Go Back   vBulletin Setup > General Forums > Official vBulletin Announcements

Reply 
 
LinkBack Thread Tools Display Modes
Old 03-01-2007, 10:30 AM   #1
Community Manager
Supporters
vBulletin Owner
vBSetup Mods
 
Brandon Sheley's Avatar
 
Join Date: Jul 2006
Location: Topeka, KS
Posts: 14,080
Blog Entries: 35
Brandon Sheley is a splendid one to beholdBrandon Sheley is a splendid one to beholdBrandon Sheley is a splendid one to beholdBrandon Sheley is a splendid one to beholdBrandon Sheley is a splendid one to beholdBrandon Sheley is a splendid one to behold
Send a message via AIM to Brandon Sheley Send a message via MSN to Brandon Sheley Send a message via Yahoo to Brandon Sheley
vBulletin 3.6.5 Released

vBulletin 3.6.5

This morning, an exploit was reported, which affects vBulletin versions 3.5.x and 3.6.x. Although the report is inaccurate and the published exploit does not work as claimed unless a highly unlikely set of circumstances exist, it has highlighted a potential security issue in these vBulletin versions.

Therefore, we have decided to release updated versions, these being vBulletin 3.5.8 and 3.6.5. We recommend that all customers running vBulletin 3.5.x or 3.6.x upgrade to the appropriate version or apply the supplied patch as soon as possible.

It is worth noting that in order to exploit the problem highlighted by the report, the attacking user must satisfy the following conditions:
  • Must already have moderator privileges
  • Must share the same IP address (or the number of IP octets specified in the Admin Control Panel for IP address matching) with an existing administrator who is currently logged in to the Admin Control Panel
  • Must know the Alt-IP and user agent (exact browser identification) of the administrator
  • OR must know the license number of the site being attacked
Given these requirements, the privilege escalation exploit claimed by the report is almost impossible to achieve.



Bugs Fixed in vBulletin 3.6.5

The Security Flaw
The reported security flaw described in this announcement, which could potentially allow a SELECT query to be hijacked, has been addressed.
Safari Cookies
A problem where users of the Apple browser Safari would be logged off the system prematurely when vBulletin runs on specific servers has been resolved.
More info...
Internet Explorer 7 Compatability
Much has been said about Microsoft's decision to make the Javascript prompt() function throw a security warning whenever it is called. This change resulted in vBulletin's text editor system throwing security warnings whenever a user tried to insert an image or an email link. The use of prompt() for Internet Explorer 7 users has now been discontinued in favour of an alternative method of collecting user input.
More info...

Additionally, improvements in Internet Explorer 7 mean that certain aspects of the vBulletin pop-up menu system, which were previously required to circumvent rendering issues, can now be bypassed. Most notable amongst these is the code that hides all <select> elements that would intersect with the menu when opened.
Fix for Infractions Bug
A problem where infraction expiration was not cleaned-up properly has been addressed.
More info...
Workaround for a FreeBSD Regular Expression Error on Login
Some users running recent versions of PHP running on FreeBSD have encountered a bug in the regular expression engine that caused an error to be shown when logging in. We have worked around this problem. However, it may still appear in other areas, so we are trying to find a proper fix for the issue.
Updating your vBulletin to Fix the Potential Exploit

There are two ways in which you can fix the potential exploit in your version of vBulletin:
  1. Full Upgrade: The best way to fix the problem is to perform a full upgrade by downloading the complete 3.6.5 package from the vBulletin Members' Area and following the regular upgrade instructions.
  2. Patch: A second option is to download the patch files discussed in this thread and upload them to your web server, overwriting the existing files. The patch is available from the Members' Area patch page or you can find it attached to this thread.
Please note that vBulletin 3.6.5 requires at least PHP 4.3.3 and MySQL 4.0.16 or later.



A Note Regarding vBulletin 3.6.6

The publication of this exploit has required a swift release of an updated version to fix the published problem. The original intention for vBulletin 3.6.5 had been to include a number of other bug fixes and improvements that have been reported since 3.6.4.

