+ Reply to Thread
Results 1 to 5 of 5

Thread: vBulletin 3.0.7 Released - Security Patch

  1. #1
    Former vBulletin Developer Mike Sullivan will become famous soon enough Mike Sullivan's Avatar
    Join Date
    Apr 2000
    Location
    Regexia
    Age
    25
    Posts
    13,374
    Blog Entries
    7

    vBulletin 3.0.7 Released - Security Patch

    vBulletin 3.0.7

    The discovery of a potentially serious security hole has necessitated the release of vBulletin 3.0.7. All customers are strongly encouraged to take one of the actions described in this post.

    All versions of vBulletin 3 up to and including 3.0.6 are affected only if you have enabled the Add Template Name in HTML Comments option (Admin Control Panel -> vBulletin Options -> General Settings). We hope most of you will not have had this option enabled anyway, as it is mostly for debugging and wastes a fair amount of bandwidth on a production site.

    Thus, to fix the issue, you should choose one of these options:
    1. Disable the Add Template Name in HTML Comments option on your board.
    2. Download the zip file attached to this post (or from here) and overwrite the misc.php in the main vBulletin directory on your server with the version in the zip. (More extensive instructions are provided in the zip file.)
    3. Upgrade to 3.0.7. A link to upgrade instructions is provided below.
    We would strongly recommend options 2 or 3 if possible.



    The Importance of Keeping Current with Security Updates

    We would like to take this time to reiterate the importance of keeping current with security updates. If you are not currently running a version with the recent patches built in or have not manually patched your board, please see the 3.0.5 and 3.0.6 announcements for important patches.

    Recently, more issues have been discovered than we would have liked, but we try to make patching as painless as possible to ease the burden these issues create. We are looking into ways to make patch delivery even easier for future versions.



    Backing Up Your Forums

    Please be sure to check that your backups are complete before continuing with an upgrade. We had reports that PHP was causing time out errors when creating the back up SQL, and this was causing for incomplete or corrupted backups. The safest way to do a backup is to use the mysqldump utility through SSH/Telnet, as it will not suffer from any such problems. Full instructions for backing up your database are available in the vBulletin 3 Manual.



    Installing or Upgrading vBulletin

    Please see the appropriate manual sections: Installing vBulletin and Upgrading vBulletin.
    Attached Files
    --Mike "Ed" Sullivan
    Former vBulletin Developer

    Twitter | Regexia (personal)

  2. #2
    Former vBulletin Developer Mike Sullivan will become famous soon enough Mike Sullivan's Avatar
    Join Date
    Apr 2000
    Location
    Regexia
    Age
    25
    Posts
    13,374
    Blog Entries
    7

    Bugs Fixed from 3.0.6 to 3.0.7

    --Mike "Ed" Sullivan
    Former vBulletin Developer

    Twitter | Regexia (personal)

  3. #3
    Former vBulletin Developer Mike Sullivan will become famous soon enough Mike Sullivan's Avatar
    Join Date
    Apr 2000
    Location
    Regexia
    Age
    25
    Posts
    13,374
    Blog Entries
    7

    Templates Changed from 3.0.6 to 3.0.7

    newattachment

    Added conditional that displays "Forum is closed for new attachments" if editing a post that contains attachments in a forum that is closed for posting.

    Requires Revert: Yes to gain this functionality.



    pm_messagelist_periodgroup

    Added a conditional to the colspan to prevent an empty column from being displayed if icons are disabled.

    Requires revert? No.



    SHOWTHREAD

    Added a conditional to add some spacing below the posts when using the legacy postbit. See this bug.

    Requires revert? No.
    --Mike "Ed" Sullivan
    Former vBulletin Developer

    Twitter | Regexia (personal)

  4. #4
    Former vBulletin Developer Mike Sullivan will become famous soon enough Mike Sullivan's Avatar
    Join Date
    Apr 2000
    Location
    Regexia
    Age
    25
    Posts
    13,374
    Blog Entries
    7

    Files Changed from 3.0.6 to 3.0.7

    • /
      • attachment.php
      • calendar.php
      • editpost.php
      • forumdisplay.php
      • joinrequests.php
      • member.php
      • memberlist.php
      • misc.php
      • moderator.php
      • newattachment.php
      • printthread.php
      • profile.php
      • register.php
      • showpost.php
      • showthread.php
    • /admincp/
      • adminreputation.php
      • image.php
      • misc.php
      • moderator.php
      • phrase.php
    • /archive/
      • index.php
    • /includes/
      • adminfunctions.php
      • adminfunctions_help.php
      • adminfunctions_language.php
      • adminfunctions_options.php
      • adminfunctions_template.php
      • functions.php
      • functions_bbcodeparse.php
      • functions_calendar.php
      • functions_forumdisplay.php
      • functions_newpost.php
      • functions_wysiwyg.php
    • /modcp/
      • deletedposts.php
      • moderate.php
      • user.php
    --Mike "Ed" Sullivan
    Former vBulletin Developer

    Twitter | Regexia (personal)

  5. #5
    Former vBulletin Developer Mike Sullivan will become famous soon enough Mike Sullivan's Avatar
    Join Date
    Apr 2000
    Location
    Regexia
    Age
    25
    Posts
    13,374
    Blog Entries
    7
    You may discuss the release in this thread:

    http://www.vbulletin.com/forum/showthread.php?t=130592
    --Mike "Ed" Sullivan
    Former vBulletin Developer

    Twitter | Regexia (personal)

+ Reply to Thread

Similar Threads

  1. Starcraft patch 1.12 RELEASED!!!
    By PeteRoy in forum Chit Chat
    Replies: 18
    Last Post: Sat 19th Feb '05, 9:48pm
  2. when a new patch is released is it automatically included in the full-version?
    By rnmcd in forum vBulletin 3.0 How Do I and Troubleshooting Forum
    Replies: 6
    Last Post: Wed 29th Sep '04, 2:15pm
  3. How long before a patch is released...
    By Glock21 in forum vBulletin 2 'How Do I' and Troubleshooting
    Replies: 0
    Last Post: Thu 30th Jan '03, 10:01am
  4. Microsoft Issues Critical IE Security Patch
    By Joe Gronlund in forum Chit Chat
    Replies: 1
    Last Post: Tue 12th Feb '02, 6:42pm
  5. vBulletin 2.0.3 Released - *important security fix*
    By John in forum vBulletin Announcements
    Replies: 1
    Last Post: Wed 1st Aug '01, 12:33am

Bookmarks

Posting Permissions

Posting Permissions
  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts