Follow vBSEO on Twitter
vBulletin Modifications
  • Forums
  • Add-Ons
  • Template Modifications
  • Styles
  • Graphics
  • Tutorials
  • Support Center
  • Register
  • vBulletin SEO

Member Log In

Site Navigation

  • Register
  • Members List
  • Social Groups
  • Search
  • Today's Posts
  • Mark Forums Read

Latest Modifications

  • [vB 3.6.x] StopSpam
    By: flappi282
  • [vB 3.8.x] vBulletin Chat Addon for...
    By: 123flashchat
  • [vB 3.5.x] 404 Page Redirect To...
    By: Ak Worm
  • [vB 3.8.x] 404 Page Redirect To...
    By: Ak Worm
  • [vB 4.0.x] 404 Page Redirect To...
    By: Ak Worm

Latest Template Mods

  • [vB 3.8.4] Images PassWordBox...
    By: cRs!MP
  • [vB 3.8.4] Footer Follow Ups
    By: Ak Worm
  • [vB 3.7.2] Worldofwarcraft blue...
    By: Mikeyodesigns
  • [vB 3.7.0] My Links
    By: blind-eddie
  • [vB 3.7.0] Pop-Up Warning Before...
    By: Thelonius Beck

Latest Styles

  • [vB 3.8.4] CompletevB - Skylight
    By: DreadKnight
  • [vB 3.8.3] [vB 3.8.4] Barcelona...
    By: hoiquantinhoc.com
  • [vB 3.8.3] Natures Walk by vBSkin...
    By: Chri5
  • [vB 3.8.3] Green Theme
    By: Robdog
  • [vB 3.8.2] Unreal T 3 - vB3.8.x
    By: Butcher

Latest Graphics

  • [vB ] [anim.]Team Ranks
    By: cRs!MP
  • [vB ] Abstract Circles (3...
    By: cRs!MP
  • [vB ] PlayStation Rank Images
    By: cRs!MP
  • [vB 3.6.12] Heavy Stroked Button...
    By: Shelley
  • [vB ] Minature Ranks.
    By: Shelley
vBulletin Modifications » vBHackers.com » Announcements » vBulletin 3.6.5 released
Reply
Page 1 of 2 1 2 >

 

  • Thread Tools
Old 03-01-2007, 04:40 PM   #1
Mikeyodesigns
Advanced Coder

Mikeyodesigns's Avatar

Activity Longevity
0/20 13/20
Today Posts
0/3 ssssss520
Location: Scotland
Mikeyodesigns is on a distinguished road
Status: Offline Default vBulletin 3.6.5 released
From Vbulletin.com

vBulletin 3.6.5

This morning, an exploit was reported, which affects vBulletin versions 3.5.x and 3.6.x. Although the report is inaccurate and the published exploit does not work as claimed unless a highly unlikely set of circumstances exist, it has highlighted a potential security issue in these vBulletin versions.

Therefore, we have decided to release updated versions, these being vBulletin 3.5.8 and 3.6.5. We recommend that all customers running vBulletin 3.5.x or 3.6.x upgrade to the appropriate version or apply the supplied patch as soon as possible.

It is worth noting that in order to exploit the problem highlighted by the report, the attacking user must satisfy the following conditions:
  • Must already have moderator privileges
  • Must share the same IP address (or the number of IP octets specified in the Admin Control Panel for IP address matching) with an existing administrator who is currently logged in to the Admin Control Panel
  • Must know the Alt-IP and user agent (exact browser identification) of the administrator
  • OR must know the license number of the site being attacked
Given these requirements, the privilege escalation exploit claimed by the report is almost impossible to achieve.



Bugs Fixed in vBulletin 3.6.5

The Security Flaw
The reported security flaw described in this announcement, which could potentially allow a SELECT query to be hijacked, has been addressed.
Safari Cookies
A problem where users of the Apple browser Safari would be logged off the system prematurely when vBulletin runs on specific servers has been resolved.
More info...
Internet Explorer 7 Compatability
Much has been said about Microsoft's decision to make the Javascript prompt() function throw a security warning whenever it is called. This change resulted in vBulletin's text editor system throwing security warnings whenever a user tried to insert an image or an email link. The use of prompt() for Internet Explorer 7 users has now been discontinued in favour of an alternative method of collecting user input.
More info...

Additionally, improvements in Internet Explorer 7 mean that certain aspects of the vBulletin pop-up menu system, which were previously required to circumvent rendering issues, can now be bypassed. Most notable amongst these is the code that hides all <select> elements that would intersect with the menu when opened.
Fix for Infractions Bug
A problem where infraction expiration was not cleaned-up properly has been addressed.
More info...
Workaround for a FreeBSD Regular Expression Error on Login
Some users running recent versions of PHP running on FreeBSD have encountered a bug in the regular expression engine that caused an error to be shown when logging in. We have worked around this problem. However, it may still appear in other areas, so we are trying to find a proper fix for the issue.
Updating your vBulletin to Fix the Potential Exploit

There are two ways in which you can fix the potential exploit in your version of vBulletin:
  1. Full Upgrade: The best way to fix the problem is to perform a full upgrade by downloading the complete 3.6.5 package from the vBulletin Members' Area and following the regular upgrade instructions.
  2. Patch: A second option is to download the patch files discussed in this thread and upload them to your web server, overwriting the existing files. The patch is available from the Members' Area patch page or you can find it attached to this thread.
Please note that vBulletin 3.6.5 requires at least PHP 4.3.3 and MySQL 4.0.16 or later.



A Note Regarding vBulletin 3.6.6

The publication of this exploit has required a swift release of an updated version to fix the published problem. The original intention for vBulletin 3.6.5 had been to include a number of other bug fixes and improvements that have been reported since 3.6.4.

Unfortunately, the necessity of bringing out a version quickly to fix the exploit has meant that many of these fixes have not had sufficient time to be fully tested to the extent that we would like and have therefore been kept back for vBulletin 3.6.6.

We understand that this may be frustrating to our customers, and in order to minimize the inconvenience, we have ensured that this vBulletin 3.6.5 release contains no template or phrase changes, which will hopefully make upgrading as painless as possible.
Hellfire
Reply With Quote
Old 03-01-2007, 04:45 PM   #2
Nick R
vBulletin Guru

Nick R's Avatar

Activity Longevity
0/20 13/20
Today Posts
0/3 sssss4450
Location: Cyberspace, UK
Age: 30
Nick R is on a distinguished road
Send a message via MSN to Nick R Send a message via Yahoo to Nick R
Status: Offline Default
Interesting. I'm upgrading my boards now.
Reply With Quote
Old 03-01-2007, 05:06 PM   #3
Michael Biddle
Staff
Michael Biddle's Avatar

Activity Longevity
4/20 17/20
Today Posts
0/3 sssss2823
Location: Anaheim
Age: 21
Michael Biddle is on a distinguished road
Status: Offline Default
Already upgraded my development board now off to do it on my car one :D
Support will only be offered through forums
Michael Biddle / vBHackers.com
vBSEO 3.3.0 Gold Released with New "Virtual HTML Display" Feature Available for download now

vBSEO Google Sitemap Generator - Version 2.5 Released

Crawlability Network: vBulletin SEO | vBulletin Hackers
Reply With Quote
Old 03-01-2007, 05:18 PM   #4
Ateist
Psih

Activity Longevity
0/20 11/20
Today Posts
0/3 ssssssss7
Location: Russia
Age: 27
Ateist is on a distinguished road
Send a message via ICQ to Ateist Send a message via MSN to Ateist
Status: Offline Default
Thank You! I m go to upgrade...
Reply With Quote
Old 03-01-2007, 06:34 PM   #5
Likenota
Banned

Activity Longevity
0/20 11/20
Today Posts
0/3 ssssss173
Likenota is on a distinguished road
Status: Offline Default
thanks. hey if i upgrade do i have to re apply all the hacks and whatnot ?
Reply With Quote
Old 03-01-2007, 06:43 PM   #6
Nick R
vBulletin Guru

Nick R's Avatar

Activity Longevity
0/20 13/20
Today Posts
0/3 sssss4450
Location: Cyberspace, UK
Age: 30
Nick R is on a distinguished road
Send a message via MSN to Nick R Send a message via Yahoo to Nick R
Status: Offline Default
if your going from 3.6.4 to .5 then there are no changes to the templates. Just a few files. aka; All your templates and hacks should work and stay the same.
Reply With Quote
Old 03-01-2007, 07:29 PM   #7
Ateist
Psih

Activity Longevity
0/20 11/20
Today Posts
0/3 ssssssss7
Location: Russia
Age: 27
Ateist is on a distinguished road
Send a message via ICQ to Ateist Send a message via MSN to Ateist
Status: Offline Default
I do not download 3.6.5 - Errors, 90%.... ??? 10 attempts... Support - sleep?
Reply With Quote
Old 03-01-2007, 07:49 PM   #8
Michael Biddle
Staff
Michael Biddle's Avatar

Activity Longevity
4/20 17/20
Today Posts
0/3 sssss2823
Location: Anaheim
Age: 21
Michael Biddle is on a distinguished road
Status: Offline Default
what...? what do u mean? it went pretty clean for me, had one error, but i just deleted that row in database
Support will only be offered through forums
Michael Biddle / vBHackers.com
vBSEO 3.3.0 Gold Released with New "Virtual HTML Display" Feature Available for download now

vBSEO Google Sitemap Generator - Version 2.5 Released

Crawlability Network: vBulletin SEO | vBulletin Hackers
Reply With Quote
Old 03-01-2007, 08:06 PM   #9
Brandon Sheley
Coder

Brandon Sheley's Avatar

Activity Longevity
0/20 15/20
Today Posts
0/3 sssss1369
Location: Kansas
Age: 32
Brandon Sheley is on a distinguished road
Send a message via MSN to Brandon Sheley Send a message via Yahoo to Brandon Sheley
Status: Offline Default
I'll just patch until the real update occurs

no reason to do full upgrades when another release will likely be soon.

-Bs
Reply With Quote
Old 03-01-2007, 08:20 PM   #10
Ken Iovino
vBulletin Guru

Ken Iovino's Avatar

Activity Longevity
0/20 20/20
Today Posts
0/3 sssss2695
Location: Miami, Florida
Age: 26
Ken Iovino is on a distinguished road
Status: Offline Default
errrr, I hate upgrades! :(
Reply With Quote

Reply
Page 1 of 2 1 2 >

    Tags

vbulletin

« vBulletin 3.6.8 Released | - »

Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)

 
Thread Tools
Show Printable Version Show Printable Version
Email this Page Email this Page

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Forum Rules

Similar Threads
Thread Thread Starter Forum Replies Last Post
vBulletin 3.6.4 Released Mikeyodesigns Announcements 3 11-28-2006 06:09 AM
vBulletin 3.6.0 Gold Released Rex Announcements 11 10-18-2006 09:18 PM
vBulletin 3.6 Release Candidate 1 Released Ken Iovino Announcements 3 07-11-2006 08:32 PM
vBulletin 3.6 Beta 3 Released Ken Iovino Announcements 9 06-24-2006 08:58 PM
vBulletin 3.0.2 Released Ryan Ashbrook Announcements 8 07-06-2004 03:51 PM



All times are GMT. The time now is 03:11 PM.

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.2 ©2009, Crawlability, Inc.
Transverse Styles
  • Top
  • Archive
  • vBSEO
  • Contact Us
LinkBack
LinkBack URL LinkBack URL
About LinkBacks About LinkBacks
Bookmark & Share
Digg this Thread! Digg this Thread!
Add Thread to del.icio.us Add Thread to del.icio.us
Bookmark in Technorati Bookmark in Technorati
Furl this Thread! Furl this Thread!