vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   News and Announcements (https://vborg.vbsupport.ru/forumdisplay.php?f=2)
-   -   vBulletin 3.7.3 PL1 and 3.6.11 PL1 Released (https://vborg.vbsupport.ru/showthread.php?t=190015)

vB.Org System 09-04-2008 02:00 PM

vBulletin 3.7.3 PL1 and 3.6.11 PL1 Released
 
vBulletin 3.7.3 PL1 / vBulletin 3.6.11 PL1

A report was published recently pointing to potential flaws within the random number generator in PHP applications who use a weak seed and then go on to disclose any of the random numbers generated. This flaw could allow random numbers within vBulletin to be predicted and under the correct circumstances allow an attacker to obtain access to a user's account. To resolve this issue, it is necessary to release patch level versions of vBulletin 3.7.3 and 3.6.11.

This original flaw was discovered by Stefan Esser and its application within vBulletin by another individual.

The upgrade process is the same as previous patch level releases - simply download the patch from the Members Area, extract the files and upload to your webserver, overwriting the existing files. There is no upgrade script required.

As with all security-based releases, we recommend that all customers upgrade as soon as possible in order to prevent any potential damage resulting from the flaw being exploited.


Upgrading from 3.7.3 or 3.6.11

If you are already running 3.7.3 or 3.6.11, the process you will be required to follow to make your board immune to this flaw is very simple.

There is no need to run an upgrade script if you are already running 3.7.3 or 3.6.11.

Visit the Patches section of the vBulletin Members' Area and download either the patch for 3.7.3, or the patch for 3.6.11, according to the version you are currently running, then extract the files from the archive you downloaded, then upload the files to your board via FTP etc., overwriting the existing files. This will update your version to the PL1 release.


Upgrading from Versions Earlier than 3.7.3 or 3.6.11

If you are not already running 3.7.3 or 3.6.11, you should download the most latest version from the Members' Area and perform an upgrade as normal.

Full instructions for upgrading vBulletin are available here.


Download vBulletin 3.7.3 PL1 or 3.6.11 PL1

As usual, both versions released today are available for all customers with valid, active licenses to download from the vBulletin Members' Area.

vBulletin Members Area

Please do not use this thread for support questions.

More...

iogames 09-04-2008 02:16 PM

Mmmh... Ok

Fireproof 09-04-2008 02:18 PM

Patched!

steve1966 09-04-2008 02:30 PM

many thanks

cheat-master30 09-04-2008 02:30 PM

Updated again.

PaylaX 09-04-2008 03:27 PM

upgrade but I get this problem

Quote:

Fatal error: Call to undefined method vB_Database::mstimer_start() in /home/.../public_html/forum/includes/init.php on line 157

Opserty 09-04-2008 03:31 PM

Quote:

Originally Posted by PaylaX (Post 1614466)
upgrade but I get this problem

Marco hasn't got round to editing the thread yet... but when he does he will say:
Quote:

Please do not use this thread for support questions.
:D (Post your problems in the main vBulletin help forums here or at vBulletin.com

PaylaX 09-04-2008 03:35 PM

ok, I'll probably fix this

Kinneas 09-05-2008 07:06 AM

Patched!

JamesFreeman 09-05-2008 09:28 AM

Woo, Patched.

choccyclaire 09-05-2008 11:43 AM

I'm all patched up. :)

rapidphim 09-09-2008 01:47 PM

I already patched it and now I received another email to tell me vB released exactly 3.7.3 PL1? And it also shown on my admincp ???? am I missing anything?


All times are GMT. The time now is 05:03 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01096 seconds
  • Memory Usage 1,733KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (3)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (12)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete