===================================================================== CERT-Renater Note d'Information No. 2013/VULN119 _____________________________________________________________________ DATE : 29/03/2013 HARDWARE PLATFORM(S): / OPERATING SYSTEM(S) : Systems running IP.Board versions up to and including 3.4, 3.3, 3.2, 3.1. ====================================================================== http://community.invisionpower.com/topic/382719-ipboard-31x-32x-33x-34x-critical-security-update/ ______________________________________________________________________ Security Update: 21 March 2013 As part of our ongoing security auditing we have discovered a possible security issue. We are releasing a critical security update today to address this issue. Instructions We are providing a patch for IP.Board versions 3.4, 3.3, 3.2, and 3.1. Version 3.1 is end of life for support but we are still providing the patch for the convenience of clients who have not yet upgraded. If you are running a version less than 3.1 you should upgrade to get this and other security enhancements. Patching is very easy: Identify the version of IP.Board you are running. Download and unzip the appropriate patch file below that matches your version. Upload the contents of the extracted "upload" folder to your IP.Board home directory If you have renamed your admin directory, then copy the files manually to the appropriate admin folder. IP.Board 3.4.x Attached File ipb34_mar21.zip 2.58K 3163 downloads IP.Board 3.3.x Attached File ipb33_mar21.zip 2.58K 878 downloads IP.Board 3.2.x Attached File ipb32_mar21.zip 2.65K 315 downloads IP.Board 3.1.x Attached File ipb31_mar21.zip 2.68K 354 downloads Notes: When you apply the security update the bulletin in your AdminCP will still display. We keep the bulletin in place for at least a week after a security release. Our main software packages accessed via the client area have already been updated with this security update. If you are an IPS Hosting client your community has been automatically patched. ====================================================================== ========================================================= Serveur de référence du CERT-Renater https://services.renater.fr/ssi/ ========================================================= + CERT-RENATER | tel : 01-53-94-20-44 + + 23 - 25 Rue Daviel | fax : 01-53-94-20-41 + + 75013 Paris | email: certsvp@renater.fr + =========================================================