+ Reply to Thread
Results 1 to 2 of 2

Thread: vBulletin 3.7.4 PL1 Released

  1. #1
    Former Senior Developer, vBulletin Mike Sullivan will become famous soon enough Mike Sullivan's Avatar
    Join Date
    Apr 2000
    Location
    Regexia
    Age
    26
    Posts
    13,374
    Blog Entries
    7

    vBulletin 3.7.4 PL1 Released

    vBulletin 3.7.4 PL1

    An XSS flaw within the user control panel has recently been discovered. This could allow an attacker to carry out an action as a user or obtain access to a user's account. To resolve this issue, it is necessary to release a patch level version of vBulletin 3.7.4.

    vBulletin 3.6 is not affected. vBulletin 3.8 is affected, and the next beta/release candidate will include the fix.

    The upgrade process is the same as previous patch level releases - simply download the patch from the Members Area, extract the files and upload to your webserver, overwriting the existing files. There is no upgrade script required.

    As with all security-based releases, we recommend that all customers upgrade as soon as possible in order to prevent any potential damage resulting from the flaw being exploited.


    Upgrading from 3.7.4

    If you are already running 3.7.4, the process you will be required to follow to make your board immune to this flaw is very simple.

    There is no need to run an upgrade script if you are already running 3.7.4.

    Visit the Patches section of the vBulletin Members' Area and download the patch for 3.7.4, then extract the files from the archive you downloaded, then upload the files to your board via FTP etc., overwriting the existing files. This will update your version to the PL1 release.


    Upgrading from Versions Earlier than 3.7.4

    If you are not already running 3.7.4, you should download the latest version from the Members' Area and perform an upgrade as normal.

    Full instructions for upgrading vBulletin are available here.


    Download vBulletin 3.7.4 PL1

    As usual, the version released today is available for all customers with valid, active licenses to download from the vBulletin Members' Area.

    vBulletin Members Area




    You can discuss this patch release in the existing 3.7.4 release discussion.
    --Mike "Ed" Sullivan
    Former vBulletin Developer

    Twitter | Regexia (personal)

  2. #2
    vBulletin Team Wayne Luke is a splendid one to behold Wayne Luke is a splendid one to behold Wayne Luke is a splendid one to behold Wayne Luke is a splendid one to behold Wayne Luke is a splendid one to behold Wayne Luke is a splendid one to behold Wayne Luke is a splendid one to behold Wayne Luke's Avatar
    Join Date
    Aug 2000
    Location
    So. California
    Age
    39
    Posts
    36,178
    Blog Entries
    1
    Patch Level releases can only be applied to the version of vBulletin that they were created for. If you are not using vBulletin 3.7.4, you will need to upgrade before you can apply this patch to your forums. Applying Patch Level releases to previous version of vBulletin is not supported and can cause problems when upgrading in the future.
    Wayne Luke
    Get started with your own social network.
    Purchase and download vBulletin today.


+ Reply to Thread

Similar Threads

  1. vBulletin 3.0.17 Released
    By Kier in forum vBulletin Announcements
    Replies: 3
    Last Post: Wed 22nd Nov '06, 10:28am
  2. vBulletin 3.0.16 Released
    By Mike Sullivan in forum vBulletin Announcements
    Replies: 3
    Last Post: Wed 8th Nov '06, 8:42am
  3. vBulletin 2.3.11 Released
    By Mike Sullivan in forum vBulletin Announcements
    Replies: 3
    Last Post: Wed 8th Nov '06, 8:42am
  4. vBulletin 3.5.1, 3.0.10 & 2.3.8 Released
    By Kier in forum vBulletin Announcements
    Replies: 8
    Last Post: Wed 2nd Nov '05, 4:21am
  5. vBulletin 3.0.0 RC5 Released
    By Kier in forum vBulletin Announcements
    Replies: 0
    Last Post: Fri 19th Mar '04, 4:58pm

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts