Why don't provide local YUI Files for security fix

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • ThomasTr
    New Member
    • Jun 2005
    • 7
    • 3.0.7

    Why don't provide local YUI Files for security fix

    Hi,

    why you don't provide local YUI 2.9.0 Files for the security fix? For users who don't us the remote files the fix does not work. Or when you forget to switch to google or yahoo or switch later back to local the fix also does not work.

    You deliver software with old and unsecure js files.
  • Steve Machol
    Former Customer Support Manager
    • Jul 2000
    • 154488

    #2
    AFAIK there is no known security issue with the .js files. As per this, only the .swf are affected and are not used in 3.8:



    If you have proof of an exploit in the .js files, then please provide it.
    Steve Machol, former vBulletin Customer Support Manager (and NOT retired!)
    Change CKEditor Colors to Match Style (for 4.1.4 and above)

    Steve Machol Photography


    Mankind is the only creature smart enough to know its own history, and dumb enough to ignore it.


    Comment

    • ThomasTr
      New Member
      • Jun 2005
      • 7
      • 3.0.7

      #3
      Hi,

      I don't have any exploit in the .js files. But why do you provide an patch for vbulletin which forces users to use 2.9.0 remote and don't patch the local files to 2.9.0 even if the exploited swf files aren't used (local and remote)?

      Comment

      • Steve Machol
        Former Customer Support Manager
        • Jul 2000
        • 154488

        #4
        There is no patch because there is no security expolit. You are free to change the one character manually, but that does not really fix anything.
        Last edited by Steve Machol; Mon 13 Jun '11, 8:38am.
        Steve Machol, former vBulletin Customer Support Manager (and NOT retired!)
        Change CKEditor Colors to Match Style (for 4.1.4 and above)

        Steve Machol Photography


        Mankind is the only creature smart enough to know its own history, and dumb enough to ignore it.


        Comment

        • m0rgulvale
          Senior Member
          • Jun 2008
          • 240

          #5
          ideally it would be nice to have the local files.. i don't want to need to rely on google / yahoo to host these external files forever... what happens if they stop providing the external service? then that will break my site.

          please provide the updated local files.

          Comment

          • Samir
            Senior Member
            • Nov 2003
            • 287
            • 3.8.x

            #6
            I'm sure there's a way you can download the current version of YUI and put it on your server manually. There's redistribution rules when incorporating software from other authors, so this simply may not have been feasible in order to roll out the patch as quickly as possible.
            Huntsville's Premiere Car and Bike e-magazine: www.huntsvillecarscene.com

            Comment

            • BirdOPrey5
              Senior Member
              • Jul 2008
              • 9613
              • 5.6.3

              #7
              You can download the Yahoo YUI file yourself: http://developer.yahoo.com/yui/2/

              Comment

              Related Topics

              Collapse

              Working...