, we recommend that all customers upgrade as soon as possible in order to prevent any potential damage resulting from the flaw being exploited.


vBulletin 3.7.3 and 3.6.11 to be Released Next Week

In line with our new scheduled maintenance release policy, a new release for 3.6 and 3.7 will be made on Tuesday, August 26th.

These releases will contain bug fixes, but will also address a situation related to users that use their username as their password. In 3.6.11 and 3.7.3, this will be completely disallowed. Users affected by this will be forced to change their password on their first login. Additionally, a tool will be provided to email affected users with a new password. Please be aware of these potential compatibility changes when upgrading.

This release will be mentioned in the security bulletin sent out to customers today, but we will not send a further notification next week when 3.7.3 and 3.6.11 are released. Watch your Admin CP News, or the latest version check in the Admin CP to see when the new version is available. Alternatively, keep an eye on this forum for the 3.7.3 and 3.6.11 announcements.


Upgrading from 3.7.2, 3.6.10 or their patch level versions

If you are already running 3.7.2, 3.6.10 or their patch level versions, the process you will be required to follow to make your board immune to the XSS problem is very simple.

There is no need to run an upgrade script if you are already running 3.7.2, 3.6.10 or their patch level versions.

Visit the Patches section of the vBulletin Members' Area and download either the patch for 3.7.2, or the patch for 3.6.10, according to the version you are currently running, then extract the files from the archive you downloaded, then upload the files to your board via FTP etc., overwriting the existing files. This will update your version to the PL1 or PL3 release respectively.

The 3.7.2 PL2 patch file includes the PL1 fix.
The 3.6.10 PL4 patch file also includes the PL1, PL2, and PL3 fixes.


Upgrading from Versions Earlier than 3.7.2 or 3.6.10

If you are not already running 3.7.2 or 3.6.10, you should download the most latest version from the Members' Area and perform an upgrade as normal.

Full instructions for upgrading vBulletin are available here.


Download vBulletin 3.7.2 PL2 or 3.6.10 PL4

As usual, both versions released today are available for all customers with valid, active licenses to download from the vBulletin Members' Area.

vBulletin Members Area


More...

Last edited by Marco van Herwaarden; 18 Aug 2008 at 12:09.
  #2  
Old 18 Aug 2008, 10:37
cheat-master30's Avatar
cheat-master30 cheat-master30 is offline
 
Join Date: Mar 2007
Location: Information Classified
Real name: cheat-master30
Thanks for the update, improved security is always nice.
__________________
Proud vBulletin supporter (cheat-master30 at official forum)
DS Ultimate- A Great Nintendo DS forum-
My Nintendo DS forum covering Mario Kart DS, Super Mario 64 DS and the like. Powered by the amazing vBulletin 3.7 software.
  #3  
Old 18 Aug 2008, 11:07
projectego's Avatar
projectego projectego is offline
 
Join Date: Feb 2006
Location: UK
Real name: Steve
/me upgrades right away
__________________
  #4  
Old 18 Aug 2008, 12:21
Spank Spank is offline
 
Join Date: Jan 2007
Real name: Mark
Nice to see vbulletin is on the ball with the security issues. The username being the same as the password has caused quite a few problems for a few people that have posted about it at vb.com.
  #5  
Old 18 Aug 2008, 16:57
nascartr nascartr is offline
 
Join Date: Jun 2008
Just a quick question...will updating these files overwrite any customizing done to the original templates? If so, is there an easier way to upgrade without having to redo the templates?
  #6  
Old 18 Aug 2008, 17:10
Marco van Herwaarden Marco van Herwaarden is offline
 
Join Date: Jul 2004
Overwriting files will not change any templates.
__________________
Marco van Herwaarden
Ex vBulletin.org Coordinator
  #7  
Old 18 Aug 2008, 21:09
iogames's Avatar
iogames iogames is offline
 
Join Date: Jan 2007
Real name: Josh Arcadia
No-waaay!

p.s. Thanks Federico
__________________
. █│║▌│█│║▌║│█║▌│║║█║
  #8  
Old 18 Aug 2008, 22:47
bizhat bizhat is offline
 
Join Date: Aug 2008
It is my first vbulletin upgrade. vBulletin 3.7.2 PL1 to PL2, it was easier then i thought.
  #9  
Old 19 Aug 2008, 02:28
Vackrick Vackrick is offline
 
Join Date: Apr 2008
Real name: Matt
Yeah^^^
  #10  
Old 19 Aug 2008, 16:19
ThorstenA's Avatar
ThorstenA ThorstenA is offline
 
Join Date: Nov 2004
I only noticed now that vbulletin.org is running vbulletin 3.6. Is there a reason for not-upgrading?
  #11  
Old 19 Aug 2008, 18:36
cheat-master30's Avatar
cheat-master30 cheat-master30 is offline
 
Join Date: Mar 2007
Location: Information Classified
Real name: cheat-master30
I hear they are upgrading, but it's taking longer because vBulletin.org has a lot of custom modifications and programming that needs to be migrated over to 3.7 before the upgrade can technically be run/fully complete.
__________________
Proud vBulletin supporter (cheat-master30 at official forum)
DS Ultimate- A Great Nintendo DS forum-
My Nintendo DS forum covering Mario Kart DS, Super Mario 64 DS and the like. Powered by the amazing vBulletin 3.7 software.
  #12  
Old 19 Aug 2008, 19:44
Brandon Sheley's Avatar
Brandon Sheley Brandon Sheley is offline
 
Join Date: Mar 2005
Real name: Brandon
I'm just happy vb.org upgraded past 3.5 finally
__________________

Email me for website help: brandon[at]sheley[dot]org
  #13  
Old 19 Aug 2008, 23:25
King Kovifor's Avatar
King Kovifor King Kovifor is offline
 
Join Date: Nov 2004
Real name: Jeremy
There are several threads in the feedback forum about this topic, please see those.
__________________
Former vBulletin.org Staff Member

Do not request support through any other means except the forums.

Useful Post With Links on Learning How To Develop vBulletin Plugins

Latest Modification: Stop Forum Spam Integration
  #14  
Old 20 Aug 2008, 09:20
ThorstenA's Avatar
ThorstenA ThorstenA is offline
 
Join Date: Nov 2004
Originally Posted by King Kovifor View Post
There are several threads in the feedback forum about this topic, please see those.
As this is official discussion thread about new vbulletin 3.7.2 PL 2 I was asking here vbulletin.org is property of jelsoft, too. I am just curious why they did not adopt newest version.
  #15  
Old 20 Aug 2008, 09:38
Marco van Herwaarden Marco van Herwaarden is offline
 
Join Date: Jul 2004
This thread is to discuss the release, not the implementation on vB.org. For this we have the vBulletin.org Site Feedback, where this topic is already covered in a few threads.
__________________
Marco van Herwaarden
Ex vBulletin.org Coordinator
Closed Thread



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off


New To Site? Need Help?

All times are GMT. The time now is 20:53.

Layout Options | Width: Wide Color: