Exploit found in Yahoo YUI Uploader affecting VB4 and VB5 forums

Discussion in 'vBulletin Discussions' started by BirdOPrey5, Jan 3, 2014.

  1. BirdOPrey5

    BirdOPrey5 #Awesome

    343
    105
    418
    http://www.vbulletin.com/forum/foru...4388-yui-security-issue-found-in-uploader-swf

    Basically you need to overwrite clientscript/yui/uploader/assets/uploader.swf file with a blank/empty file of the same name.

    This will force VB4 to use the AJAX/JavaScript uploader instead.

    VB5 has the file but doesn't use it so no functionality will be lost in VB5, but VB4 users will lose the flash uploader.

    Yahoo says they will not be fixing the issue.

    VB3 is unaffected.
     
    too_cool_3 and Dan Hutter like this.
  2. AWS

    AWS Administrator Admin Talk Staff

    1,616
    693
    818
    Thanks Joe. This should affect a few products. I think others also use this.
     
  3. BirdOPrey5

    BirdOPrey5 #Awesome

    343
    105
    418
    Typo'ed the title- can't seem to fix it. :( Foung = Found, obviously. :oops:
     
    Last edited: Jan 3, 2014
  4. AWS

    AWS Administrator Admin Talk Staff

    1,616
    693
    818
    Fixed. Got to check permissions too while I'm at it. You should have edit permissions on the title.
     
    BirdOPrey5 likes this.
  5. zappaDPJ

    zappaDPJ Regular Member

    250
    165
    418
    Does anybody know what effect this will have on the functionality of the asset manager if any?
     
  6. BirdOPrey5

    BirdOPrey5 #Awesome

    343
    105
    418
    The asset manager continues to work, just uploads will be done via the AJAX form rather than the flash uploader.
     
    zappaDPJ likes this.
  7. jmurrayhead

    jmurrayhead Regular Member

    153
    113
    418
    I wonder why Yahoo decided not to fix the issue...are they working on a replacement?
     
  8. BirdOPrey5

    BirdOPrey5 #Awesome

    343
    105
    418
    Yahoo considers YUI 2.x end of life. They have YUI 3.x out but they do longer have a flash based uploader in YUI 3.x.
     
  9. jmurrayhead

    jmurrayhead Regular Member

    153
    113
    418
    Got ya, so basically vBulletin just needs to update to later version.
     
  10. zappaDPJ

    zappaDPJ Regular Member

    250
    165
    418
    OK, thanks, no disruption to my users then.
     
  11. BamaStangGuy

    BamaStangGuy Administrator

    769
    549
    518
  12. zappaDPJ

    zappaDPJ Regular Member

    250
    165
    418
    That's odd, I'm fairly sure I didn't quote myself in that post.
     
  13. WEfail

    WEfail Regular Member

    77
    179
    418
    Fixed this yesterday. Not sure why VB doesnt list the exploit in the admincp. Another fail.
     
  14. Dan Hutter

    Dan Hutter aka Big Dan

    1,412
    515
    818
    Thanks for the post @BirdOPrey5 as I haven't followed the vB.com boards in quite a while. I patched my clients boards.
     
  15. WEfail

    WEfail Regular Member

    77
    179
    418
    Birdofprey is amazing.
     
  16. Alfa1

    Alfa1 Regular Member

    303
    196
    418
    Yes, that was in 2009. vb4 & vb5 were released after YUI3.
     
  17. BirdOPrey5

    BirdOPrey5 #Awesome

    343
    105
    418
    YUI 3 beat VB4 by just a couple months... Couldn't throw everything out and change to YUI 3 at that point.
     
  18. NixFifty

    NixFifty Regular Member

    4
    3
    35
    Weekend? :)
     
  19. Alfa1

    Alfa1 Regular Member

    303
    196
    418
    I actually warned vbulletin about the issue long before that, as YUI2 beta releases were already flowing and at that time there also was a YUI2 exploit.
    At that time the wisest decision would have been to implement jQuery instead. Back then it was already clear that jQuery was the future.
     
  20. Peace

    Peace Regular Member

    100
    58
    394
    BirdOPrey5 likes this.

Share This Page