vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   News and Announcements (https://vborg.vbsupport.ru/forumdisplay.php?f=2)
-   -   vBulletin 3.6.7 Released (https://vborg.vbsupport.ru/showthread.php?t=147326)

Marco van Herwaarden 05-15-2007 03:36 PM

vBulletin 3.6.7 Released
 
vBulletin 3.6.7

As much as we hate to spring another upgrade on you all so soon after the release of vBulletin 3.6.6, an XSS flaw was identified today and in order to maintain our commitment to fix security problems as soon as we become aware of them, we have to release 3.6.7 and a patch for older versions.

All versions of vBulletin 3.6 prior to 3.6.7 are vulnerable to the XSS. vBulletin 3.5.x and 3.0.x are not affected.

To minimize the pain of another upgrade, there are no changed templates since 3.6.6 and no database schema changes, so the upgrade should be as simple and quick as possible.

Since we have fixed several bugs since vBulletin 3.6.6 was released, these fixes are also incorporated in this version and include amongst others:A complete list of bugs fixed in the 3.6 branch is available in the project manager.

Please accept our apologies for bringing out a new version just days after the previous release. We're sorry.

Fixing the XSS Bug

The XSS problem can be resolved in one of three ways.
  1. Full Upgrade: The best way to fix the problem is to perform a full upgrade, downloading the complete 3.6.7 package from the vBulletin Members' Area and following the regular upgrade instructions. This is the only option that will not only fix the XSS issue, but will also apply all the bug fixes made since the release of 3.6.6.
  2. Patch: A second option is to download the patch files either in the Members' Area or attached to this thread and upload them to your web server, overwriting the existing files.
    Patch file: 366_patch.zip
  3. Plugin: The plugin built into vBulletin 3.6 allows the problem to be fixed with a simple plugin. The install file for this plugin is also attached to this thread and is the easiest way to fix the problem, as it does not require you to upload any files via FTP. The plugin will be automatically removed when you perform your next full upgrade. You can install the plugin by following the instructions here.
    Plugin File: vb_calendar366_css_fix_plugin.xml
Please note the following:
  • The plugin can be used with any previous version of vBulletin 3.6
  • The patch can only be applied to vBulletin 3.6.4, 3.6.5 or 3.6.6
  • You may perform a full upgrade to vBulletin 3.6.7 from any previous version of vBulletin 3.
You can read more at the original thread on vBulletin.com: vBulletin 3.6.7 Released

EnIgMa1234 05-15-2007 03:39 PM

aww upgrading again. oh well thanks :D

ProSkinner.com 05-15-2007 03:44 PM

Yippee.. another upgrade! :)

Snake 05-15-2007 03:53 PM

Thanks, upgrading now... :)

Triky 05-15-2007 03:54 PM

Arg! I will upgrade Web City again. https://vborg.vbsupport.ru/

Seb@ 05-15-2007 04:08 PM

upgrading :)

MrPHD 05-15-2007 04:15 PM

Ok installed and running. Regards

Mudvayne 05-15-2007 04:39 PM

Ah! I just upgrade my forum today & now planning to sleep :(. Gosh they don't sleep & let us sleep :p.. Anyway upgrading now.

ShawnV 05-15-2007 05:28 PM

Ug!

_V

Distance 05-15-2007 05:29 PM

Oh dear :(

Best fix sooner rather than later though eh

Phatback 05-15-2007 05:39 PM

Can you attach the plugin to this thread?

deezelpope 05-15-2007 05:41 PM

Quote:

Originally Posted by Phatback (Post 1248260)
Can you attach the plugin to this thread?

  1. Full Upgrade: The best way to fix the problem is to perform a full upgrade, downloading the complete 3.6.7 package from the vBulletin Members' Area and following the regular upgrade instructions. This is the only option that will not only fix the XSS issue, but will also apply all the bug fixes made since the release of 3.6.6.
  2. Patch: A second option is to download the patch files either in the Members' Area or attached to this thread and upload them to your web server, overwriting the existing files.
    Patch file: 366_patch.zip
  3. Plugin: The plugin built into vBulletin 3.6 allows the problem to be fixed with a simple plugin. The install file for this plugin is also attached to this thread and is the easiest way to fix the problem, as it does not require you to upload any files via FTP. The plugin will be automatically removed when you perform your next full upgrade. You can install the plugin by following the instructions here.
    Plugin File: vb_calendar366_css_fix_plugin.xml

Phatback 05-15-2007 05:50 PM

for some reason i dont see any attachments...

calorie 05-15-2007 05:54 PM

Go to http://www.vbulletin.com/forum/showthread.php?t=229950 for attachments.

Brandon Sheley 05-15-2007 05:58 PM

aww, another upgrade :(

nexialys 05-15-2007 06:37 PM

Quote:

Originally Posted by Phatback (Post 1248260)
Can you attach the plugin to this thread?

This site is not for supporting direct upgrades of vBulletin... you have to go to the official website, have your license updated...

-- please other members, don't fall in the trick of a request... if the guy does not see the attachments, it is because he is not licensed... not us to deal with that

Mrdby 05-15-2007 07:22 PM

I just added the plug in...whoelse did this?

Quantnet 05-15-2007 07:29 PM

Just did the plugin as well. Still at 3.6.4
At this rate, I can wait till 3.7.

Shazz 05-15-2007 07:36 PM

I haven't even upgraded to 3.6.6 yet! :mad:

Mark.B 05-15-2007 07:39 PM

I have put the plugin on for now, full upgrade either later tonight or tomorrow, as I have half a dozen code changes to make and I have to be in the mood. :D

basilrath 05-15-2007 10:23 PM

is this a friggin joke

rayw 05-15-2007 10:26 PM

Quote:

Originally Posted by basilrath (Post 1248347)
is this a friggin joke

Don't think so!

I'm staying on 3.6.5 for the time being (it works fine, so I'm not going to stuff around with it). Not to mention all the mods and template edits I've made. When I take a week off work in a couple of months, I will think about upgrading then. :(

deezelpope 05-15-2007 10:39 PM

I'm still on 3.6.4...and nervous as h-e-double hockey sticks about upgrading! I don't wanna! So, for the time being, I'm staying where I'm at...unless someone would kindly volunteer to hold my hand through it.:p

DieselMinded 05-15-2007 10:45 PM

Do i have to install all the files in the upload folder ? Can you just tell me what changed so i can only upload them ones ?

DM

http://www.vbulletin.com/forum/showp...29&postcount=3

Ill just overwrite these ones

Ohiosweetheart 05-15-2007 11:27 PM

DM I doubt that anyone except the developers know exactly what changed in each file. This is why I hardly ever use hacks that require me to edit the php files. You're going to run into this everytime.

Mrdby 05-15-2007 11:29 PM

i just used the plugin

Mudvayne 05-16-2007 03:14 AM

Upgraded to 3.6.7 last night & waiting for 3.6.8 http://img503.imageshack.us/img503/7449/yikesft3.gif

DieselMinded 05-16-2007 03:38 AM

Ive learned a big lesson here after the 3.6.6 update i had 10 Templates that needed updated things seemed to be working fine and i went in to the templates and had no idea what was going on so i just sweep them under the rug ,,,, in the mean time i made some minor changes here and there and 3 of the 10 left the que at the time i was like cool ..... Well then today all **** hit the fan cant stay logged in and last vistied date was like 5 years ago all forums showing read ARGHHHHHHHH so i upgraded to the 3.6.7 with the quickness and it didnt fix anything , so then i cowboyed up and started clicking around in the out of date templates and finnaly learned how to read the compairison thing then i updated the remaining 7 templates this way and my site took off Speed wise and things got better how ever i still have some issues and i cant get the 3 templates back on there to run the compairison thing so i can make the changes , I have ran the check for out dated templates and nothing I have also un installed vbSEO as i couldnt get it to work on my server cause of .htaccess issues My boards sitill a little messed up Loging out users and intermittingly messing up the last vistited witch effects the forums read feature , Hoping for version 4.0 and all templates get edited so i can catch them 3 back up , Ive been in touch with the .com peeps and they want me to Revert all templates ...LOL yeah right thats like a last ditch effort thing .

To any newbies like me out there DO NOT ignore the Out of Date Templates

DM

HMBeaty 05-16-2007 04:04 AM

Sometimes you have to learn the hard way ;)

DieselMinded 05-16-2007 04:17 AM

Well With your Help I backed up before i installed the 3.6.7 So I have 2 back ups one right before the 3.6.5 upgrade , PM me on DB about how to apply a back up if i have to ;)

miner 05-16-2007 06:10 AM

Upgrade my test boards and working again to update all my free skins from 3.6.4 to 3.6.7 opps!!

...

MThornback 05-16-2007 06:19 AM

Installed easily :)

To all the people who said they're not bothering to update....they DID read the part about the WHOLE 3.6.x line having the same flaw right? It didn't just crop up in 3.6.6 it goes all the way back to the initial gold release....I hope people are patching at the very least and 3am has me reading most of page 2 wrong :p

FiRe_MaStER 05-16-2007 06:31 AM

thanks.upgrading...

no mods 05-16-2007 07:02 AM

Installed patch and .xml file. Ive messed my site up two many times to try something now, so ill wait to upgrade.:)

KingPuyol 05-16-2007 08:06 AM

Cool, I love upgrading

Shelley_c 05-16-2007 10:40 AM

Quote:

Originally Posted by KingPuyol (Post 1248606)
Cool, I love upgrading

I agree, there's nothing more satisfying than updating scores of templates (in my case 85). :)

Paul M 05-16-2007 11:18 AM

Quote:

Originally Posted by nexialys (Post 1248302)
-- please other members, don't fall in the trick of a request... if the guy does not see the attachments, it is because he is not licensed... not us to deal with that

Please don't post assumptions on things you know nothing about. You might want to remember that unlicensed members cannot post in this forum.

Triky 05-16-2007 11:35 AM

Web City Forum Online upgrade completed succesfully, one time again! https://vborg.vbsupport.ru/

ShawnV 05-16-2007 11:47 AM

Quote:

Originally Posted by Ohiosweetheart (Post 1248388)
DM I doubt that anyone except the developers know exactly what changed in each file. This is why I hardly ever use hacks that require me to edit the php files. You're going to run into this everytime.

I learned the hard way to keep a roster of all "Hacks" installed, marking the ones that require php.file edits in "large bold red text" ;)


_V

accessdeniedzzz 05-16-2007 02:20 PM

thanks,
hope that no more critical bugs will be on! (at least for next month)


All times are GMT. The time now is 05:20 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01398 seconds
  • Memory Usage 1,820KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (6)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (1)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (40)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete