==================================================================== CERT-Renater Note d'Information No. 2017/VULN105 _____________________________________________________________________ DATE : 07/04/2017 HARDWARE PLATFORM(S): / OPERATING SYSTEM(S): Systems running MyBB versions prior to 1.8.11, MyBB Merge System versions prior to 1.8.11. ===================================================================== https://blog.mybb.com/2017/04/04/mybb-1-8-11-merge-system-1-8-11-release/ ____________________________________________________________________ MyBB 1.8.11 & Merge System 1.8.11 Release Posted on April 4, 2017 by StefanT MyBB 1.8.11 is now available from the MyBB website, and is a security and maintenance release. What’s added/changed in this version? This release fixes 3 security vulnerabilities and 32 reported issues causing incorrect functionality of MyBB. Please be aware that not all issues have been fixed in this version in order to provide easy to manage updates. Vulnerabilities: High risk: XSS Injection in Email MyCode – reported by Zhiyang Zeng of Tencent security platform department Medium risk: SSRF protection can be bypassed – reported by Orange Tsai of DEVCORE and Jasveer Singh of SEC Consult Vulnerability Lab Low risk: Directory Traversal in smilie module – reported by Zhiyang Zeng of Tencent security platform department Bugs fixed: Fixed issues in 1.8.11 Unfixed issues Please view the 1.8.11 changes on the Docs site for more information about the changes in this version. Please note, that you do need to run the upgrade script for this version. Upgrading from 1.8.10 and Other Versions Before performing any upgrade please remember to backup your forum’s files and database and store them safely. If you have edited core files, including language files, please make sure you make a changelog for these changes so you can make them again (if necessary) once the upgrade is complete. To upgrade, follow the Upgrading process. The upgrade script is required. There are changes to 5 language files and 7 templates were changed or added. If you’re using MyBB 1.8.10: Download and use the Changed Files Package MD5: f99cdecf3d96c8c39441c81d8468e4f6 SHA1: 323bec46d3da051fe5e9899e1a4ffdd8e538b5f5 SHA256: f3a50f31dc6045e63ccad826fd4fa35f1240891238f4fbcdaeb724835cd58f4d SHA512: 4d9018f2e1f286dd447e4c4db0ba9be18b1c407ed63272711d11deb6a09d7e301967917d465e368d8ebdd046cc0c7c5a23308b8ed72f8d5f9e9307ba6a81f8e3 Follow the Docs Upgrading Instructions If you’re using MyBB 1.8.9 or lower: Download and use the full 1.8.11 Release Package MD5: d4d3de795b69b076264a007e7a989f64 SHA1: 5ca8bf23a8efe0940bfe3c6fba852676144ea134 SHA256: c95cf770fffb37f811bee17a828cea8f0c789f22069c1783f3fb6f567fa7ca43 SHA512: 9db6ec3894cd66a26dffb5682109e25073148f1c885f2e0638be8c7d95eb2ba5e16db6dc66087431e919d849acdb7c2c11c95e247e99f6f8f44bcc19fe721015 Follow the Docs Upgrading Instructions Reporting MyBB security vulnerabilities If you think you’ve found a vulnerability in MyBB, we advise you not to publicly post it on these forums or publicly release information about it elsewhere until we’ve had time to prepare and release a patch. As always, you can send through security related messages on the MyBB website from the Contact Us page or in our Private Inquiries forum – where you can start a new thread that only you and the MyBB Team can see. MyBB Merge System 1.8.11 MyBB Merge System 1.8.11 is now available on the MyBB website and is a maintenance update to the MyBB Merge 1.8 series. This release is to ensure that all users of MyBB Merge 1.8 have the latest fixes. What’s new in this version? 2 bug fixes (View all) Thanks, MyBB Team Note about updated packages The original packages have been replaced by updated packages to fix a compatibility issue causing warnings on certain PHP environments. If you installed or updated your forums using either the full or changed files packages prior to 19:00 on April 6, 2017 GMT please download a fresh package from the links above and replace the following file: inc/functions.php You do not need to run the installer or make any further changes. You can use the file verification tool to determine whether you have the latest package, the file above will appear to be modified if you need to download an updated copy. We apologise of any inconvenience. ========================================================== + CERT-RENATER | tel : 01-53-94-20-44 + + 23 - 25 Rue Daviel | fax : 01-53-94-20-41 + + 75013 Paris | email: cert@support.renater.fr + ==========================================================