Go Back   vBulletin Setup > General Forums > Official vBulletin Announcements

Why not Register and remove some of the ads from vBulletin Setup
Post New Thread  Reply



#1   05-15-2007, 01:00 PM
Send a message via AIM to Brandon Send a message via MSN to Brandon Send a message via Yahoo to Brandon Brandon is a glorious beacon of lightBrandon is a glorious beacon of lightBrandon is a glorious beacon of lightBrandon is a glorious beacon of light Join Date: Jul 2006 Posts: 9,242 Location: Topeka, KS
vBulletin 3.6.7


vBulletin 3.6.7

As much as we hate to spring another upgrade on you all so soon after the release of vBulletin 3.6.6, an XSS flaw was identified today and in order to maintain our commitment to fix security problems as soon as we become aware of them, we have to release 3.6.7 and a patch for older versions.

All versions of vBulletin 3.6 prior to 3.6.7 are vulnerable to the XSS. vBulletin 3.5.x and 3.0.x are not affected.

To minimize the pain of another upgrade, there are no changed templates since 3.6.6 and no database schema changes, so the upgrade should be as simple and quick as possible.

Since we have fixed several bugs since vBulletin 3.6.6 was released, these fixes are also incorporated in this version and include amongst others:A complete list of bugs fixed in the 3.6 branch is available in the project manager.

Please accept our apologies for bringing out a new version just days after the previous release. We're sorry.

Fixing the XSS Bug

The XSS problem can be resolved in one of three ways.
  1. Full Upgrade: The best way to fix the problem is to perform a full upgrade, downloading the complete 3.6.7 package from the vBulletin Members' Area and following the regular upgrade instructions. This is the only option that will not only fix the XSS issue, but will also apply all the bug fixes made since the release of 3.6.6.
  2. Patch: A second option is to download the patch files either in the Members' Area or attached to this thread and upload them to your web server, overwriting the existing files.
    Patch file: 366_patch.zip
  3. Plugin: The plugin system built into vBulletin 3.6 allows the problem to be fixed with a simple plugin. The install file for this plugin is also attached to this thread and is the easiest way to fix the problem, as it does not require you to upload any files via FTP. The plugin will be automatically removed when you perform your next full upgrade. You can install the plugin by following the instructions here.
    Plugin File: vb_calendar366_css_fix_plugin.xml
Please note the following:
  • The plugin can be used with any previous version of vBulletin 3.6
  • The patch can only be applied to vBulletin 3.6.4, 3.6.5 or 3.6.6
  • You may perform a full upgrade to vBulletin 3.6.7 from any previous version of vBulletin 3.
--------------------
Brandon Sheley / vBulletin Setup Staff
Check out our Newsletter for the latest vB and SEO news.
Are you looking for vBulletin work to be done on your forums ?
Would you like to Help Support vBulletin Setup.
Reply to the Welcome PM for Full Access to the Forums.. Thanks

Please do not PM me for support, that's what the forums are for.
Have you heard about Crowdgather?
Find it on Forums
Check out this cool page - Bar Code Signatures
Quote   |  



#2   05-15-2007, 01:00 PM
Send a message via AIM to cajunboy2208 cajunboy2208 has a spectacular aura about Join Date: May 2007 Posts: 267 Location: Central, Louisiana
Re: vBulletin 3.6.7


Don't think I will run this anytime soon... It is just too quick. Maybe if I am on tonight and my forum is dead I will...
You gunna do the upgrade... or plugin?
--------------------
Owner of www.bleepd.com
Quote   |  



#3   05-15-2007, 03:37 PM
Send a message via AIM to Brandon Send a message via MSN to Brandon Send a message via Yahoo to Brandon Brandon is a glorious beacon of lightBrandon is a glorious beacon of lightBrandon is a glorious beacon of lightBrandon is a glorious beacon of light Join Date: Jul 2006 Posts: 9,242 Location: Topeka, KS
Re: vBulletin 3.6.7


I'll more then likely just add the patch.
--------------------
Brandon Sheley / vBulletin Setup Staff
Check out our Newsletter for the latest vB and SEO news.
Are you looking for vBulletin work to be done on your forums ?
Would you like to Help Support vBulletin Setup.
Reply to the Welcome PM for Full Access to the Forums.. Thanks

Please do not PM me for support, that's what the forums are for.
Have you heard about Crowdgather?
Find it on Forums
Check out this cool page - Bar Code Signatures
Quote   |  



#4   05-16-2007, 03:46 AM
eric is a jewel in the rougheric is a jewel in the rough Join Date: Oct 2006 Posts: 864 Location: France
Re: vBulletin 3.6.7


lol, I knew it when 3.6.6 was announced, I said I'd wait, maybe now I'll go for it. Since some time now I saw this pattern after each great update, quickly a little bug fix follows.
--------------------
Eric / vBulletin Setup Staff
Check out our Newsletter for the latest vB and SEO news.
Are you looking for vBulletin work to be done on your forums ?
Would you like to Help Support vBulletin Setup.

