It appears you have not yet registered with our community. To register please click here...

vbulletin-skins-forum
| Discussions: 2,328 | Messages: 6,935 | Members: 5,375 | Online: 28 | Newest : cuervo (Welcome!)
Logo
All times are GMT -5. The time now is 05:52 PM.

Go Back   Forums Help - vBulletin, IPB, phpBB, SMF skins and community > Forum Areas > Forums In Depth > Forums News

Forums News Forums and boards news

Tags: , , , , , , , , , , , , , , ,

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
Old 03-01-2007, 03:16 PM   #1 (permalink)
User Profile
ForumsHelp
Senior Member
 
ForumsHelp's Avatar
 

Join Date: Apr 2006
Age: 31
Posts: 968
Total Points: 185,091
Donate
My Photos: (1)
My Mood:
Send a message via ICQ to ForumsHelp Send a message via AIM to ForumsHelp Send a message via MSN to ForumsHelp Send a message via Skype™ to ForumsHelp
vBulletin 3.6.5 - An early release

According to vBulletin.org and vBulletin.com, a bug has been reported that affects both vb 3.6.x and 3.5.x versions, and as a fast reaction to this bug, two new versions have been released, these versions are vBulletin 3.6.5 and vBulletin 3.5.8.

Although the bug reported can hardly affect forums and needs a lot of circumstances but it's adviced to upgrade now in order to make sure that your forum is safe.
The circumstances needed for this bug need the attacker to have:
  • Must already have moderator privileges
  • Must share the same IP address (or the number of IP octets specified in the Admin Control Panel for IP address matching) with an existing administrator who is currently logged in to the Admin Control Panel
  • Must know the Alt-IP and user agent (exact browser identification) of the administrator
  • OR must know the license number of the site being attacked
Given these requirements, the privilege escalation exploit claimed by the report is almost impossible to achieve.

And due to the early release, this version lacked some updates and fixes that were expected in vBulletin 3.6.5 but in the meanwhile it has a good number of fixes, which are:
Bugs Fixed in vBulletin 3.6.5

The Security Flaw
The reported security flaw described in this announcement, which could potentially allow a SELECT query to be hijacked, has been addressed.
Safari Cookies
A problem where users of the Apple browser Safari would be logged off the system prematurely when vBulletin runs on specific servers has been resolved.
More info...
Internet Explorer 7 Compatability
Much has been said about Microsoft's decision to make the Javascript prompt() function throw a security warning whenever it is called. This change resulted in vBulletin's text editor system throwing security warnings whenever a user tried to insert an image or an email link. The use of prompt() for Internet Explorer 7 users has now been discontinued in favour of an alternative method of collecting user input.
More info...

Additionally, improvements in Internet Explorer 7 mean that certain aspects of the vBulletin pop-up menu system, which were previously required to circumvent rendering issues, can now be bypassed. Most notable amongst these is the code that hides all <select> elements that would intersect with the menu when opened.
Fix for Infractions Bug
A problem where infraction expiration was not cleaned-up properly has been addressed.
More info...
Workaround for a FreeBSD Regular Expression Error on Login
Some users running recent versions of PHP running on FreeBSD have encountered a bug in the regular expression engine that caused an error to be shown when logging in. We have worked around this problem. However, it may still appear in other areas, so we are trying to find a proper fix for the issue.
Updating your vBulletin to Fix the Potential Exploit

There are two ways in which you can fix the potential exploit in your version of vBulletin:
  1. Full Upgrade: The best way to fix the problem is to perform a full upgrade by downloading the complete 3.6.5 package from the vBulletin Members' Area and following the regular upgrade instructions.
  2. Patch: A second option is to download the patch files discussed in this thread and upload them to your web server, overwriting the existing files. The patch is available from the Members' Area patch page or you can find it attached to this thread.
Please note that vBulletin 3.6.5 requires at least PHP 4.3.3 and MySQL 4.0.16 or later.
ForumsHelp is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 04-26-2007, 08:34 PM   #2 (permalink)
User Profile
tsho44
Junior Member
 

Join Date: Apr 2007
Posts: 1
Total Points: 147
Donate
My Photos: (0)
thanks for the notes.
tsho44 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply



Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Points Per Thread View: 1
Points Per Thread: 15
Points Per Reply: 5



Links: Babyforum.com | Deejayforum.com | Hometalkcafe.com | Equineboard.com | Evboard.com


Forums Help: Forum Skin Design and Professional Services RSS Feeds



Powered by vBulletin® Version 3.6.7
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.0.0
Forums Help - All Rights Reserved