PhotoPost Photo Gallery Sales PhotoPost Sales Toll Free Phone Number
Mon-Fri 9am-4pm EST
  PhotoPost Photo Sharing Photo Gallery    Visualize community tm
| | | | | | | | |
Old April 23rd, 2010, 11:07 AM   #1 (permalink)
Member
Verified Customer
 
Join Date: Feb 2002
Posts: 47
Problem with patch recommended for vB Gallery 2.4.2

I am dealing with the security issue for a client.

In this message:
Security Notice: Update for vBGallery v2.5

You say we have to patch "profile_start.php" in /forums/includes/vbgallery/ but the file doesn't exist on the sites I am managing for a client?

Does this vulnerability only exist in this file? Therefore if the file is not on the server, they are immune to the threat?
c0bra is offline   Reply With Quote
Old April 23rd, 2010, 11:19 AM   #2 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 71,669
Actually in the thread we announced there are two downloads.

1. There is a text file that releases php file in older versions

2. There is a plugin txt file to replace the contents of the profile_start plugin for vbgallery

So you would use whichever one is for your version. You are going to have a file or a plugin
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is offline   Reply With Quote
Old April 23rd, 2010, 11:33 AM   #3 (permalink)
Member
Verified Customer
 
Join Date: Feb 2002
Posts: 47
I know the plugin doesn't exist in 2.4.2. Your advisory says its for 2.5+.

I can't find the file you are telling us to patch in any 2.4.2 installations either.
c0bra is offline   Reply With Quote
Old April 23rd, 2010, 11:38 AM   #4 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 71,669
Potential SQL Injection

The download thread was attached in the email. I beleive Michael has explained which is the plugin and which is the php file there.
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is offline   Reply With Quote
Old April 26th, 2010, 06:37 AM   #5 (permalink)
Member
Verified Customer
 
Join Date: Feb 2002
Posts: 47
I have fully understood the information Michael presented. What I don't understand, is why our 2.4.2 installs are missing the apparently vulnerable profile_start.php file. Was this an optional component? Or was it included by default in all installs/upgrades?

And if we don't have the file on our server, and the profile_start plugin is also not present on our site, are we safe from this attack?
c0bra is offline   Reply With Quote
Old April 26th, 2010, 07:05 AM   #6 (permalink)
Member
Verified Customer
 
Join Date: Nov 2005
Location: Southern Germany
Posts: 213
Checked an old 2.4.2 folder and there isn't indeed a profile_start.php file. Than there shouldn't be a risk for you?
Ramses is offline   Reply With Quote
Old April 26th, 2010, 01:29 PM   #7 (permalink)
Member
Verified Customer
 
Join Date: Feb 2002
Posts: 47
Quote:
Originally Posted by Ramses View Post
Checked an old 2.4.2 folder and there isn't indeed a profile_start.php file. Than there shouldn't be a risk for you?
Thanks. That's what I am trying to figure out. Either the risk isn't present in 2.4.2, or the code is lurking somewhere else.
c0bra is offline   Reply With Quote
Old April 26th, 2010, 02:12 PM   #8 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 71,669
well not a problem in 2.42 I think everything is a plugin so you download the plugin not the php file.
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is offline   Reply With Quote
Old April 26th, 2010, 09:43 PM   #9 (permalink)
Member
Verified Customer
 
Join Date: Feb 2002
Posts: 47
Quote:
Originally Posted by Chuck S View Post
well not a problem in 2.42 I think everything is a plugin so you download the plugin not the php file.
There is no profile_start plugin in 2.4.2 either though. Could you clarify with developers the situation? Maybe the advistory is wrong and 2.4.2 is not affected by this vulnerability. It would be good to get some clarification.
c0bra is offline   Reply With Quote
Old April 27th, 2010, 12:24 AM   #10 (permalink)
Registered User
 
Join Date: Aug 2005
Posts: 1,229
Quote:
Originally Posted by c0bra View Post
There is no profile_start plugin in 2.4.2 either though. Could you clarify with developers the situation? Maybe the advistory is wrong and 2.4.2 is not affected by this vulnerability. It would be good to get some clarification.
Well in the advisory there is a link:
Original Advisory
http://archives.neohapsis.com/archives/bugtraq/2010-03/0236.html

there you find:
Quote:
Versions
---------
Affected Version(s): 2.5
Not affected Versions: Versions prior to 2.5
this is not quite correct...
affected are 2.43 and 2.5 (that is why michael posted 2 fixes)
because that was when vbulletin introduced the tabbed profile..
versions prior to 2.43 | i.e. 2.42 for vbulletin 3.6 are NOT affected because they do not have this plugin.

Luc
Luciano is offline   Reply With Quote
Old April 27th, 2010, 05:48 AM   #11 (permalink)
Member
Verified Customer
 
Join Date: Feb 2002
Posts: 47
Luciano,

Yep I read the Bugtraq announcement.

But Michael announced:
Quote:
Attached is a new profile_start.php script for versions 2.0-2.4.X.
2.0-2.4.X implies that every release since version 2.0 is affected. But thanks for clarifying what I assumed was correct.
c0bra is offline   Reply With Quote
Old April 27th, 2010, 10:16 AM   #12 (permalink)
Registered User
 
Join Date: Aug 2005
Posts: 1,229
That was said because only vbgallery 2.0-2.43 had plugins as files...
the version above have plugins as code...
Luc
Luciano is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
meta description patch - browsimages.php Zachariah Bugs - vBulletin 3.6x 1 December 26th, 2008 01:39 PM
vBulletin 3.0.7 Released - Security Patch kl General Discussion 6 February 22nd, 2005 11:48 AM
4.86 Patch did not included manually fixes. lakerszone Photopost Pro Installation & Upgrades 1 January 4th, 2005 11:47 AM


All times are GMT -5. The time now is 11:34 AM.

Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0