What versions are still maintained?

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • pw2467
    New Member
    • May 2011
    • 8
    • 3.7.x

    What versions are still maintained?

    I own a number of forum licenses. Some of them (bought at the time of 3.8.x release) only have version 4.0.8 Forum PL9 available for download. The latest 4.2.2. Suite PL4 version is not available for download for them.

    The latest security patch to help prevent CSRF attacks is only available to versions 4.2.2, 3.8.7 & 3.8.8

    Questions:

    Are 4.2.2, 3.8.7 and 3.8.8 the only versions that are maintained at this moment?

    What about version 4.0.8 PL9 - the latest available to 3.8.x licensed forums?



  • Zachery
    Former vBulletin Support
    • Jul 2002
    • 59097

    #2
    That is correct, only 3.8.7/8/9, 4.2.2/3 and 5.x are being maintained at this time. I believe you should have access to the patches, you can diff them to try to fix it on your end.

    The easiest way to resolve the issue would be to upgrade the license to a vBulletin 5 license.

    Comment

    • Paul M
      Former Lead Developer
      vB.Com & vB.Org
      • Sep 2004
      • 9886

      #3
      There is nothing nuts about it.
      If you made the choice to run vB4 on a licence you were aware only had access to 4.0.8 then you must take the consequences.

      If you want a later version, then you have to pay for an upgrade, just like everything else in life.
      You wont see Microsoft give you Windows 8 for free just because windows XP has a new security issue in it.
      Baby, I was born this way

      Comment

      • Kat
        Senior Member
        • Nov 2001
        • 197

        #4
        I don't mind (well, not too much) that I don't have access to 4.2.2 but what I do mind is that there does not seem to be a CSRF attacks security patch for those of us running a 4x version lower than 4.2.2. Why do they 3x users get a patch but there does not appear to be one for the earlier 4x series?

        Comment

        • Mark.B
          vBulletin Support
          • Feb 2004
          • 24288
          • 6.0.X

          #5
          Your license is a vB3 license. As a courtesy, we gave holders of what were then "active" vB3 licenses, access to then-current versions of vB4.

          Technically speaking your license is only valid for vB3, under the licensing system you should really only have vB3. vB4 was a courtesy. If you now require later versions of vB4, you need to buy a new license.

          We support only the latest versions of each branch. 4.0.8 has many bugs and security issues, these were fixed in later versions.

          MARK.B
          vBulletin Support
          ------------
          My Unofficial vBulletin 6.0.0 Demo: https://www.talknewsuk.com
          My Unofficial vBulletin Cloud Demo: https://www.adminammo.com

          Comment

          • Kat
            Senior Member
            • Nov 2001
            • 197

            #6
            Oh ok, but I just want to have access to a patch. Why don't those of us stuck in the middle have access to a patch for this CSRF attacks?

            Comment

            • Mark.B
              vBulletin Support
              • Feb 2004
              • 24288
              • 6.0.X

              #7
              Originally posted by Kat
              Oh ok, but I just want to have access to a patch. Why don't those of us stuck in the middle have access to a patch for this CSRF attacks?
              The reason is that we don't maintain ancient versions such as 4.0.8. That's the bottom line. It would cost considerable resources, in terms of development costs, for someone to keep 4.0.8 maintained to the same security level as 4.2.2 - no company is going to do that. Zero return on investments.

              However - if it's just the ModCP issue you're worried about - just upload the global.php file from the modcp folder in the 4.2.2 patch. No guarantees but I'm 99% certain you'll be fine. Keep a copy of the old one just in case. (Don't upload the rest of the patch though...it won't work).
              MARK.B
              vBulletin Support
              ------------
              My Unofficial vBulletin 6.0.0 Demo: https://www.talknewsuk.com
              My Unofficial vBulletin Cloud Demo: https://www.adminammo.com

              Comment

              • Kat
                Senior Member
                • Nov 2001
                • 197

                #8
                How do I access the 4.2.2 patch?

                Comment

                • Mark.B
                  vBulletin Support
                  • Feb 2004
                  • 24288
                  • 6.0.X

                  #9
                  Originally posted by Kat
                  How do I access the 4.2.2 patch?
                  Send me a support ticket for my attention, referencing this thread. I'll then email the file to you.
                  MARK.B
                  vBulletin Support
                  ------------
                  My Unofficial vBulletin 6.0.0 Demo: https://www.talknewsuk.com
                  My Unofficial vBulletin Cloud Demo: https://www.adminammo.com

                  Comment

                  • ozzy47
                    Senior Member
                    • Oct 2009
                    • 215

                    #10
                    But having that file, does not in no way save you from all the other vulnerabilities that are in that old of a version. You are setting yourself up for trouble.
                    My Mods also available at OzzModz.com

                    New vBulletin Spider Definitions, vBulletin Spiders List Hits 1000 Spiders!
                    Stop Spam Now The era of Big Spam is over.

                    Vote to bring back hooks in vB5, http://tracker.vbulletin.com/browse/VBV-10333

                    Comment

                    • Kat
                      Senior Member
                      • Nov 2001
                      • 197

                      #11
                      Originally posted by Mark.B

                      Send me a support ticket for my attention, referencing this thread. I'll then email the file to you.
                      Thank you. I just did that, I hope I did it the right way.

                      ozzy47, yes, I realize that, but for the moment I need to get this current problem taken care of.

                      Comment

                      widgetinstance 262 (Related Topics) skipped due to lack of content & hide_module_if_empty option.
                      Working...