PDA

View Full Version : Patch



Maplewoods
Mon 9th Feb '09, 2:28pm
Hi

The latest version that my membership allows me to download is Version 6.0

All I want is to have all the latest security updates/patches

Patches available to me are:

Security patch for 3.6.2 all the way through Security patch: 3.7.4 PL1

My question is:

Should I install each and every security patch (separately) all the way up to 3.7.4 PL1

Even though I am running VB version 6.0 ?

Thanks

Steve Machol
Mon 9th Feb '09, 2:29pm
You cannot do that. There is no way to patch 3.6.0. You would need to do a full upgrade.

Maplewoods
Mon 9th Feb '09, 2:35pm
You cannot do that. There is no way to patch 3.6.0. You would need to do a full upgrade.

I can't even do a security patch of 3.6.2 (for my current version of 3.6.0) ?

Steve Machol
Mon 9th Feb '09, 2:57pm
No. There is no patch you can use to fully secure 3.6.0. Sorry.

Maplewoods
Tue 10th Feb '09, 7:12pm
No. There is no patch you can use to fully secure 3.6.0. Sorry.

If there was never any Patch written specifically for 3.6.0,

may I assume it is because this version has no known exploits, for which a patch, would have potentially, have been needed for?

(so I can feel reasonably secure? :-)

I am (obviously) not asking for any kind of "guarantee".

I am only asking if there are no "known security issues" to the VB team for this specific version, which (I assume logically) would have necessitated them to create a patch for it, if it was a known security issue or known exploit.

Steve Machol
Tue 10th Feb '09, 7:15pm
No sorry, you cannot assume that. All version prior to 3.7.5 and 3.8.0 have security issues.

Patches are only good for the versions they are written for. So a patch for 3.6.1 will only work with 3.6.1. There is no way to ensure that a patch for 3.7.4 would work for version 3.6.0 which is many versions out-of-date.

Please note that 3.6.x is also end-of-life and no longer actively supported.

Maplewoods
Tue 10th Feb '09, 7:17pm
Please note that 3.6.x is also end-of-life and no longer actively supported.

What is the usual "life expectancy" of most versions before they reach (what is called) "end-of-life"?

Steve Machol
Tue 10th Feb '09, 7:20pm
There is no set 'life expectancy'. vB 3.6.0 was released in August 2006 and has since bene superceded by 3.7 and 3.8.