Aeroclix -- DistantHost link directory
Domains hosting, server rent... -- Distant-Help link directory
Quote   |  



#5   05-16-2007, 01:49 PM
Send a message via AIM to Brandon Send a message via MSN to Brandon Send a message via Yahoo to Brandon Brandon is a glorious beacon of lightBrandon is a glorious beacon of lightBrandon is a glorious beacon of lightBrandon is a glorious beacon of light Join Date: Jul 2006 Posts: 9,242 Location: Topeka, KS
Download Latest Version 3.6.7 PL1


what the hell's this ?

are they patching 3.6.7

wtf.jpg
--------------------
Brandon Sheley / vBulletin Setup Staff
Check out our Newsletter for the latest vB and SEO news.
Are you looking for vBulletin work to be done on your forums ?
Would you like to Help Support vBulletin Setup.
Reply to the Welcome PM for Full Access to the Forums.. Thanks

Please do not PM me for support, that's what the forums are for.
Have you heard about Crowdgather?
Find it on Forums
Check out this cool page - Bar Code Signatures
Quote   |  



#6   05-16-2007, 03:32 PM
Send a message via AIM to cajunboy2208 cajunboy2208 has a spectacular aura about Join Date: May 2007 Posts: 267 Location: Central, Louisiana
Re: vBulletin 3.6.7


Hahaha! This is crazy! What is up? They said they researched everything for 6 months for 3.6.6. And what 3 days later, already 2 updates for it? Come on VB!
--------------------
Owner of www.bleepd.com
Quote   |  



#7   05-17-2007, 12:51 PM
Michael Biddle is just really niceMichael Biddle is just really nice Join Date: Aug 2006 Posts: 1,514 Location: Anaheim, CA
Re: vBulletin 3.6.7


Well I dont see why people insist on bitching at vb. You should be glad enough that they fix these exploits for our own security. If you read the news, it says it will affect all vb 3.6.x. So it is recomended for your own security to upgrade.
--------------------
Do NOT PM me for Support!
Michael Biddle / vBulletin Setup Staff
Check out our Newsletter for the latest vB and SEO news.
Are you looking for vBulletin work to be done on your forums ?
Would you like to Help Support vBulletin Setup.
Quote   |  



#8   05-17-2007, 01:26 PM
Send a message via AIM to cajunboy2208 cajunboy2208 has a spectacular aura about Join Date: May 2007 Posts: 267 Location: Central, Louisiana
Re: vBulletin 3.6.7


It is what people do when they pay for a service. They enjoy complaining about the product, even though if they didn't have it, they would be up shit creek without a paddle.
I was not trying to sound a little bitchy. I just thought it was funny that they apparently worked on 3.6.6 for 6 months getting all the exploits and other stuff gone, and they were proud of it. And then once the released it, they quickly realized, hey, we didn't look at this close enough. It is bad for their business when stuff like that happens. It shows that in fact they didn't spend enough time getting everything correct. Who wants to go through updates every 2 days? Not me...
--------------------
Owner of www.bleepd.com
Quote   |  



#9   05-17-2007, 05:05 PM
Send a message via AIM to James Send a message via MSN to James James is a jewel in the rough Join Date: Mar 2007 Posts: 306 Location: Kent, WA
Re: vBulletin 3.6.7


Quote:
Originally Posted by cajunboy2208 View Post
Who wants to go through updates every 2 days? Not me...
Maybe not every 2 days upgrading, but maybe once a week....

I upgraded my test forum last night and all the others will be tomorrow night.
--------------------
My Updated Blog
Quote   |  



#10   05-17-2007, 05:23 PM
Michael Biddle is just really niceMichael Biddle is just really nice Join Date: Aug 2006 Posts: 1,514 Location: Anaheim, CA
Re: vBulletin 3.6.7


Besides if u upgraded to 3.6.7, then all you have to do is overwrite files for the pl1
--------------------
Do NOT PM me for Support!
Michael Biddle / vBulletin Setup Staff
Check out our Newsletter for the latest vB and SEO news.
Are you looking for vBulletin work to be done on your forums ?
Would you like to Help Support vBulletin Setup.
Quote   |  
Post New Thread  Reply
vBulletin Setup > General Forums > Official vBulletin Announcements


Thread Tools
Display Modes

 
Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -6. The time now is 07:24 AM.

vBulletin Setup, vBulletin Setup Forums, vBulletin Services, vBulletin Blogs, vBulletin SEO, vBulletin Questions, vBulletin Skins, Styles, Templates
vBulletin Hacks / Modifications, vBulletin Monetization, Blogs, vBulletin Link Directory,Quality Link Directory