Unfortunately, the necessity of bringing out a version quickly to fix the exploit has meant that many of these fixes have not had sufficient time to be fully tested to the extent that we would like and have therefore been kept back for vBulletin 3.6.6.

We understand that this may be frustrating to our customers, and in order to minimize the inconvenience, we have ensured that this vBulletin 3.6.5 release contains no template or phrase changes, which will hopefully make upgrading as painless as possible.
__________________
Brandon Sheley / vBulletinSetup Staff
Check the
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
&
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
for the latest deals.
Looking for a place to
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
?

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
and other
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
.

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
/
Read the->
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

Are you on Twitter?
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
I'm offering a few
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
& here is my
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
experiment
Brandon Sheley is offline   Reply With Quote

Advertisement [Remove Advertisement]

Old 03-01-2007, 06:46 PM   #2
vBulletin Owner
 
G_Man's Avatar
 
Join Date: Oct 2006
Location: Spokane, Washington
Posts: 537
G_Man has a spectacular aura about
Re: vBulletin 3.6.5 Released

ah... crap...

Maybe I will just try patching it.

Anyone else use the patches as opposed to a full install?
__________________

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
G_Man is offline   Reply With Quote
Old 03-01-2007, 07:49 PM   #3
Community Manager
Supporters
vBulletin Owner
vBSetup Mods
 
Brandon Sheley's Avatar
 
Join Date: Jul 2006
Location: Topeka, KS
Posts: 14,080
Blog Entries: 35
Brandon Sheley is a splendid one to beholdBrandon Sheley is a splendid one to beholdBrandon Sheley is a splendid one to beholdBrandon Sheley is a splendid one to beholdBrandon Sheley is a splendid one to beholdBrandon Sheley is a splendid one to behold
Send a message via AIM to Brandon Sheley Send a message via MSN to Brandon Sheley Send a message via Yahoo to Brandon Sheley
Re: vBulletin 3.6.5 Released

I'll just patch em.. it sounds like there will be another update shortly that might have tempalte edits too..
__________________
Brandon Sheley / vBulletinSetup Staff
Check the
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
&
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
for the latest deals.
Looking for a place to
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
?

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
and other
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
.

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
/
Read the->
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

Are you on Twitter?
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
I'm offering a few
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
& here is my
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
experiment
Brandon Sheley is offline   Reply With Quote
Old 03-01-2007, 07:52 PM   #4
vBulletin Owner
 
G_Man's Avatar
 
Join Date: Oct 2006
Location: Spokane, Washington
Posts: 537
G_Man has a spectacular aura about
Re: vBulletin 3.6.5 Released

Quote:
Originally Posted by Brandon View Post
I'll just patch em.. it sounds like there will be another update shortly that might have tempalte edits too..
Template edit?!!??

*pulls out remaining hair*
__________________

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
G_Man is offline   Reply With Quote
Old 03-01-2007, 09:04 PM   #5
Community Manager
Supporters
vBulletin Owner
vBSetup Mods
 
Brandon Sheley's Avatar
 
Join Date: Jul 2006
Location: Topeka, KS
Posts: 14,080
Blog Entries: 35
Brandon Sheley is a splendid one to beholdBrandon Sheley is a splendid one to beholdBrandon Sheley is a splendid one to beholdBrandon Sheley is a splendid one to beholdBrandon Sheley is a splendid one to beholdBrandon Sheley is a splendid one to behold
Send a message via AIM to Brandon Sheley Send a message via MSN to Brandon Sheley Send a message via Yahoo to Brandon Sheley
Re: vBulletin 3.6.5 Released

lol.. you know if you ever need a hand, you have a few ppl that would be glad to help
__________________
Brandon Sheley / vBulletinSetup Staff
Check the
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
&
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
for the latest deals.
Looking for a place to
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
?

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
and other
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
.

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
/
Read the->
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

Are you on Twitter?
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
I'm offering a few
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
& here is my
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
experiment
Brandon Sheley is offline   Reply With Quote
Old 03-01-2007, 11:57 PM   #6
vBulletin Owner
 
eric's Avatar
 
Join Date: Oct 2006
Location: France
Posts: 1,153
eric is a jewel in the rougheric is a jewel in the rough
Re: vBulletin 3.6.5 Released

patching tonight, indeed a new release should follow soon if you read the text.... reason I will never heavily hack a template anymore, spend way to much time in the past on each upgrade...
__________________

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
eric is offline   Reply With Quote
Old 03-02-2007, 09:51 AM   #7
vBulletin Owner
 
Yvgeniy's Avatar
 
Join Date: Jan 2007
Location: Pennsylvania
Posts: 79
Yvgeniy will become famous soon enough
Send a message via AIM to Yvgeniy Send a message via MSN to Yvgeniy
Re: vBulletin 3.6.5 Released

I think I'll wait until 3.6.6. Sounds like it'll be a less rushed update. And OMG template updates?! I hope not... I have a good amount of mods. I should just appoint one of my admins to do template upgrades, he :P
__________________

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

Last edited by Yvgeniy; 03-02-2007 at 10:03 AM.
Yvgeniy is offline   Reply With Quote
Old 03-02-2007, 10:02 AM   #8
Supporters
vBulletin Owner
 
Michael Biddle's Avatar
 
Join Date: Aug 2006
Location: Anaheim, CA
Posts: 1,657
Michael Biddle is just really niceMichael Biddle is just really niceMichael Biddle is just really nice
Re: vBulletin 3.6.5 Released

i did a full upgrade on this, went very smooth on 2 of my sites
Michael Biddle is offline   Reply With Quote
Old 03-02-2007, 12:01 PM   #9
vBulletin Owner
 
eric's Avatar
 
Join Date: Oct 2006
Location: France
Posts: 1,153
eric is a jewel in the rougheric is a jewel in the rough
Re: vBulletin 3.6.5 Released

I just patched for now, will wait next update for a full update. Since it seems to be soon. Don't want to spend twice the time in less then a month
__________________

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
eric is offline   Reply With Quote
Old 03-07-2007, 06:52 AM   #10
Humbe
Guest
 
Posts: n/a
Re: vBulletin 3.6.5 Released

I've been looking and there is a powerful exploit (the new one), forums can be hacked easily (If you know how to)....

PATCH IS A MUST!!!

;-)
  Reply With Quote
Old 03-09-2007, 05:16 AM   #11
vBulletin Owner
 
Join Date: Mar 2007
Location: Lewisburg
Posts: 23
JUdieDJ will become famous soon enough
Send a message via Yahoo to JUdieDJ
Re: vBulletin 3.6.5 Released

I was not too concerned originaly about the update. I saw a fairly decent explination of the exploit and therefor just skipped it. If there is an addition issue with 3.6.4 then I guess I best....gulp....go ahead and do it.
JUdieDJ is offline   Reply With Quote
Old 03-09-2007, 11:11 AM   #12
vBulletin Owner
 
James's Avatar
 
Join Date: Mar 2007
Location: Kent, WA
Posts: 302
James is a jewel in the rough
Send a message via AIM to James Send a message via MSN to James
Re: vBulletin 3.6.5 Released

I will be patching mine forums this weekend. Just haven't had the time.
James is offline   Reply With Quote
Reply 
vBulletin Setup > General Forums > Official vBulletin Announcements

Tags
released, vbulletin

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
vBulletin 3.8.4 PL1, 3.7.6 PL1 and 3.6.12 PL2 Released Brandon Sheley Official vBulletin Announcements 0 10-07-2009 04:38 PM
vBulletin 3.8.1 Released ArnyVee Official vBulletin Announcements 7 03-29-2009 09:15 AM
vBulletin 3.7.3 Released Brandon Sheley Official vBulletin Announcements 10 08-27-2008 02:22 PM
vBulletin 3.7.2 PL2 and 3.6.10 PL4 Released Cerberus Official vBulletin Announcements 17 08-23-2008 07:47 PM
vBulletin 3.6.9 Released Brandon Sheley Official vBulletin Announcements 4 04-01-2008 06:02 PM


All times are GMT -8. The time now is 10:41 AM.