<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Why does VulnDetect recommend older versions]]></title><description><![CDATA[<p dir="auto">In VulnDetect I get for some applications recommendations for <strong>older</strong> versions.<br />
<strong>Examples:</strong></p>
<ul>
<li>
<p dir="auto"><strong>Application</strong>: TeamSpeak 3 Client<br />
<strong>Installed Version</strong>: 3.2.3<br />
<strong>Recommended</strong>: 3.2.2</p>
</li>
<li>
<p dir="auto"><strong>Application</strong>: Vortex<br />
<strong>Installed Version</strong>: 0.16.10<br />
<strong>Recommended</strong>: 0.16.8</p>
</li>
<li>
<p dir="auto"><strong>Application</strong>: Elite Dangerous<br />
<strong>Installed Version</strong>: 3.2.1.300<br />
<strong>Recommended</strong>: 3.3.0.100</p>
</li>
</ul>
<p dir="auto">Why does VulnDetect suggest here an <strong>older</strong> version?<br />
Normally these recommendations means to see here a newer version, like</p>
<ul>
<li><strong>Application</strong>: Notepad++<br />
<strong>Installed Version</strong>: 7.5.8<br />
<strong>Recommended</strong>: 7.5.9</li>
</ul>
<p dir="auto">But here (on Notepad++) the status "OK" is also not correct.<br />
Here it should be "Outdated" or "Update available".<br />
I know we have a separate suggestion for this: <a href="https://vulndetect.org/topic/151/new-status-outdated-for-non-security-updates">https://vulndetect.org/topic/151/new-status-outdated-for-non-security-updates</a></p>
<p dir="auto">This is really very confusing...</p>
]]></description><link>https://vulndetect.org/topic/463/why-does-vulndetect-recommend-older-versions</link><generator>RSS for Node</generator><lastBuildDate>Sun, 14 Jun 2026 03:48:26 GMT</lastBuildDate><atom:link href="https://vulndetect.org/topic/463.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 06 Nov 2018 20:34:02 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Why does VulnDetect recommend older versions on Mon, 11 Mar 2019 20:25:48 GMT]]></title><description><![CDATA[<blockquote>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/olli_s" aria-label="Profile: OLLI_S">@<bdi>OLLI_S</bdi></a> Because only two users run Ahnenblatt, so we don't see it that fast.</p>
</blockquote>
<p dir="auto">I have it on my PC and also the current Beta in my VM.<br />
So maybe I am the "two users"...</p>
<blockquote>
<p dir="auto">And the English Ahnenblatt website is always after the German. So even on they day where we did add "recommended" for 2.99h, the English website still recommended 2.99g.</p>
</blockquote>
<p dir="auto">You are right, this is a mess...</p>
<blockquote>
<p dir="auto">Changing the recommended version is always something that requires manual work on our side, so just because someone installs a newer version, we will continue to recommend the "old" version until we confirm that the new version is official and recommended by the vendor.</p>
</blockquote>
<p dir="auto">I know that this is a manual action.<br />
But now I understand why you recommend the older version (because of the version on the English website).</p>
]]></description><link>https://vulndetect.org/post/2749</link><guid isPermaLink="true">https://vulndetect.org/post/2749</guid><dc:creator><![CDATA[OLLI_S]]></dc:creator><pubDate>Mon, 11 Mar 2019 20:25:48 GMT</pubDate></item><item><title><![CDATA[Reply to Why does VulnDetect recommend older versions on Mon, 11 Mar 2019 10:03:50 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/olli_s" aria-label="Profile: OLLI_S">@<bdi>OLLI_S</bdi></a> Because only two users run Ahnenblatt, so we don't see it that fast.<br />
And the English Ahnenblatt website is always after the German. So even on they day where we did add "recommended" for 2.99h, the English website still recommended 2.99g.</p>
<p dir="auto">Changing the recommended version is always something that requires manual work on our side, so just because someone installs a newer version, we will continue to recommend the "old" version until we confirm that the new version is official and recommended by the vendor.</p>
]]></description><link>https://vulndetect.org/post/2740</link><guid isPermaLink="true">https://vulndetect.org/post/2740</guid><dc:creator><![CDATA[Tom]]></dc:creator><pubDate>Mon, 11 Mar 2019 10:03:50 GMT</pubDate></item><item><title><![CDATA[Reply to Why does VulnDetect recommend older versions on Fri, 08 Mar 2019 14:50:59 GMT]]></title><description><![CDATA[<p dir="auto">Today I installed the version <strong>2.99h</strong> of <strong>Ahnenblatt</strong>.<br />
But VulnDetect <strong>recommends 2.99g</strong> (an older version).</p>
]]></description><link>https://vulndetect.org/post/2730</link><guid isPermaLink="true">https://vulndetect.org/post/2730</guid><dc:creator><![CDATA[OLLI_S]]></dc:creator><pubDate>Fri, 08 Mar 2019 14:50:59 GMT</pubDate></item><item><title><![CDATA[Reply to Why does VulnDetect recommend older versions on Sat, 02 Feb 2019 21:27:20 GMT]]></title><description><![CDATA[<p dir="auto"><strong><a class="plugin-mentions-user plugin-mentions-a" href="/user/tom" aria-label="Profile: Tom">@<bdi>Tom</bdi></a></strong> Today VulnDetect <strong>recommended version 0.10.11.0</strong>  although I have <strong>version 1.0.0.0</strong> installed.</p>
<p dir="auto"><img src="/assets/uploads/files/1549142493259-vulndetect_1.0.0.0_update_available.png" alt="VulnDetect_1.0.0.0_Update_Available.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">I wonder what happens when I click on the Update button? :confused:</p>
<p dir="auto">I know that this is just because you did not make 1.0.0.0 official or something like that.<br />
But for users this is very very confusing (especially when have <strong>not expanded the entry</strong>, then <strong>click on the Update button</strong> and <strong>get an older version installed</strong>.</p>
<p dir="auto">By the way: in my VM I have the same problem!<br />
<strong>So this seems to be a global issue!</strong></p>
]]></description><link>https://vulndetect.org/post/2626</link><guid isPermaLink="true">https://vulndetect.org/post/2626</guid><dc:creator><![CDATA[OLLI_S]]></dc:creator><pubDate>Sat, 02 Feb 2019 21:27:20 GMT</pubDate></item><item><title><![CDATA[Reply to Why does VulnDetect recommend older versions on Thu, 31 Jan 2019 15:28:46 GMT]]></title><description><![CDATA[<p dir="auto">OK, thank you!</p>
]]></description><link>https://vulndetect.org/post/2592</link><guid isPermaLink="true">https://vulndetect.org/post/2592</guid><dc:creator><![CDATA[OLLI_S]]></dc:creator><pubDate>Thu, 31 Jan 2019 15:28:46 GMT</pubDate></item><item><title><![CDATA[Reply to Why does VulnDetect recommend older versions on Thu, 31 Jan 2019 15:28:02 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/olli_s" aria-label="Profile: OLLI_S">@<bdi>OLLI_S</bdi></a> Yes, we will work on improving the suggestions within the right channels.<br />
I will test the VirtualBox rules over the coming days, since both 5.2 and 6.0 are maintained in parallel by the vendor at the moment.</p>
]]></description><link>https://vulndetect.org/post/2591</link><guid isPermaLink="true">https://vulndetect.org/post/2591</guid><dc:creator><![CDATA[Tom]]></dc:creator><pubDate>Thu, 31 Jan 2019 15:28:02 GMT</pubDate></item><item><title><![CDATA[Reply to Why does VulnDetect recommend older versions on Thu, 31 Jan 2019 15:08:52 GMT]]></title><description><![CDATA[<p dir="auto"><strong><a class="plugin-mentions-user plugin-mentions-a" href="/user/tom" aria-label="Profile: Tom">@<bdi>Tom</bdi></a></strong> I updated <strong>from 6.0.2 to 6.0.4</strong>.<br />
So I understand it when you <strong>recommended 6.0.2 or 6.0.0</strong>.<br />
What I don't understand that you recommended 5.2.24 <strong>although</strong> you have <strong>rules for 6.0.2 and 6.0.0</strong>.</p>
]]></description><link>https://vulndetect.org/post/2585</link><guid isPermaLink="true">https://vulndetect.org/post/2585</guid><dc:creator><![CDATA[OLLI_S]]></dc:creator><pubDate>Thu, 31 Jan 2019 15:08:52 GMT</pubDate></item><item><title><![CDATA[Reply to Why does VulnDetect recommend older versions on Thu, 31 Jan 2019 14:54:15 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/olli_s" aria-label="Profile: OLLI_S">@<bdi>OLLI_S</bdi></a> Because we didn't detect the new version before.<br />
You know that we have to see the (new) file version before we add a Specific Rule for it. Only for some products do we proactively add new Specific Rules before we actually see the new version. For most products it isn't much of an issue because users start installing the new version very short time after they are released from the vendors, and quite often we see the new versions before the release notes / announcements / security bulletins are published.</p>
]]></description><link>https://vulndetect.org/post/2580</link><guid isPermaLink="true">https://vulndetect.org/post/2580</guid><dc:creator><![CDATA[Tom]]></dc:creator><pubDate>Thu, 31 Jan 2019 14:54:15 GMT</pubDate></item><item><title><![CDATA[Reply to Why does VulnDetect recommend older versions on Tue, 29 Jan 2019 18:40:12 GMT]]></title><description><![CDATA[<p dir="auto"><strong><a class="plugin-mentions-user plugin-mentions-a" href="/user/tom" aria-label="Profile: Tom">@<bdi>Tom</bdi></a></strong> I have a new issue:<br />
Today I updated <strong>Oracle VirtualBox</strong> to version <strong>6.0.4</strong>.<br />
And the <strong>recommended version</strong> is <strong>5.2.24</strong>.</p>
<p dir="auto">This is totally confusing for the user.<br />
Why is such an old version recommended?<br />
It this <strong>recommendation is valid</strong> then you <strong>have to explain this to the user</strong> so he understands this.<br />
Otherwise <strong>he might</strong> think that <strong>VulnDetect is crap</strong>.</p>
]]></description><link>https://vulndetect.org/post/2573</link><guid isPermaLink="true">https://vulndetect.org/post/2573</guid><dc:creator><![CDATA[OLLI_S]]></dc:creator><pubDate>Tue, 29 Jan 2019 18:40:12 GMT</pubDate></item><item><title><![CDATA[Reply to Why does VulnDetect recommend older versions on Thu, 08 Nov 2018 13:34:26 GMT]]></title><description><![CDATA[<p dir="auto">Yes, that is a good question. I will check all the above again and update the Rules accordingly.</p>
<p dir="auto">However, what is important to understand is, that we often see new versions BEFORE the vendor changes the information on their website. For example, in the last two days, we've seen build 3177 of the Sublime text editor, but build 3177 is not listed on the site, not even as a dev or beta version, so build 3176 is still the recommended one. The same is often the case with Skype, we see the new version and two or three days later they update their changelog.</p>
<p dir="auto">When we don't see any posting about a new version, we will usually not recommend it - at least not for software where the vendor usually does post this information. But then there is exceptions like with some of the gaming software, where there is no official announcements and in these cases we just update the recommended to the highest version number we have seen.</p>
<p dir="auto">In short, if you see that the vendor starts to recommend a different version than we do, then make a post or send me a message on the chat and we shall update it as soon as possible.</p>
<p dir="auto">TeamSpeak: Updated<br />
Vortex: Updated to 0.16.12<br />
Elite Dangerous: 3.2.1.300 is the newest we have seen. Do you have a URL where we can see release information?</p>
<p dir="auto">We always show "OK" if the version hasn't been flagged as vulnerable. You have previously suggested that we make it more clear that it is outdated or that another version is recommended. This is something we are still considering, so no immediate plans to change this. I mean, it is "VulnDetect", not "OldVersionDetect" ;)</p>
<p dir="auto">But thank you for highlighting these cases :D</p>
]]></description><link>https://vulndetect.org/post/1760</link><guid isPermaLink="true">https://vulndetect.org/post/1760</guid><dc:creator><![CDATA[Tom]]></dc:creator><pubDate>Thu, 08 Nov 2018 13:34:26 GMT</pubDate></item></channel></rss>