vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   News and Announcements (https://vborg.vbsupport.ru/forumdisplay.php?f=2)
-   -   vBulletin 3.6.4 Released (https://vborg.vbsupport.ru/showthread.php?t=132196)

Marco van Herwaarden 11-22-2006 01:57 PM

vBulletin 3.6.4 Released
 
vBulletin 3.6.4

The discovery of a potential cross-site scripting (XSS) issue in the administrators control panel has necessitated the preventative release of vBulletin 3.6.4 Due to several mitigating factors, this issue is hard to exploit and careful browsing by the admins can prevent it entirely. Nonetheless, we strongly recommend that all of our customers upgrade or apply the patch as soon as possible.

Additionally, vBulletin 3.6.4 includes fixes for several non-security-related bugs, see here for a full list.

Updating your vBulletin to combat the XSS issue:

Please note that this issue is present in other versions of vBulletin as well. Please see the appropriate announcement!

You have two options to fix the XSS issue:
  1. Full Upgrade: The best way to fix the problem is to perform a full upgrade, downloading the complete 3.6.4 package from the vBulletin Members' Area and following the regular upgrade instructions.
  2. Patch: A second option is to download the patch files discussed in this thread and upload them to your web server, overwriting the existing files. The patch is available from the Members' Area patch page!
If you absolutely cannot apply the patch or upgrade...

We strongly recommend you actively take steps to address this issue. However, if this is not possible, we recommend that administrators only log into the control panel when work is necessary. While you are logged into the control panel, do not click unknown links. Log out from the control panel using the link in the upper right of the screen immediately after finishing your work. If you are unexpectedly presented with the control panel login screen after clicking a link, do not login.

PHP and MySQL Requirements

Please note that vBulletin 3.6.x requires at least PHP 4.3.3 and MySQL 4.0.16 or later.

....Read more at vBulletin 3.6.4 Released

Shazz 11-22-2006 02:00 PM

That was fast!

puertoblack2003 11-22-2006 02:12 PM

man can't keep up with you guys.:D

Shazz 11-22-2006 02:22 PM

This is going to cause me a headahe..

DPSR 11-22-2006 03:00 PM

again... :( but don't know why i love to update lol :D:D

Snake 11-22-2006 03:20 PM

Thanks for the heads up. On my way to upgrade both forums. :)

joopss 11-22-2006 05:13 PM

That was fast!

Greek76 11-22-2006 05:27 PM

At this rate we should reach 6.1.0 in two months!

Shazz 11-22-2006 05:29 PM

Quote:

Originally Posted by Greek76 (Post 1123123)
At this rate we should reach 6.1.0 in two months!

Errm, there is still such thing as 3.7,3.8,3.9 :)

coffee 11-22-2006 05:50 PM

Let's call it XSS wwIII :)

Rickie3 11-22-2006 07:21 PM

its bloody ridiculous,vbulletin is in beta,release after release in a matter of months is beyond a joke,ive got better things to do than constant upgrades, I give up!!!!

Shazz 11-22-2006 07:23 PM

Quote:

Originally Posted by Rickie3 (Post 1123199)
its bloody ridiculous,vbulletin is in beta,release after release in a matter of months is beyond a joke,ive got better things to do than constant upgrades, I give up!!!!

[high]* Shazz joins you[/high]

projectego 11-22-2006 07:41 PM

[high]* projectego goes to upgrade now... ;)[/high]

Mr Pink 11-22-2006 09:23 PM

Upgraded succesfully.

Quote:

Originally Posted by Rickie3 (Post 1123199)
its bloody ridiculous,vbulletin is in beta,release after release in a matter of months is beyond a joke,ive got better things to do than constant upgrades, I give up!!!!

Yes, but when you see your forum with *Hacked* to the header of your page, you will come to say "Why vB hadn't upgraded and fixed some security problems!?".

da420 11-22-2006 10:13 PM

Quote:

Originally Posted by Rickie3 (Post 1123199)
its bloody ridiculous,vbulletin is in beta,release after release in a matter of months is beyond a joke,ive got better things to do than constant upgrades, I give up!!!!

Then don't upgrade. But, if it's hacked it's your fault. These exploits are hard to take advantage of, but it's possible, and I'd much rather a solution to the problem than to have a big upgrade once a year while these exploits can be taken advantage of.

VBUsers 11-22-2006 10:50 PM

wow the upgrades are very close to each other. getting ready to upgrade now. thanks

chanthuyen 11-22-2006 11:13 PM

oh my god, ton of releases !

JimmyN 11-22-2006 11:15 PM

lol its like a upgrade every month, oh well shows good support :)

I just upgraded again few mins ago
thanks

Q139 11-23-2006 12:15 AM

You don't have to upgrade.....all you have to do is upload the 2 files from the last 2 patches to be fully patched.

Takes about 30 seconds.....:confused:

All though I prefer the full update to address the bugs....great job!!!

Phaedrus 11-23-2006 12:32 AM

It's not a bad upgrade. No Template changes, except on ones that are rarely changed. You might need to redo changes to the pm template, and that is a "might".

Josh1 11-23-2006 12:35 AM

Quote:

Originally Posted by da420 (Post 1123285)
Then don't upgrade. But, if it's hacked it's your fault. These exploits are hard to take advantage of, but it's possible, and I'd much rather a solution to the problem than to have a big upgrade once a year while these exploits can be taken advantage of.

Aye true.

RedTyger 11-23-2006 10:36 AM

Quote:

Originally Posted by Rickie3 (Post 1123199)
its bloody ridiculous,vbulletin is in beta,release after release in a matter of months is beyond a joke,ive got better things to do than constant upgrades, I give up!!!!

I share your frustration, but that's just the way it goes. Code will always have errors, bugs and security issues. Ain't no perfect coder in the world. The real issue is what's done about them, and vBulletin are exceptionally quick.

Marco van Herwaarden 11-23-2006 05:44 PM

For 3.6:
1 update to iron out bugs discovered once 3.6 was generally used and a few improvements based on customer feedback. This is to be expected for the first stable release.
1 Update to fix a serious bug introduced when releasing the first update. serious bugs like this don't happen often with vB.
1 Update to fix a security issue in IE (so the release was not vB triggered)
1 update to fix a possible vulnerability that was almost impossible to exploit, but fixed anyway.

tbaleno 11-23-2006 09:08 PM

Am I mistaken or was there only one file to replace with this patch going from 3.6.3?

Shazz 11-23-2006 09:10 PM

Quote:

Originally Posted by tbaleno (Post 1123927)
Am I mistaken or was there only one file to replace with this patch going from 3.6.3?

On the 3.6.2 patched is one file change...
On the 3.6.3 its numerious code fixes I think you can read more about it the 3.6.3 thread

itsid 11-24-2006 03:23 AM

Now I'm happy that I never had any 3.6.3 in my hands :D

'sid

ps constant improvement is something to respect for!

da420 11-24-2006 03:38 AM

Successfully upgraded last night without problems. Only one template in each style to revert. :)

jobbe 11-25-2006 03:25 PM

Quote:

Originally Posted by Shazz (Post 1123929)
On the 3.6.2 patched is one file change...
On the 3.6.3 its numerious code fixes I think you can read more about it the 3.6.3 thread

Sorry to bother; I read the thread on vbcom and I didn't see all these code changes if you're on 3.6.3 as i am.
I see there are something on templates but nothing that really needs to revert.
Well, probably I misunderstood something, but i really thought that overwriteng admincp/index.php was enough :(

MorrisMcD 11-26-2006 01:04 AM

Upgrading is so easy now with the 3.6 version... I dont know what you are complaining about.. In fact, its almost too easy now.. Templates used to be the pain in the ass, but anymore you rarely have file edits, and minimal if at all, and you can compare template history to figure out what template changes need done if any during an upgrade..

The 3.0 days are over.. 3.6 makes upgrading simple.. Quit yer +++++in :)

Zelos 11-26-2006 05:37 AM

I personally like the fact that VB has been upgrading so often. phpBB has been plagued with exploit after exploit, and has still yet to release another upgrade since June!

MorrisMcD 11-26-2006 11:35 PM

Quote:

Originally Posted by Zelos (Post 1125309)
I personally like the fact that VB has been upgrading so often. phpBB has been plagued with exploit after exploit, and has still yet to release another upgrade since June!

+1

Well put

DannyMilner 12-03-2006 10:34 AM

Quote:

Originally Posted by Zelos (Post 1125309)
I personally like the fact that VB has been upgrading so often. phpBB has been plagued with exploit after exploit, and has still yet to release another upgrade since June!

Very true, I totaly agree.

Ohiosweetheart 12-03-2006 03:53 PM

Quote:

Originally Posted by Zelos (Post 1125309)
I personally like the fact that VB has been upgrading so often. phpBB has been plagued with exploit after exploit, and has still yet to release another upgrade since June!

Quote:

Originally Posted by MorrisMcD (Post 1125997)
+1

Well put

Quote:

Originally Posted by DannyMilner (Post 1130656)
Very true, I totaly agree.

Agreed.

The fact that they are always on top of security issues and bug fixes, coupled with the top notch support, sure makes me feel good about purchasing a vB license rather than going with a freebie.

radarhunter 12-04-2006 12:39 AM

hey wasn`t the version 3.6.3 and 3.6.4 released too early.....

da420 12-04-2006 01:08 AM

Quote:

Originally Posted by radarhunter (Post 1131300)
hey wasn`t the version 3.6.3 and 3.6.4 released too early.....

Not when security is at risk.

Phaedrus 12-10-2006 08:03 PM

So... I sorta expected to see that 3.6.5 had been released, or to have missed a couple... Are they finally settling?

snoop_1 12-11-2006 09:37 AM

Quote:

Originally Posted by Zelos (Post 1125309)
I personally like the fact that VB has been upgrading so often. phpBB has been plagued with exploit after exploit, and has still yet to release another upgrade since June!

yeah, i agree i like some of the updates on it :alien:

digital_sc4rz 12-12-2006 02:08 AM

lmao:rolleyes:
Quote:

Originally Posted by coffee (Post 1123151)
Let's call it XSS wwIII :)



All times are GMT. The time now is 06:02 AM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01350 seconds
  • Memory Usage 1,814KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (16)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (38)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete