4.2.3 BETA 3 security question

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • tommyxv
    Senior Member
    • Oct 2003
    • 331

    4.2.3 BETA 3 security question

    Does the 4.2.3 BETA 3 package still come with the YUI Security Issue found in uploader.swf?
  • Mark.B
    vBulletin Support
    • Feb 2004
    • 24287
    • 6.0.X

    #2
    The file was removed in an earlier version so 4.2.3 does not have that security problem.
    MARK.B
    vBulletin Support
    ------------
    My Unofficial vBulletin 6.0.0 Demo: https://www.talknewsuk.com
    My Unofficial vBulletin Cloud Demo: https://www.adminammo.com

    Comment

    • BirdOPrey5
      Senior Member
      • Jul 2008
      • 9613
      • 5.6.3

      #3
      Well the file wasn't completely removed- instead it was replaced with a blank file, so once you upgrade to 4.2.3 (or reinstall any version of VB4) it will replace the compromised file with a blank one so your forum is safe.

      You will need to go to Admin CP -> Settings -> Options -> Message Attachment Options, and change the Asset Manager option to Ajax by default. On a fresh install (Not upgrade) it will be set to Ajax uploader by default in VB 4.2.3.

      Your other option of course is to use the free modification to bring back the Flash uploader- but this is not supported- http://www.vbulletin.org/forum/showt...hreadid=307008

      If you use the above mod you must re-install it anytime you upgrade vBulletin.

      Comment

      • tommyxv
        Senior Member
        • Oct 2003
        • 331

        #4
        I uploaded all the vb 4.2.3 Beta 3 files. The uploaded.swf file size is 7.24kb and not an emtpy 0kb file.

        Comment

        • tommyxv
          Senior Member
          • Oct 2003
          • 331

          #5
          Bump. Can I get some clarification on this. The file is not a blank file in the latest 4.2.3 BETA 3 download package.

          Comment

          • BirdOPrey5
            Senior Member
            • Jul 2008
            • 9613
            • 5.6.3

            #6
            You're right, the file isn't blank- I'm sorry I didn't know it was being added back in. Best I can tell it is a safe version to use because it is NOT the old file, it is different. Will try to get a full explanation.

            Comment

            • tommyxv
              Senior Member
              • Oct 2003
              • 331

              #7
              Originally posted by Joe D.
              You're right, the file isn't blank- I'm sorry I didn't know it was being added back in. Best I can tell it is a safe version to use because it is NOT the old file, it is different. Will try to get a full explanation.

              Ok, thanks.

              Comment

              • BirdOPrey5
                Senior Member
                • Jul 2008
                • 9613
                • 5.6.3

                #8
                The file in the 4.2.3 Beta has been patched against the known exploit.

                Comment

                Related Topics

                Collapse

                Working...