Go Back   vb.org Archive > News and Announcements > News and Announcements
FAQ Community Calendar Today's Posts Search

Closed Thread
 
Thread Tools Display Modes
  #1  
Old 11-21-2008, 09:40 AM
vB.Org System vB.Org System is offline
Senior Member
 
Join Date: Aug 2007
Posts: 386
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default vBulletin 3.7.4 PL1 Released

vBulletin 3.7.4 PL1

An XSS flaw within the user control panel has recently been discovered. This could allow an attacker to carry out an action as a user or obtain access to a user's account. To resolve this issue, it is necessary to release a patch level version of vBulletin 3.7.4.

vBulletin 3.6 is not affected. vBulletin 3.8 is affected, and the next beta/release candidate will include the fix.

The upgrade process is the same as previous patch level releases - simply download the patch from the Members Area, extract the files and upload to your webserver, overwriting the existing files. There is no upgrade script required.

As with all security-based releases, we recommend that all customers upgrade as soon as possible in order to prevent any potential damage resulting from the flaw being exploited.


Upgrading from 3.7.4

If you are already running 3.7.4, the process you will be required to follow to make your board immune to this flaw is very simple.

There is no need to run an upgrade script if you are already running 3.7.4.

Visit the Patches section of the vBulletin Members' Area and download the patch for 3.7.4, then extract the files from the archive you downloaded, then upload the files to your board via FTP etc., overwriting the existing files. This will update your version to the PL1 release.


Upgrading from Versions Earlier than 3.7.4

If you are not already running 3.7.4, you should download the latest version from the Members' Area and perform an upgrade as normal.

Full instructions for upgrading vBulletin are available here.


Download vBulletin 3.7.4 PL1

As usual, the version released today is available for all customers with valid, active licenses to download from the vBulletin Members' Area.

vBulletin Members Area

Please do not use this thread for support questions.

More...
  #2  
Old 11-21-2008, 11:10 AM
veenuisthebest's Avatar
veenuisthebest veenuisthebest is offline
 
Join Date: Mar 2008
Location: India
Posts: 1,416
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Thank you!
  #3  
Old 11-21-2008, 02:20 PM
Golzarion's Avatar
Golzarion Golzarion is offline
 
Join Date: Jan 2008
Posts: 214
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Thanks!
  #4  
Old 11-21-2008, 02:59 PM
Shazz's Avatar
Shazz Shazz is offline
 
Join Date: Jun 2006
Location: Utah
Posts: 4,758
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

A forced upgrade
  #5  
Old 11-21-2008, 06:44 PM
gamerfu gamerfu is offline
 
Join Date: Apr 2008
Location: 台灣,&
Posts: 326
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Why does 3.7.x series have so many problems?

[ADDED]: Thanks for the patches. *uploaded*
  #6  
Old 11-21-2008, 06:50 PM
Si?uNoopy Si?uNoopy is offline
 
Join Date: Oct 2008
Location: Alger
Posts: 51
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Thanks you
  #7  
Old 11-21-2008, 09:43 PM
Pete C's Avatar
Pete C Pete C is offline
 
Join Date: Aug 2005
Location: South coast, England
Posts: 161
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Initially I accepted that recent error messages generated after my upgrade were due to my host installing hardened php and Suhosin. (see here: https://vborg.vbsupport.ru/showpost....6&postcount=28) After further discussions it appears that the problems with hardened php and Suhosin only seem apparent when upgrading to 3.7.4

In this regard there is clearly an issue with this version of vBulletin.

In addition, since upgrading to 3.7.4 I've noticed that guests no longer appear in the Currently Active Users display. Only logged in members appear. Clicking "Who's Online" reveals several guests present, but the Currently Active Users display says there are none.

Reading back I see that this is a known bug with 3.7.4! Despite this, 3.7.4 PL1 has now been released but this issue remains unaddressed. I've applied this update and I STILL cannot see guests on my board.

I had no such problems with previous versions and I am rapidly coming to the conclusion that 3.7.4 is a disaster. So much so in fact that I'm seriously considering giving up vBulletin. Releasing software with known bugs to paying customers is simply not acceptable - this is supposed to be a final release not a BETA! These constant "upgrades" are frankly nothing short of a nuisance - especially if they cause problems that didn't exist before. Most of the time they offer little if anything to improve the average forums - they just cause more work for webmasters. It seems to me that the constant release of "upgrades" is simply a way of ensuring that renewal fees keep rolling in!

Why can there not be an established and stable version where owners do not need to constantly edit templates and etc? Surely security patches could still be released if vulnerabilities are discovered.

