Connect with Facebook
Go Back   vBulletin Setup > General Forums > Official vBulletin Announcements


Please Register to get full access to the forums.
Reply
 
LinkBack Thread Tools Display Modes
Old 08-18-2008, 07:20 AM   #1
Supporters
vBulletin Owner
 
Cerberus's Avatar
 
Join Date: Mar 2008
Posts: 1,321
Cerberus is just really niceCerberus is just really niceCerberus is just really nice
vBulletin 3.7.2 PL2 and 3.6.10 PL4 Released
Recent Blog: Need some advice...

vBulletin 3.7.2 PL2 / vBulletin 3.6.10 PL4

An XSS flaw related to JavaScript escaping has been identified. This could allow an attacker to carry out an action as a user or obtain access to a user's account. To resolve this issue, it is necessary to release patch level versions of vBulletin 3.7.2 and 3.6.10.

This flaw was discovered by Federico Muttis.

The upgrade process is the same as previous patch level releases - simply download the patch from the Members Area, extract the files and upload to your webserver, overwriting the existing files. There is no upgrade script required.

As with all security-based releases, we recommend that all customers upgrade as soon as possible in order to prevent any potential damage resulting from the flaw being exploited.


vBulletin 3.7.3 and 3.6.11 to be Released Next Week

In line with our new scheduled maintenance release policy, a new release for 3.6 and 3.7 will be made on Tuesday, August 26th.

These releases will contain bug fixes, but will also address a situation related to users that use their username as their password. In 3.6.11 and 3.7.3, this will be completely disallowed. Users affected by this will be forced to change their password on their first login. Additionally, a tool will be provided to email affected users with a new password. Please be aware of these potential compatibility changes when upgrading.

This release will be mentioned in the security bulletin sent out to customers today, but we will not send a further notification next week when 3.7.3 and 3.6.11 are released. Watch your Admin CP News, or the latest version check in the Admin CP to see when the new version is available. Alternatively, keep an eye on this forum for the 3.7.3 and 3.6.11 announcements.


Upgrading from 3.7.2, 3.6.10 or their patch level versions

If you are already running 3.7.2, 3.6.10 or their patch level versions, the process you will be required to follow to make your board immune to the XSS problem is very simple.

There is no need to run an upgrade script if you are already running 3.7.2, 3.6.10 or their patch level versions.

Visit the Patches section of the vBulletin Members' Area and download either the patch for 3.7.2, or the patch for 3.6.10, according to the version you are currently running, then extract the files from the archive you downloaded, then upload the files to your board via FTP etc., overwriting the existing files. This will update your version to the PL1 or PL3 release respectively.

The 3.7.2 PL2 patch file includes the PL1 fix.
The 3.6.10 PL4 patch file also includes the PL1, PL2, and PL3 fixes.


Upgrading from Versions Earlier than 3.7.2 or 3.6.10

If you are not already running 3.7.2 or 3.6.10, you should download the most latest version from the Members' Area and perform an upgrade as normal.

Full instructions for upgrading vBulletin are available here.


Download vBulletin 3.7.2 PL2 or 3.6.10 PL4

As usual, both versions released today are available for all customers with valid, active licenses to download from the vBulletin Members' Area.

vBulletin Members Area
__________________
Cerberus is offline   Reply With Quote
Old 08-18-2008, 08:05 AM   #2
Supporters
vBulletin Owner
 
ArnyVee's Avatar
 
Join Date: Apr 2008
Location: South Florida
Posts: 2,700
Blog Entries: 1
ArnyVee is a jewel in the roughArnyVee is a jewel in the rough
Send a message via AIM to ArnyVee Send a message via Yahoo to ArnyVee Send a message via Skype™ to ArnyVee
Re: vBulletin 3.7.2 PL2 and 3.6.10 PL4 Released

Is it that huge of a security issue to put out a patch when there's another update coming out in a week?
__________________
Walt Disney Boards -- Walt Disney Buddies -- Glam Rock Talk -- Gervais Book <-- My newest site for Ricky Gervais Fans :D
ArnyVee is offline   Reply With Quote
Old 08-18-2008, 09:18 AM   #3
Supporters
vBulletin Owner
 
glennybee's Avatar
 
Join Date: Mar 2008
Location: Scotland
Posts: 1,075
Recipes: 2
glennybee is just really niceglennybee is just really nice
Re: vBulletin 3.7.2 PL2 and 3.6.10 PL4 Released

That's what I was thinking, I think I'll just wait for the 3.7.3 revision.
glennybee is offline   Reply With Quote
Old 08-18-2008, 01:30 PM   #4
vBulletin Owner
 
Greek76's Avatar
 
Join Date: Sep 2006
Location: NYC
Posts: 592
Greek76 has a spectacular aura about
Send a message via MSN to Greek76
Re: vBulletin 3.7.2 PL2 and 3.6.10 PL4 Released

Looks like going to have to be doing templated edits all over again lol next week.
Greek76 is offline   Reply With Quote
Old 08-18-2008, 03:03 PM   #5
vBulletin Owner
 
Join Date: Apr 2007
Location: USA, NJ
Posts: 213
snakeair is a jewel in the rough
Re: vBulletin 3.7.2 PL2 and 3.6.10 PL4 Released

Strange, i updated today and now next week will do the same thing. Couldn't they just put this patch in with the next one. What could happen in a week anyway's?

I hope there are no template changes in the next release coming. That's what i hate the most, if template changes need to be made. lol
__________________
Free To Advertise Forum
snakeair is offline   Reply With Quote
Old 08-18-2008, 07:40 PM   #6
vBulletin Owner
 
Caddyman's Avatar
 
Join Date: Dec 2006
Location: Delaware
Posts: 3,627
Recipes: 7
Caddyman is a glorious beacon of lightCaddyman is a glorious beacon of lightCaddyman is a glorious beacon of lightCaddyman is a glorious beacon of light
Send a message via AIM to Caddyman Send a message via MSN to Caddyman Send a message via Yahoo to Caddyman Send a message via Skype™ to Caddyman
Re: vBulletin 3.7.2 PL2 and 3.6.10 PL4 Released
Recent Blog: Wicked

there usually aren't too many template changes, i wouldnt worry about it, if you logged into my ACP you would see a glaring 23 templates that need edited....lol

no biggie.
Caddyman is offline   Reply With Quote
Old 08-18-2008, 08:47 PM   #7
Supporters
vBulletin Owner
 
ArnyVee's Avatar
 
Join Date: Apr 2008
Location: South Florida
Posts: 2,700
Blog Entries: 1
ArnyVee is a jewel in the roughArnyVee is a jewel in the rough
Send a message via AIM to ArnyVee Send a message via Yahoo to ArnyVee Send a message via Skype™ to ArnyVee
Re: vBulletin 3.7.2 PL2 and 3.6.10 PL4 Released

I have 16 that need editing too. But, I haven't run into any issues, so I guess I'm okay.
__________________
Walt Disney Boards -- Walt Disney Buddies -- Glam Rock Talk -- Gervais Book <-- My newest site for Ricky Gervais Fans :D
ArnyVee is offline   Reply With Quote
Old 08-18-2008, 09:13 PM   #8
vBulletin Owner
 
Michael Biddle's Avatar
 
Join Date: Aug 2006
Location: Anaheim, CA
Posts: 1,752
Recipes: 2
Michael Biddle is just really niceMichael Biddle is just really niceMichael Biddle is just really nice
Re: vBulletin 3.7.2 PL2 and 3.6.10 PL4 Released

I do not know why people are complaining about this upgrade...it is just 4 new files to upload and your fixed...Be secure and patch, or leave a hole, the choice is yours. They are not forcing you to update. And their are no template updates in the patch.
__________________
Do NOT PM me for Support!
Michael Biddle is offline   Reply With Quote
Old 08-19-2008, 05:28 AM   #9
Supporters
vBulletin Owner
 
Cerberus's Avatar
 
Join Date: Mar 2008
Posts: 1,321
Cerberus is just really niceCerberus is just really niceCerberus is just really nice
Re: vBulletin 3.7.2 PL2 and 3.6.10 PL4 Released
Recent Blog: Need some advice...

Yeah it takes all of a minute LOL
__________________
Cerberus is offline   Reply With Quote
Old 08-21-2008, 10:35 AM   #10
vBulletin Owner
 
Soliloquy's Avatar
 
Join Date: Jun 2007
Location: New York City
Posts: 2,693
Recipes: 60
Soliloquy is a jewel in the rough
Re: vBulletin 3.7.2 PL2 and 3.6.10 PL4 Released

I'm glad there are no template editss this time because I'm not even done with the last round yet! But still patching all my vBulletin sites is yet another chore to add to the list...
__________________
Science Chats | Disabled NYC | The Chic Petite
Soliloquy is offline   Reply With Quote
Old 08-21-2008, 11:22 AM   #11
vBulletin Owner
 
Caddyman's Avatar
 
Join Date: Dec 2006
Location: Delaware
Posts: 3,627
Recipes: 7
Caddyman is a glorious beacon of lightCaddyman is a glorious beacon of lightCaddyman is a glorious beacon of lightCaddyman is a glorious beacon of light
Send a message via AIM to Caddyman Send a message via MSN to Caddyman Send a message via Yahoo to Caddyman Send a message via Skype™ to Caddyman
Re: vBulletin 3.7.2 PL2 and 3.6.10 PL4 Released
Recent Blog: Wicked

i usually dont upgrade till there is a release that includes cool features, if it is a bad bad security flaw i will but if not ill skip it.
Caddyman is offline   Reply With Quote
Old 08-21-2008, 03:21 PM   #12
vBulletin Owner
 
Join Date: Apr 2007
Location: USA, NJ
Posts: 213
snakeair is a jewel in the rough
Re: vBulletin 3.7.2 PL2 and 3.6.10 PL4 Released

Does anyone know what's instore for the next big vBulletin release? I do like the nice features we have now in 3.7

Plus, people are coming up with awesome codes at vbulletin.org
__________________
Free To Advertise Forum
snakeair is offline   Reply With Quote
Old 08-21-2008, 07:10 PM   #13
vBulletin Owner
 
Michael Biddle's Avatar
 
Join Date: Aug 2006
Location: Anaheim, CA
Posts: 1,752
Recipes: 2
Michael Biddle is just really niceMichael Biddle is just really niceMichael Biddle is just really nice
Re: vBulletin 3.7.2 PL2 and 3.6.10 PL4 Released

Well the biggest thing that I think is in store for the 3.7.3 is you cannot have your password = your username. Other then that, just the trivial fixes I believe. I also expect to see the blog 2.0 beta to be out relatively soon once they release the 3.7.3 as they said it is required for the new version.
__________________
Do NOT PM me for Support!
Michael Biddle is offline   Reply With Quote
Old 08-22-2008, 03:26 PM   #14
vBulletin Owner
 
Soliloquy's Avatar
 
Join Date: Jun 2007
Location: New York City
Posts: 2,693
Recipes: 60
Soliloquy is a jewel in the rough
Re: vBulletin 3.7.2 PL2 and 3.6.10 PL4 Released

Snakeair, they said something about improved user albums and social networking features, I think...
__________________
Science Chats | Disabled NYC | The Chic Petite
Soliloquy is offline   Reply With Quote
Old 08-22-2008, 04:46 PM   #15
vBulletin Owner
 
Join Date: Apr 2007
Location: USA, NJ
Posts: 213
snakeair is a jewel in the rough
Re: vBulletin 3.7.2 PL2 and 3.6.10 PL4 Released

That's good cause i'm still not sure what to do with those features right now. Perhaps a better idea will come to mind as the features get added.
__________________
Free To Advertise Forum
snakeair is offline   Reply With Quote
Old 08-23-2008, 09:27 AM   #16
vBulletin Owner
 
Caddyman's Avatar
 
Join Date: Dec 2006
Location: Delaware
Posts: 3,627
Recipes: 7
Caddyman is a glorious beacon of lightCaddyman is a glorious beacon of lightCaddyman is a glorious beacon of lightCaddyman is a glorious beacon of light
Send a message via AIM to Caddyman Send a message via MSN to Caddyman Send a message via Yahoo to Caddyman Send a message via Skype™ to Caddyman
Re: vBulletin 3.7.2 PL2 and 3.6.10 PL4 Released
Recent Blog: Wicked

yeah the user albums will have more control features, you will be able to move pics from one album to anothers and such (my members complained about that almost immediately.)
Caddyman is offline   Reply With Quote
Old 08-23-2008, 08:34 PM   #17
vBulletin Owner
 
Soliloquy's Avatar
 
Join Date: Jun 2007
Location: New York City
Posts: 2,693
Recipes: 60
Soliloquy is a jewel in the rough
Re: vBulletin 3.7.2 PL2 and 3.6.10 PL4 Released

You'd think they'd build that in with the release of user albums, but I guess not...
__________________
Science Chats | Disabled NYC | The Chic Petite
Soliloquy is offline   Reply With Quote
Old 08-23-2008, 08:47 PM   #18
vBulletin Owner
 
Caddyman's Avatar
 
Join Date: Dec 2006
Location: Delaware
Posts: 3,627
Recipes: 7
Caddyman is a glorious beacon of lightCaddyman is a glorious beacon of lightCaddyman is a glorious beacon of lightCaddyman is a glorious beacon of light
Send a message via AIM to Caddyman Send a message via MSN to Caddyman Send a message via Yahoo to Caddyman Send a message via Skype™ to Caddyman
Re: vBulletin 3.7.2 PL2 and 3.6.10 PL4 Released
Recent Blog: Wicked

yeaht eh only way now is to delete the pic from the album and reupload it to the album you want it in which is kinda of a PITA
Caddyman is offline   Reply With Quote
Reply

Tags
pl2, pl4, released, vbulletin

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
vBulletin 3.7.2 Released Brandon Sheley Official vBulletin Announcements 0 06-28-2008 03:03 PM
vBulletin 3.6.7 PL 1 Released Michael Biddle Making Money Marketing vBulletin 0 06-20-2007 08:14 PM
vBulletin 3.6.4 Released Brandon Sheley Official vBulletin Announcements 0 11-22-2006 04:30 PM
vBulletin 3.6.3 Released Brandon Sheley Official vBulletin Announcements 7 11-09-2006 05:18 PM
vBulletin 3.6.1 Released Brandon Sheley Official vBulletin Announcements 0 09-13-2006 09:23 AM


All times are GMT -6. The time now is 05:51 AM.

vBulletin Setup, vBulletin Setup Forums, vBulletin Services, vBulletin Blogs, vBulletin SEO, vBulletin Questions
vBulletin Skins, Styles, Templates, vBulletin Monetization, Blogs, vBulletin Link Directory,Quality Link Directory