• Register
    • Help

    striker  0 Items
    Currently Supporting
    • Home
    • News
      • VaultWiki News
      • Visit the Wiki
    • Forum
    • Wiki
    • Support
    • What's New?
    • Buy Now
    • Manual
    • 
    • Home
    • VaultWiki Security Update: September 2017

    1. Welcome to VaultWiki.org, home of the wiki add-on for vBulletin and XenForo!

      VaultWiki allows your existing forum users to collaborate on creating and managing a site's content pages. VaultWiki is a fully-featured and fully-supported wiki solution for vBulletin and XenForo.

      The VaultWiki Team encourages you to join our community of forum administrators and check out VaultWiki for yourself.

    • VaultWiki Security Update: September 2017

      by
      pegasus
      • View Profile
      • View Forum Posts
      • View Blog Entries
      • Visit Homepage
      • View Articles
      Published on September 13, 2017 12:03 PM
      0 Comments Comments
      As of September 13, 2017, the delayed, but otherwise regularly scheduled, security patches for September are now available.

      Issue List

      VWE-2017-3978 is a Remote Code Execution issue (previously disclosed) that requires a compromised DNS or a compromised remote server that VaultWiki is using as an import source. The issue affects VaultWiki 4.0.0 Beta 6 - 4.0.17, except lite versions. Versions 4.0.0 Beta 5 and earlier, as well as versions 4.0.18 and later, are not affected by this issue.

      VWE-2017-3979 is a Decompression Bomb issue (previously disclosed), which can be exploited to create a Denial of Service condition. The issue affects all versions of VaultWiki 4.x, except lite versions.

      VWE-2017-3981 is a Permissions Escalation issue, where it is possible to craft image proxy URLs manually without permission to use functions which generate proxy URLs normally, if the wiki was not installed properly. The issue affects VaultWiki 4.0.1 and later, except lite versions.

      VWE-2017-3992 is a Permissions Escalation issue, in which the previously uploaded images are still treated as images even though their dimensions exceed the permitted amounts, if that file-type is newly given image functionality or has its permitted dimensions changed. The issue affects all versions of VaultWiki 4.x, except lite versions.

      VWE-2017-3999 is a Data Loss issue in the Admin Panel's Mass Management Tools, in which content that does not meet the search criteria may be accidentally altered or removed if the prepared results are not carefully reviewed. The issue affects VaultWiki 4.0.18 and later.

      Patches

      The following patches, issued September 13, 2017, address the aforementioned issues:
      • 4.0.19 Patch Level 1
      • 4.0.18 Patch Level 2
      • 4.0.17 Patch Level 4
      • 4.0.16 Patch Level 5
      • 4.0.15 Patch Level 9
      • 4.0.14 Patch Level 12


      We highly recommend that all users running VaultWiki 4.x in a production environment update to a patched release.

      Notes

      The previously disclosed minor issue VWE-2017-4004 is not addressed by this release, but will be covered in the future. If you desire protection against that issue immediately, please follow the workaround instructions in the disclosure: https://www.vaultwiki.org/articles/2...04-update-9-12
    • Contact Us
    • License Agreement
    • Privacy
    • Terms
    • Top
    All times are GMT -4. The time now is 6:33 AM.
    This site uses cookies to help personalize content, to tailor your experience, and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Learn more… Accept Remind me later
  • striker
    Powered by vBulletin® Version 4.2.5 Beta 2
    Copyright © 2025 vBulletin Solutions Inc. All rights reserved.
    Search Engine Optimisation provided by DragonByte SEO (Pro) - vBulletin Mods & Addons Copyright © 2025 DragonByte Technologies Ltd.
    Copyright © 2008 - 2024 VaultWiki Team, Cracked Egg Studios, LLC.