Well I'm sure these are questions that have been asked before and I'm equally sure there will be some pat answers to them . . . but at the end of the day the 3.7.0 release candidate, together with subsequent security patches would have been less troublesome than the "upgraded" version I'm currently stuck with.

Yeh yeh, nobody HAS to upgrade, but if you're trying to design skins, graphics etc. there is little credibility for the work if it's presented on an out-of-date board version.

I've been running vBulletin on an active owned license for several years now, but it's unlikely I'll renew again. I've closed my board now and I'll probably remove vBulletin from my server soon. Back to open source software and html pages if this is the best vB can offer.
  #8  
Old 11-22-2008, 02:10 PM
Valyx Valyx is offline
 
Join Date: Nov 2008
Posts: 14
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Belder View Post
Initially I accepted that recent error messages generated after my upgrade were due to my host installing hardened php and Suhosin. (see here: https://vborg.vbsupport.ru/showpost....6&postcount=28) After further discussions it appears that the problems with hardened php and Suhosin only seem apparent when upgrading to 3.7.4

In this regard there is clearly an issue with this version of vBulletin.

In addition, since upgrading to 3.7.4 I've noticed that guests no longer appear in the Currently Active Users display. Only logged in members appear. Clicking "Who's Online" reveals several guests present, but the Currently Active Users display says there are none.

Reading back I see that this is a known bug with 3.7.4! Despite this, 3.7.4 PL1 has now been released but this issue remains unaddressed. I've applied this update and I STILL cannot see guests on my board.

I had no such problems with previous versions and I am rapidly coming to the conclusion that 3.7.4 is a disaster. So much so in fact that I'm seriously considering giving up vBulletin. Releasing software with known bugs to paying customers is simply not acceptable - this is supposed to be a final release not a BETA! These constant "upgrades" are frankly nothing short of a nuisance - especially if they cause problems that didn't exist before. Most of the time they offer little if anything to improve the average forums - they just cause more work for webmasters. It seems to me that the constant release of "upgrades" is simply a way of ensuring that renewal fees keep rolling in!

Why can there not be an established and stable version where owners do not need to constantly edit templates and etc? Surely security patches could still be released if vulnerabilities are discovered.

Well I'm sure these are questions that have been asked before and I'm equally sure there will be some pat answers to them . . . but at the end of the day the 3.7.0 release candidate, together with subsequent security patches would have been less troublesome than the "upgraded" version I'm currently stuck with.

Yeh yeh, nobody HAS to upgrade, but if you're trying to design skins, graphics etc. there is little credibility for the work if it's presented on an out-of-date board version.

I've been running vBulletin on an active owned license for several years now, but it's unlikely I'll renew again. I've closed my board now and I'll probably remove vBulletin from my server soon. Back to open source software and html pages if this is the best vB can offer.
obviously it's not vBulletin's fault if you're the only one having those problems?
  #9  
Old 11-22-2008, 02:22 PM
Pete C's Avatar
Pete C Pete C is offline
 
Join Date: Aug 2005
Location: South coast, England
Posts: 161
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Valyx View Post
obviously it's not vBulletin's fault if you're the only one having those problems?
No I'm not the only one.

https://vborg.vbsupport.ru/showpost....9&postcount=22

https://vborg.vbsupport.ru/showpost....1&postcount=37

As already stated, the issue with guests not appearing has already been reported in the bug tracker and is apparently still unresolved.
  #10  
Old 11-22-2008, 02:32 PM
Wayne Luke's Avatar
Wayne Luke Wayne Luke is offline
Senior Member
 
Join Date: Jan 2002
Location: Southern California
Posts: 1,694
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Belder View Post
Reading back I see that this is a known bug with 3.7.4! Despite this, 3.7.4 PL1 has now been released but this issue remains unaddressed. I've applied this update and I STILL cannot see guests on my board.
PL or Patch Level releases deal solely with security issues that can affect the integrity of your board by allowing someone permissions that they shouldn't have. Patch Levels do not address other individual bugs if they are not a security risk. A non-critical bug such as what you describe if confirmed will be fixed as soon as its possible, most likely the next version which would be vBulletin 3.7.5 in this case.

You will find a patch for this issue here: http://www.vbulletin.com/forum/proje...6759#note71097
Closed Thread


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 04:12 AM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.04452 seconds
  • Memory Usage 2,269KB
  • Queries Executed 13 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (3)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (1)pagenav_pagelink
  • (10)post_thanks_box
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (10)post_thanks_postbit_info
  • (10)postbit
  • (10)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete