The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#1
|
|||
|
|||
EOL and security patches
Can anyone help me understand how security patches work with versions 3.x? I keep running across the term "end of life" and I don't know exactly how it relates to security patches.
For example, if an exploit is discovered, will 3.x users get a patch? If so, how long into the future can I expect patches to be made for 3.x given that it is "EOL"? I note this forum is running 3.6.12, so is it safe to say that no exploits have been discovered since 3.6.12 and my 3.7.2.1 forum would be as secure as this one from a VB code standpoint? I would like to either keep running 3.7.2.1 if there are no known security holes or perhaps update to 3.8, but my site has been hacked a few times and it is no fun. |
#2
|
||||
|
||||
If they do release a security patch for a 3.x version, it will only be for 3.8.7 and/or 3.8.8 (just like the last time). I wouldn't be surprised if they stop releasing security patches for the 3.x versions.
Yes, this forum is running 3.6.12, but it is a very customized 3.6 site. There have been MANY security exploits found since this version. However, one of vBulletin's Lead Developers is running this site and you can be certain he has modified the code so those security exploits do not exist on this site. If you installed 3.6.12, you would not have a secure site at all. 3.7.2 is also not secure. I would suggest you upgrade to 3.8.7 if you want to have a secure site. |
#3
|
|||
|
|||
Thank you for the informative reply.
|
Thread Tools | |
Display Modes | |
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
More Information | |
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|