+ Reply to Thread
Results 1 to 5 of 5




  

Thread: vBulletin 3.6.5 Released

      
  1. #1
    Grand Masters Colleen has a reputation beyond reputeColleen has a reputation beyond reputeColleen has a reputation beyond reputeColleen has a reputation beyond reputeColleen has a reputation beyond reputeColleen has a reputation beyond reputeColleen has a reputation beyond reputeColleen has a reputation beyond reputeColleen has a reputation beyond reputeColleen has a reputation beyond reputeColleen has a reputation beyond repute Colleen's Avatar
    Join Date
    September 22, 2006
    Location
    Canada
    Posts
    11,144
    Rep Power
    26
    Feedback Score
    0

    Exclamation vBulletin 3.6.5 Released

    Well at least this time there was a longer timespan between releases:

    This morning, an exploit was reported, which affects vBulletin versions 3.5.x and 3.6.x. Although the report is inaccurate and the published exploit does not work as claimed unless a highly unlikely set of circumstances exist, it has highlighted a potential security issue in these vBulletin versions.

    Therefore, we have decided to release updated versions, these being vBulletin 3.5.8 and 3.6.5. We recommend that all customers running vBulletin 3.5.x or 3.6.x upgrade to the appropriate version or apply the supplied patch as soon as possible.

    It is worth noting that in order to exploit the problem highlighted by the report, the attacking user must satisfy the following conditions:

    * Must already have moderator privileges
    * Must share the same IP address (or the number of IP octets specified in the Admin Control Panel for IP address matching) with an existing administrator who is currently logged in to the Admin Control Panel
    * Must know the Alt-IP and user agent (exact browser identification) of the administrator
    * OR must know the license number of the site being attacked

    Given these requirements, the privilege escalation exploit claimed by the report is almost impossible to achieve.
    MORE: http://www.vbulletin.com/forum/showthread.php?t=221905

  2. #2
    Favors Da Nooners! Kaos has a reputation beyond reputeKaos has a reputation beyond reputeKaos has a reputation beyond reputeKaos has a reputation beyond reputeKaos has a reputation beyond reputeKaos has a reputation beyond reputeKaos has a reputation beyond reputeKaos has a reputation beyond reputeKaos has a reputation beyond reputeKaos has a reputation beyond reputeKaos has a reputation beyond repute Kaos's Avatar
    Join Date
    October 28, 2006
    Location
    upstate NY
    Posts
    2,906
    Rep Power
    7
    Feedback Score
    0

    Default

    If someone is going to those extremes to hack into a forum... its insane! I guess beware of all mods j/k
    Good tip though, thanks.

  3. #3
    Grand Masters Colleen has a reputation beyond reputeColleen has a reputation beyond reputeColleen has a reputation beyond reputeColleen has a reputation beyond reputeColleen has a reputation beyond reputeColleen has a reputation beyond reputeColleen has a reputation beyond reputeColleen has a reputation beyond reputeColleen has a reputation beyond reputeColleen has a reputation beyond reputeColleen has a reputation beyond repute Colleen's Avatar
    Join Date
    September 22, 2006
    Location
    Canada
    Posts
    11,144
    Rep Power
    26
    Feedback Score
    0

    Default

    Real lame people even do that crap, must be kids.

  4. #4
    The Force is Strong! Saagar is on a distinguished road Saagar's Avatar
    Join Date
    January 3, 2007
    Location
    Minneapolis, US
    Posts
    156
    Rep Power
    6
    Feedback Score
    0

    Default

    that's not all, may be for the first time VB team has clearly hinted 3.6.6 is coming before 4.x

    I updated my forum sw

  5. #5
    I'm New! arindra is on a distinguished road arindra's Avatar
    Join Date
    March 8, 2007
    Location
    Kolkata India
    Posts
    28
    Rep Power
    6
    Feedback Score
    0

    Default

    it doesnt have any template changes anyway ... so no harm in updating .

+ Reply to Thread

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

     

Similar Threads

  1. vBulletin 3.6.9 Released
    By Big Dan in forum Forum Management
    Replies: 8
    Last Post: Apr 8th, 2008, 10:59 pm
  2. vBulletin 3.7 RC2 Released
    By EmmaB in forum Forum Management
    Replies: 4
    Last Post: Apr 1st, 2008, 6:39 pm
  3. vBulletin Patch Released for 3.6.8 ONLY
    By Big Dan in forum Forum Management
    Replies: 3
    Last Post: Oct 17th, 2007, 3:56 pm
  4. vBulletin 3.6.4 Released
    By Ohiosweetheart in forum Forum Management
    Replies: 18
    Last Post: Nov 29th, 2006, 9:17 am
  5. vBulletin 3.6.3 Released
    By Ohiosweetheart in forum Forum Management
    Replies: 3
    Last Post: Nov 8th, 2006, 9:52 am

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
WebTalkForums
WebTalkForums
Recent Forum Threads