Security exploit .patch file?

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • sticky
    Senior Member
    • Aug 2003
    • 411

    Security exploit .patch file?

    I read the instructions on the new patch to fix a security exploit and I don't understand it.

    I'm running 4.2.1 and have the right version of php installed. So, the thread says to download VBIV-15935.zip(11 KB, 1 view) and extract it. All that is in the zip is a .patch file. What exactly am I supposed to do with this file?
  • Zachery
    Former vBulletin Support
    • Jul 2002
    • 59097

    #2
    You should upgrade to 4.2.2, instead of trying to apply the patch file.

    Comment


    • sticky
      sticky commented
      Editing a comment
      My host thinks otherwise considering it will require a php upgrade and might break all my modifications. If it does break all my modifications then... um, are you going to help me fix it? Doubtful.

    • Zachery
      Zachery commented
      Editing a comment
      Sorry what? That doesn't even make sense. If 4.2.2 requires a php upgrade, then any version of vBulletin 4 would. vBulletin 4 did not raise the minimum version requirement.

      As of vBulletin 4.2.2 we’ve stopped suppressing notices and warnings. This is a change from all previous versions of the software.

      In some environments more notices/warnings show than in others. In order to address the issue you just need to add the following line to your config.php file
      define('SKIP_ALL_ERRORS', true);

      You can see additional information about this change here: http://www.vbulletin.com/forum/forum...-been-released

    • joeychgo
      joeychgo commented
      Editing a comment
      Get a new host..... They don't know what they are talking about. php 5.4 is a much better version and as Zack said, just add that line and your fine for nearly all mods that I know about.
  • ShannonA27
    New Member
    • Feb 2005
    • 18

    #3
    I have the same issue. I am currently running 4.2.0 Patch level 4 and I have the right php version installed. I also downloaded the VBIV zip file as instructed but all that is in the zip file is a .patch file (and I don't know what to do with it). I have been looking and reading the threads posted, and also in the members area on my account to see the patches that are listed for download. Here is what is listed for me (I am just listing the top 3):
    • Security patch: 4.2.2 Forum PL1
    • Security patch: 4.2.1 Forum PL1
    • Security patch: 4.2.0 Forum PL4


    Do I download the last one (Security patch 4.2.0 Forum PL4) or is that the previous patch that I installed? I am not looking to upgrade my vBulletin right now so please advise on what patch I am supposed to be using.

    Comment

    • Zachery
      Former vBulletin Support
      • Jul 2002
      • 59097

      #4
      I would HIGHLY advise upgrading to 4.2.2, over manually patching. 4.2.2, is the only version that has the patch automatically applied to it. Otherwise, you're going to need to follow the manual patching instructions:http://www.vbulletin.com/forum/forum...s-for-vb-4-x-x

      Comment


      • sticky
        sticky commented
        Editing a comment
        Zachery why do you guys always suggest what people aren't asking? We know how to upgrade to 4.2.2. We are asking what to do with the patch file. My board is highly customized because... well, because VB 4 needs to be in order to be useful. It's these customizations that turn it into software people want to use. Telling us to upgrade may be easier for you, but it isn't for many boards with a lot of work put into them over the years to get them where they are. I cringe every time I upgrade that the VB patch will break something. It usually does...

      • Wayne Luke
        Wayne Luke commented
        Editing a comment
        Normally you run the patch file through the patch command on your server and it applies the changes to the files specified. If you can't do this, then follow the link and modify the code yourself. If you don't want to modify the code, then you need to upgrade to 4.2.2.
    • Grae
      Senior Member
      • Dec 2000
      • 112

      #5
      How do you use the patch files?

      NM - I just downloaded the patch from the members area. Thank you.
      Last edited by Grae; Thu 13 Mar '14, 8:30pm.

      Comment

      • Wayne Luke
        vBulletin Technical Support Lead
        • Aug 2000
        • 73976

        #6
        Originally posted by Grae
        How do you use the patch files?

        NM - I just downloaded the patch from the members area. Thank you.
        Translations provided by Google.

        Wayne Luke
        The Rabid Badger - a vBulletin Cloud demonstration site.
        vBulletin 5 API

        Comment

        Related Topics

        Collapse

        Working...