vBulletin 3.5.8
This morning, an exploit was reported, which affects vBulletin versions 3.5.x and 3.6.x. Although the report is inaccurate and the published exploit does not work as claimed unless a highly unlikely set of circumstances exist, it has highlighted a potential security issue in these vBulletin versions.
Therefore, we have decided to release updated versions, these being vBulletin 3.5.8 and 3.6.5. We recommend that all customers running vBulletin 3.5.x or 3.6.x upgrade to the appropriate version or apply the supplied patch as soon as possible.
It is worth noting that in order to exploit the problem highlighted by the report, the attacking user must satisfy the following conditions:
Updating your vBulletin to Fix the Potential Exploit
There are two ways in which you can fix the potential exploit in your version of vBulletin:
This morning, an exploit was reported, which affects vBulletin versions 3.5.x and 3.6.x. Although the report is inaccurate and the published exploit does not work as claimed unless a highly unlikely set of circumstances exist, it has highlighted a potential security issue in these vBulletin versions.
Therefore, we have decided to release updated versions, these being vBulletin 3.5.8 and 3.6.5. We recommend that all customers running vBulletin 3.5.x or 3.6.x upgrade to the appropriate version or apply the supplied patch as soon as possible.
It is worth noting that in order to exploit the problem highlighted by the report, the attacking user must satisfy the following conditions:
- Must already have moderator privileges
- Must share the same IP address as an existing administrator who is currently logged in to the Admin Control Panel
- Must know the Alt-IP and user agent (exact browser identification) of the administrator
- OR must know the license number of the site being attacked
Updating your vBulletin to Fix the Potential Exploit
There are two ways in which you can fix the potential exploit in your version of vBulletin:
- Full Upgrade: The best way to fix the problem is to perform a full upgrade by downloading the complete 3.5.8 package from the vBulletin Members' Area and following the regular upgrade instructions.
- Patch: A second option is to download the patch files discussed in this thread and upload them to your web server, overwriting the existing files. The patch is available from the Members' Area patch page or you can find it attached to this thread.
Comment