=====================================================================
                                   CERT-Renater

                        Note d'Information No. 2008/VULN543
_____________________________________________________________________

DATE                      : 24/11/2008

HARDWARE PLATFORM(S)      : /

OPERATING SYSTEM(S)       : Systems running vBulletin versions prior to
                                 3.7.4 PL1.

======================================================================
http://www.vbulletin.com/forum/showthread.php?t=291665
______________________________________________________________________

 vBulletin 3.7.4 PL1 Released

vBulletin 3.7.4 PL1

An XSS flaw within the user control panel has recently been discovered.
This could allow an attacker to carry out an action as a user or obtain
access to a user's account. To resolve this issue, it is necessary to
release a patch level version of vBulletin 3.7.4.

vBulletin 3.6 is not affected. vBulletin 3.8 is affected, and the next
beta/release candidate will include the fix.

The upgrade process is the same as previous patch level releases - simply
download the patch from the Members Area, extract the files and upload to
your webserver, overwriting the existing files. There is no upgrade script
required.

As with all security-based releases, we recommend that all customers upgrade
as soon as possible in order to prevent any potential damage resulting from
the flaw being exploited.


Upgrading from 3.7.4

If you are already running 3.7.4, the process you will be required to follow
to make your board immune to this flaw is very simple.

There is no need to run an upgrade script if you are already running 3.7.4.

Visit the Patches section of the vBulletin Members' Area and download the patch
for 3.7.4, then extract the files from the archive you downloaded, then upload
the files to your board via FTP etc., overwriting the existing files. This will
update your version to the PL1 release.


Upgrading from Versions Earlier than 3.7.4

If you are not already running 3.7.4, you should download the latest version from
the Members' Area and perform an upgrade as normal.

Full instructions for upgrading vBulletin are available here.


Download vBulletin 3.7.4 PL1

As usual, the version released today is available for all customers with valid,
active licenses to download from the vBulletin Members' Area.

vBulletin Members Area




You can discuss this patch release in the existing 3.7.4 release discussion.
__________________
--Mike "Ed" Sullivan, Email
vBulletin Developer


======================================================================

          =========================================================
          Les serveurs de référence du CERT-Renater
          http://www.urec.fr/securite
          http://www.cru.fr/securite
          http://www.renater.fr
          =========================================================
          + CERT-RENATER          | tel : 01-53-94-20-44          +
          + 151 bd de l'Hopital   | fax : 01-53-94-20-41          +
          + 75013 Paris           | email: certsvp@renater.fr     +
          =========================================================




