Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 182262
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Emanuele Gentili <bathym@0x656d67.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 182262 depends on: Show dependency tree
Bug 182262 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2007-06-16 21:05 0000
The JSP examples web application displays does not escape some user
provided data before including it in the output. This enables a XSS
attack.

Reproducible: Always

Steps to Reproduce:
1. Undeploy the examples web application(s).

Example:
http://host:port/jsp-examples/snp/snoop.jsp;<script>alert()</script>test.jsp

------- Comment #1 From Emanuele Gentili 2007-06-16 21:05:47 0000 -------
Versions Affected:
Tomcat 4.0.0 to 4.0.6
Tomcat 4.1.0 to 4.1.36
Tomcat 5.0.0 to 5.0.30
Tomcat 5.5.0 to 5.5.24
Tomcat 6.0.0 to 6.0.13

------- Comment #2 From Sune Kloppenborg Jeppesen 2007-06-16 22:03:57 0000 -------
java please advise.

------- Comment #3 From William L. Thomson Jr. (RETIRED) 2007-06-16 22:16:52 0000 -------
We do not enable the examples USE flag by default. So by default they are not
installed. Really only people new to Tomcat will set and use that flag. I would
be surprised if many using it in production or an env where it's likely to be
exploited have the examples USE flag set.

There is also an exploit in the manager app
http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-2450

But that requires log in to exploit. Being as how upstream nor us provides a
default log in. That's also a pretty far off exploit.

I guess like upstream we can deem both to be low severity. Not sure if we need
to do anything specific. Other than announce it and warn users. Guess we could
disable examples USE flag as an extreme.

I can add pkg_postinst messages warning when examples is set. Manager webapp is
likely used more often.

------- Comment #4 From Sune Kloppenborg Jeppesen 2007-06-17 08:07:27 0000 -------
I guess a small warning in the ebuild output should be enough.

------- Comment #5 From William L. Thomson Jr. (RETIRED) 2007-06-17 15:54:56 0000 -------
Ok I added a warning to pkg_postinst about both exploits. Also provided links
to both so users can be informed. Should be good to go there. Just need an
announcement or etc, then security can close bug per normal procedures.

------- Comment #6 From Sune Kloppenborg Jeppesen 2007-06-23 18:05:37 0000 -------
This one is ready for GLSA decision. I vote NO.

------- Comment #7 From Matt Drew 2007-06-25 14:00:24 0000 -------
I also vote NO.

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug