PDA

View Full Version : vBulletin 3.6.3, 3.5.6, 3.0.16 & 2.3.11 Released


Paul M
08 Nov 2006, 19:00
An undocumented behaviour in all Windows versions of Internet Explorer has rendered vBulletin vulnerable to a potential cross-site scripting flaw (XSS).

Therefore, Jelsoft have decided to put out a preventative security releases in order to work-around the Internet Explorer problem before it is exploited.

The official announcement threads for these releases can be found here.

vB 3.6.3 (http://www.vbulletin.com/forum/showthread.php?t=207860)
vB 3.5.6 (http://www.vbulletin.com/forum/showthread.php?t=207859)
vB 3.0.16 (http://www.vbulletin.com/forum/showthread.php?t=207858)
vB 2.3.11 (http://www.vbulletin.com/forum/showthread.php?t=207857)

In addition, vB 3.6.3 also includes fixes for approximately 50 bugs that were discovered in 3.6.2. For this reason, Jelsoft recommend all customers upgrade to 3.6.3 as soon as possible.

da420
08 Nov 2006, 19:05
Cool, thanks for the update Paul.

Ziki
08 Nov 2006, 19:10
Will patch! :D

Mudvayne
08 Nov 2006, 19:29
I've allready upgraded my forum :D..

projectego
08 Nov 2006, 20:23
/me upgrades to 3.6.3 ;)

Shazz
08 Nov 2006, 22:33
*Patched...
I don't want to get another headache on another upgrade....
They come out soo SOON

Spiffware
09 Nov 2006, 00:06
did they change vars too will the 3.6.2 hacks work?

afx1
09 Nov 2006, 00:19
did they change vars too will the 3.6.2 hacks work?

3.6.2 hacks still work.

evenmonkeys
09 Nov 2006, 08:44
Add the 3.6.3 to the list of modification versions!!! =P

Just upgraded my forums. I forgot how nice the upgrades were when you didn't skip fifty of em. Haha.

Spiffware
09 Nov 2006, 12:15
3.6.2 hacks still work.
thank you then i guess ill upgrade this week.

Shazz
09 Nov 2006, 12:18
Add the 3.6.3 to the list of modification versions!!! =P

Just upgraded my forums. I forgot how nice the upgrades were when you didn't skip fifty of em. Haha.
All 3.6.2 Mods work..

untold4you
09 Nov 2006, 17:42
Can someone tell me why there isen't a patch for version 3.6.0 ?

Tnx!

The Itchy One
09 Nov 2006, 19:38
download the 3.6.3 full file to your domain and run the upgrade_360.php file

Andrew
09 Nov 2006, 20:07
I'm so glad this came out now - My download and support period expires again tomorrow :p Was an easy upgrade too, as there were minimal template changes coming from 3.6.2.

evenmonkeys
09 Nov 2006, 21:10
All 3.6.2 Mods work..
I know...

andrewrhs
11 Nov 2006, 16:15
upgraded, works perfectly :D

Phaedrus
12 Nov 2006, 05:05
Worked well for me. Very few template changes, easy to rework... Let's hope this one lasts for a bit. This gets tiring!

Shazz
12 Nov 2006, 05:09
Worked well for me. Very few template changes, easy to rework... Let's hope this one lasts for a bit. This gets tiring!
$50 they will come up with something (3.6.4) before Jan.
Its a big vB team, and they could re-work something like a vB 10.0

Phaedrus
12 Nov 2006, 05:21
$50 they will come up with something (3.6.4) before Jan.
Its a big vB team, and they could re-work something like a vB 10.0

No bet... What do you take me for? :tired:

Shazz
12 Nov 2006, 05:35
What Do I take you for?

evenmonkeys
12 Nov 2006, 05:52
$50 they will come up with something (3.6.4) before Jan.
Its a big vB team, and they could re-work something like a vB 10.0
And what's wrong with that? There's absolutely no way to cover every single flaw and security hole indefinitely. That's what a majority of the updates vBulletin sends out are. When someone reports a security issue, vBulletin has no other choice but to send out a repair for it. Would you rather they not do anything about it and let people's forum be hacked to pieces? I think not.

They do a damn good job keeping the best forum software available up to date and nearly flawless in comparison. It's not fair to criticize them. They do as much as they can with what information they have.

Shazz
12 Nov 2006, 05:55
And what's wrong with that? There's absolutely no way to cover every single flaw and security hole indefinitely. That's what a majority of the updates vBulletin sends out are. When someone reports a security issue, vBulletin has no other choice but to send out a repair for it. Would you rather they not do anything about it and let people's forum be hacked to pieces? I think not.

They do a damn good job keeping the best forum software available up to date and nearly flawless in comparison. It's not fair to criticize them. They do as much as they can with what information they have.
I wasen't critizing, i was responding to a comment that they will have one out soon again as well
Yes they do a good job... Forgot this forum is Really Serious talk

Ziki
12 Nov 2006, 17:41
I have a scanner which found two other security holes in vb but that darn thing doesn't display them until I buy it :D

Shazz
12 Nov 2006, 17:41
I have a scanner which found two other security holes in vb but that darn thing doesn't display them until I buy it :D
Link to what scanner your talking about?