vB 4.1.12 PL3 and 4.2 PL3 Released for Potential Yahoo! User Interface Library Exploit
FYI this has been fixed on both sites.
vB 4.1.12 PL3 and 4.2 PL3 Released for Potential Yahoo! User Interface Library Exploit A recent Yahoo! report indicated a potential SWF exploit vector involving the Yahoo! User Interface Library (YUI). Upon review, the vBulletin team has determined that the vBulletin 4 Asset Manager is affected. Once the issue was identified, updated YUI files were requested from Yahoo! to eliminate the reported threat.
This issue affects ALL vBulletin 4 SUITE and FORUM versions.
Security patches have been released for vBulletin 4.1.12 and vBulletin 4.2. Patches are available at http://members.vbulletin.com. As with all security-based releases, we recommend that all affected customers upgrade as soon as possible. vBulletin 4 customers not running 4.1.12 or 4.2 can address the potential exploit by updating their Server Settings and Optimization Options using the following steps:
Log into your Admin CP.
Expand the "Settings" menu in the leftnav.
Click on the "Options" link.
Select "Server Settings and Optimization Options" from the list and click the "Edit Settings" button.
Make sure "Yahoo!" is selected in the "Use Remote YUI" section.
Scroll to the bottom of the screen and click the "Save" button.
This change will set your forum to use the latest YUI files hosted by Yahoo!. The potential exploit vector will be closed once you've performed this change. It is strongly recommended that you do so immediately. Please note, this YUI issue only affects vBulletin 4. vBulletin 3 and vBulletin 5 forums are not affected. Yahoo!'s announcement regarding the potential YUI exploit can be found here - http://www.vbulletin.com/go/yuiswfexploit The Support forum thread on this topic can be found here - http://www.vbulletin.com/go/yuiswfexploitthread
This is an attempt to block spam at the server level. I will be monitoring the results to detect any increased rate of false positives, loss of legitimate traffic, or possible success rate with these catching mechanisms over the next couple days.
* Spam-o-Matic software update to version 2.1.0.
* Link Removed script re-written and updated. Will only show 30 days of activity.
* 2013-02-06: PHP updated from 5.3.19 to 5.3.21. Various additional server OS updates.
* 2013-02-08: Link Removed has been updated to use jQuery and external JavaScript.
* 2013-02-08: Ability to highlight text and auto quote it is now available as a feature.
* 2012-02-08: Additional comment ability using Facebook social plugin.
* 2012-02-08: Restored syndication integrity.
* 2013-03-21: Link Removed timer to prevent spam bot registration.
* 2013-03-21: Continued work on single-sign on integration (pending).
* 2013-03-21: PHP was updated.
* 2013-03-27: Thread Starter ID code updated (Thanks to Richard - nmsuk)
* 2013-03-28: CloudFlare enabled and mod_cloudflare installed.
* 2013-03-28: MaxCDN provisioning for Asia underway.
* 2013-04-09: The Singapore CDN (content delivery network) edge server has been provisoned.
* 2013-04-09: It is now possible to embed PDF files into posts. See "Embed PDF": Link Removed
* 2013-04-24: Forums have been updated to vBulletin 4.2.1. vBulletin 4.2.1 contains a total of 143 bug fixes, improvement requests, and feature requests. More info @ vBulletin Community Forum
* 2013-06-01: As part of our regularly scheduled maintenance, our web server software and PHP were updated tonight. This should fix some rather uncommon bugs, improve performance in some instances, and set the groundwork for more significant upgrades. Among such technical changes (release note references follow):
Added ability to use sendfile() to send back dynamic responses.
Updated in-GUI settings explanations.
Added option to stop the server from aborting external application processes even when the client connection has been broken.
Added PHP suEXEC daemon ability to kill runaway child processes.
Reserved connections for the WebAdmin console to ensure accessibility regardless of the current number of connections.
Added CGI daemon ability to log processes killed by signals to stderr.
Fixed FileETag directive and rewrite rule incompatibility.
Fixed FreeBSD realtime stats error.
Updated PHP build utility to support up to PHP 5.3.25 and 5.4.15.
Discontinued support for Solaris SPARC.
PHP Core:
Fixed bug #64578 (debug_backtrace in set_error_handler corrupts zend heap: segfault).
Fixed bug #64458 (dns_get_record result with string of length -1).
Fixed Windows x64 version of stream_socket_pair() and improved error handling.
Zip:
Fixed bug #64342 (ZipArchive::addFile() has to check for file existence).
As always, we continue to work to improve our service offerings and thank you for your support, insofar that none of this would be possible without the continued participation of our community.