vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   News and Announcements (https://vborg.vbsupport.ru/forumdisplay.php?f=2)
-   -   vBulletin 3.8.1 PL1, 3.7.5 PL1 and 3.6.12 PL1 Released (https://vborg.vbsupport.ru/showthread.php?t=207429)

vB.Org System 03-05-2009 12:10 PM

vBulletin 3.8.1 PL1, 3.7.5 PL1 and 3.6.12 PL1 Released
 
vBulletin 3.8.1 PL1 / 3.7.5 PL1 / 3.6.12 PL1

An XSS flaw within the editor controls has recently been discovered. This could allow an attacker to carry out an action as a user or obtain access to a user's account. To resolve this issue, it is necessary to release a patch level version of the active versions of vBulletin.

The upgrade process is the same as previous patch level releases - simply download the patch from the Members Area, extract the files and upload to your webserver, overwriting the existing files. There is no upgrade script required.

As with all security-based releases, we recommend that all customers upgrade as soon as possible in order to prevent any potential damage resulting from the flaw being exploited.


Upgrading from 3.8.1, 3.7.5 or 3.6.12

If you are already running the latest version of the 3.6, 3.7 or 3.8 branch, the process you will be required to follow to make your board immune to this flaw is very simple.

There is no need to run an upgrade script if you are already running the latest version.

Visit the Patches section of the vBulletin Members' Area and download the patch for the version you are using, then extract the files from the archive you downloaded, then upload the files to your board via FTP etc., overwriting the existing files. This will update your version to the PL1 release.


Upgrading from an earlier version

If you are not already running the latest version of 3.6, 3.7 or 3.8, you should download the latest version from the Members' Area and perform an upgrade as normal.

Full instructions for upgrading vBulletin are available here.


Download vBulletin 3.8.1 PL1 / 3.7.5 PL1 / 3.6.12 PL1

As usual, the version released today is available for all customers with valid, active licenses to download from the vBulletin Members' Area.

vBulletin Members Area

Please do not use this thread for support questions.

More...

Jasem 03-05-2009 12:51 PM

many thanks

Installed!

projectego 03-05-2009 01:19 PM

[high]* projectego goes to upgrade :)[/high]

Fortunately I have the remainder of the evening to myself so I can take my time with this.

itsheinz 03-05-2009 01:51 PM

Installed! Thanks vbulletin^^

TNCclubman 03-05-2009 01:54 PM

Downloaded and patched thanks.

(Since this is my first license, just to confirm, when my license expires in 7 months and a patch comes out, is it my understanding then that my board will be vulnerable to hackers if I dont renew my license?)

Lasthero 03-05-2009 05:13 PM

thanks for patch..

steve1966 03-05-2009 06:54 PM

Thanks

as7apcool 03-06-2009 03:09 AM

installed

Shazz 03-06-2009 03:30 AM

Patches are easily fixed :)

Sweeks 03-06-2009 11:31 PM

Why does it mention the security bug here but not on vbulletin.com at all? Unless im missing it.


All times are GMT. The time now is 06:51 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01050 seconds
  • Memory Usage 1,729KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (1)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete