vBulletin 3.0.12 Released

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Kier
    Former Lead Developer, vBulletin
    • Sep 2000
    • 8179

    vBulletin 3.0.12 Released

    vBulletin 3.0.12

    A recently discovered cross-site scripting (XSS) flaw in all three branches of vBulletin has prompted us to perform a security update, releasing new versions of vBulletin 2, 3.0.x and 3.5.x simultaneously.

    All prior versions of vBulletin are vulnerable and we advise customers to upgrade or patch their vBulletin installations at their earliest convenience.

    For the vBulletin 3.0.x branch, the problem can be resolved in one of three ways.
    1. Full Upgrade: The best way to fix the problem is to perform a full upgrade, downloading the complete 3.0.12 package from the vBulletin Members' Area and following the regular upgrade instructions.
    2. Patch: A second option is to download the patch files attached to this thread and upload them to your web server, overwriting the existing files.
    Please do note that vBulletin 3.0.x is reaching the end of its life and is no longer actively developed, except for bug fixes. If you have not yet upgraded to vBulletin 3.5, you should consider doing so.

    Installing or Upgrading vBulletin

    Please see the appropriate manual sections: Installing vBulletin and Upgrading vBulletin.

    Bug Reports

    You may report bugs by clicking here. Before reporting a bug, please attempt to recreate the bug on a default, uncustomized style (especially if your errors are JavaScript related).
  • Kier
    Former Lead Developer, vBulletin
    • Sep 2000
    • 8179

    #2
    Patch File

    The file attached here allows you to fix the XSS problem without performing a full upgrade.

    Download the file and extract the zip archive, then connect to your web server using FTP and overwrite the following files using the replacement versions from the zip.
    • includes/functions_online.php
    Notes:
    • You do not need to download this patch if you perform a full upgrade to 3.0.12 or 3.5.3.
    • If you cannot download the patch, please see this thread.
    Attached Files

    Comment

    • Kier
      Former Lead Developer, vBulletin
      • Sep 2000
      • 8179

      #3
      Template Changes Since 3.0.11

      There have been no templates altered in the vBulletin 3.0.x branch since the release of 3.0.11.

      Comment

      • Mike Sullivan
        Former vBulletin Developer
        • Apr 2000
        • 13327
        • 3.6.x

        #4
        Files changed since 3.0.11
        • private.php
        • includes/
          • functions_file.php
          • functions_newpost.php
          • functions_online.php
        • install/ -- assume all files have changed

        Comment

        • Kier
          Former Lead Developer, vBulletin
          • Sep 2000
          • 8179

          #5
          You can discuss the release of vBulletin 3.0.12 using this thread:

          Comment

          widgetinstance 262 (Related Topics) skipped due to lack of content & hide_module_if_empty option.
          Working...