1.2.1


Contents

[edit] Release

MyBB 1.2.1 was released on 27 September 2006 fixing a couple of security vulnerabilities as well as reported bugs.

A patch for MyBB 1.2.1 was released on 26 November 2006 to fix a security vulnerability. However the version number was not incremented for this update.

[edit] Announcement

[edit] Original Announcement (27 September 2006)

MyBB 1.2.1 is now available on the MyBB site and is a security update & bug fix maintenance release.

We've fixed several issues identified in MyBB 1.2 in this release and added support for Internet Explorer's HttpOnly cookies. There have also been some publicly disclosed security related issues (minor severity) identified with 1.2 and a more potentially high risk vulnerability which was not transitioned from 1.1.8 to 1.2 which are all fixed in this release.

We recommend that all users upgrade to 1.2.1 so their board is patched against these vulnerabilities and running a more stable copy of the MyBB 1.2 series.

More information can be found here: http://community.mybboard.net/showthread.php?tid=12705


[edit] Security Patch (26 November 2006)

It has come to our attention that a new vulnerability has been found in MyBB 1.2.1 which also affects MyBB 1.1.8 and all other previous versions of MyBB.

This vulnerability allows a hacker to upload a false GIF image which contains executable code which can then be used to obtain the authentication details for a logged in user viewing the page.

Immediately we're releasing a patch for both versions of MyBB which we're currently supporting. Both versions, 1.2.1 and 1.1.8 have also been updated on the MyBB site.

As a security precaution we also recommend that all administrators change their passwords.

More information can be found here: http://community.mybboard.net/showthread.php?tid=14090


1.4.x 1.4.1 - 1.4.0
1.2.x 1.2.14 - 1.2.13 - 1.2.12 - 1.2.11 - 1.2.10 - 1.2.9 - 1.2.8 - 1.2.7 - 1.2.6 - 1.2.5 - 1.2.4 - 1.2.3 - 1.2.2 - 1.2.1 - 1.2.0
1.1.x / 1.0x 1.1.8 - 1.1.7 - 1.1.6 - 1.1.5 - 1.1.4 - 1.1.3 - 1.1.2 - 1.1.1 - 1.1.0 - 1.04 - 1.03 - 1.02 - 1.01 - 1.00
Pre-1.0 PR2 - PR1 - RC4 - RC3 - RC2 - RC1 - Beta 4 - DevBB
Legend Italics: Development / Beta / Private Latest Public Release


This page was last modified 03:50, 14 April 2007.