Go Back   vBulletin Modification Discussions > Site Business > News and Announcements > Jelsoft vBulletin Announcements
Home Register FAQ Members List Calendar Mark Forums Read
vBSEO Info Tags

Reply
 
LinkBack Thread Tools
Old 03-01-2007, 09:08 AM   #1 (permalink)
Administrator
 
Code Monkey's Avatar
 
Join Date: May 2006
Posts: 2,193
Code Monkey is on a distinguished road
iTrader: (0)
Post vBulletin 3.5.8 Released

vBulletin 3.5.8



This morning, an exploit was reported, which affects vBulletin versions 3.5.x and 3.6.x. Although the report is inaccurate and the published exploit does not work as claimed unless a highly unlikely set of circumstances exist, it has highlighted a potential security issue in these vBulletin versions.



Therefore, we have decided to release updated versions, these being vBulletin 3.5.8 and 3.6.5. We recommend that all customers running vBulletin 3.5.x or 3.6.x upgrade to the appropriate version or apply the supplied patch as soon as possible.



It is worth noting that in order to exploit the problem highlighted by the report, the attacking user must satisfy the following conditions:
  • Must already have moderator privileges
  • Must share the same IP address as an existing administrator who is currently logged in to the Admin Control Panel
  • Must know the Alt-IP and user agent (exact browser identification) of the administrator
  • OR must know the license number of the site being attacked
Given these requirements, the privilege escalation exploit claimed by the report is almost impossible to achieve.





Updating your vBulletin to Fix the Potential Exploit





There are two ways in which you can fix the potential exploit in your version of vBulletin:
  1. Full Upgrade: The best way to fix the problem is to perform a full upgrade by downloading the complete 3.5.8 package from the vBulletin Members' Area and following the regular upgrade instructions.
  2. Patch: A second option is to download the patch files discussed in this thread and upload them to your web server, overwriting the existing files. The patch is available from the Members' Area patch page or you can find it attached to this thread.





Link To Original Article

__________________
Please do not PM me unless it's personal. General vBulletin or mod questions by PM will be ignored.

Try the vBSEO Demo

Click here for Instant Community
Code Monkey is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links

Reply




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On


A vBSkinworks Design Recoded By vBModder.
All Code Distributed On This Site is © 2006 by it's author.
Search Engine Optimization by vBSEO 3.1.0

All times are GMT -7. The time now is 09:52 PM.
Online Users 64
Registered 1
Guests 63
Members 3144
Active Members 227
Threads 1575
Posts 6982
Top poster: Code Monkey (2193)
Welcome to our newest member, VbGuru
Most users ever online was 235, 04-11-2007 at 08:59 AM.
Speak Out! vBulletin gets the web talking!


vBulletin Setup SEO

vBulletin graphics resource images