vBulletin 3.6.5 Released

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Kier
    Former Lead Developer, vBulletin
    • Sep 2000
    • 8179

    vBulletin 3.6.5 Released

    vBulletin 3.6.5

    This morning, an exploit was reported, which affects vBulletin versions 3.5.x and 3.6.x. Although the report is inaccurate and the published exploit does not work as claimed unless a highly unlikely set of circumstances exist, it has highlighted a potential security issue in these vBulletin versions.

    Therefore, we have decided to release updated versions, these being vBulletin 3.5.8 and 3.6.5. We recommend that all customers running vBulletin 3.5.x or 3.6.x upgrade to the appropriate version or apply the supplied patch as soon as possible.

    It is worth noting that in order to exploit the problem highlighted by the report, the attacking user must satisfy the following conditions:
    • Must already have moderator privileges
    • Must share the same IP address (or the number of IP octets specified in the Admin Control Panel for IP address matching) with an existing administrator who is currently logged in to the Admin Control Panel
    • Must know the Alt-IP and user agent (exact browser identification) of the administrator
    • OR must know the license number of the site being attacked
    Given these requirements, the privilege escalation exploit claimed by the report is almost impossible to achieve.



    Bugs Fixed in vBulletin 3.6.5

    The Security Flaw
    The reported security flaw described in this announcement, which could potentially allow a SELECT query to be hijacked, has been addressed.
    Safari Cookies
    A problem where users of the Apple browser Safari would be logged off the system prematurely when vBulletin runs on specific servers has been resolved.
    More info...
    Internet Explorer 7 Compatability
    Much has been said about Microsoft's decision to make the Javascript prompt() function throw a security warning whenever it is called. This change resulted in vBulletin's text editor system throwing security warnings whenever a user tried to insert an image or an email link. The use of prompt() for Internet Explorer 7 users has now been discontinued in favour of an alternative method of collecting user input.
    More info...

    Additionally, improvements in Internet Explorer 7 mean that certain aspects of the vBulletin pop-up menu system, which were previously required to circumvent rendering issues, can now be bypassed. Most notable amongst these is the code that hides all <select> elements that would intersect with the menu when opened.
    Fix for Infractions Bug
    A problem where infraction expiration was not cleaned-up properly has been addressed.
    More info...
    Workaround for a FreeBSD Regular Expression Error on Login
    Some users running recent versions of PHP running on FreeBSD have encountered a bug in the regular expression engine that caused an error to be shown when logging in. We have worked around this problem. However, it may still appear in other areas, so we are trying to find a proper fix for the issue.



    Updating your vBulletin to Fix the Potential Exploit

    There are two ways in which you can fix the potential exploit in your version of vBulletin:
    1. Full Upgrade: The best way to fix the problem is to perform a full upgrade by downloading the complete 3.6.5 package from the vBulletin Members' Area and following the regular upgrade instructions.
    2. Patch: A second option is to download the patch files discussed in this thread and upload them to your web server, overwriting the existing files. The patch is available from the Members' Area patch page or you can find it attached to this thread.
    Please note that vBulletin 3.6.5 requires at least PHP 4.3.3 and MySQL 4.0.16 or later.



    A Note Regarding vBulletin 3.6.6

    The publication of this exploit has required a swift release of an updated version to fix the published problem. The original intention for vBulletin 3.6.5 had been to include a number of other bug fixes and improvements that have been reported since 3.6.4.

    Unfortunately, the necessity of bringing out a version quickly to fix the exploit has meant that many of these fixes have not had sufficient time to be fully tested to the extent that we would like and have therefore been kept back for vBulletin 3.6.6.

    We understand that this may be frustrating to our customers, and in order to minimize the inconvenience, we have ensured that this vBulletin 3.6.5 release contains no template or phrase changes, which will hopefully make upgrading as painless as possible.
  • Kier
    Former Lead Developer, vBulletin
    • Sep 2000
    • 8179

    #2
    Patches are now available in the members' area. You may view available patches here. Alternatively, you may use the zip attached to this post to apply the patch. Both methods are equivalent.

    Go to the page mentioned above and download the "Security patch for 3.6.4" or download the zip at the end of this post. Extract the zip archive, then connect to your web server using FTP and overwrite the following files using the replacement versions from the zip.
    • inlinemod.php

    Notes:
    1. If you cannot download the attachment in this post, you are not currently registered as a license customer. Please see this thread for instructions on how to proceed.
    2. You do not need to download this patch if you perform a full upgrade to 3.6.5.
    3. If you only apply a patch, your version number will not change. Your version number will only be updated to 3.6.5 if you perform a full upgrade.
    Attached Files

    Comment

    • Kier
      Former Lead Developer, vBulletin
      • Sep 2000
      • 8179

      #3
      Files &amp; Templates Changed Since 3.6.4
      • /
        • image.php
        • inlinemod.php
      • clientscript/
        • ieprompt.html - new
        • vbulletin_global.js
        • vbulletin_menu.js
        • vbulletin_textedit.js
      • includes/
        • class_core.php
        • functions.php
        • functions_infractions.php
        • functions_login.php
        • ieprompt.jpg - new
      • install/ - all of it

      There are no changed templates since 3.6.4.

      Comment

      • Kier
        Former Lead Developer, vBulletin
        • Sep 2000
        • 8179

        #4
        Discussion Thread

        To discuss the release of vBulletin 3.6.5, please use the following thread:
        vBulletin 3.6.5 Discussion Thread

        Comment

        • Kier
          Former Lead Developer, vBulletin
          • Sep 2000
          • 8179

          #5
          The eBulletin for this release is in the process of being sent. Its contents can be read here.

          Comment

          widgetinstance 262 (Related Topics) skipped due to lack of content & hide_module_if_empty option.
          Working...