Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 190112
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Matt Fleming (RETIRED) <mjf@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 190112 depends on: Show dependency tree
Bug 190112 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2007-08-24 22:58 0000
Some vulnerabilities and a security issue have been reported in
Bugzilla, which can be exploited by malicious users to inject shell
commands, and by malicious people to conduct cross-site scripting
attacks and to disclose potentially sensitive information.

1) Input passed to the "buildid" parameter when filing bugs using the
guided form is not properly sanitised before being returned to a user.
This can be exploited to execute arbitrary HTML and script code in a
user's browser session in context of an affected site.

The vulnerability is reported in version 2.17.1 and later.

2) The "Email::Send::Sendmail()" function does not properly sanitise
Bugzilla's "from" email information which is later passed to the "-f"
parameter of sendmail. This can be exploited to inject shell commands
via a specially crafted "from" setting.

The vulnerability is reported in version 2.23.4 and later.

3) The XML-RPC interface of Bugzilla allows to disclose certain
time-tracking information without proper access to the time-tracking
fields.

The security issue is reported in version 2.23.3 and above.

SOLUTION:
Update to a fixed version.

Bugzilla 2.20.x users:
Update to version 2.20.5.

Bugzilla 2.22.x users:
Update to version 2.22.3.

Bugzilla 3.0 users:
Update to version 3.0.1.

------- Comment #1 From Matt Fleming (RETIRED) 2007-08-24 23:01:27 0000 -------
Setting whiteboard status.

------- Comment #2 From Mike Doty 2007-08-25 00:36:09 0000 -------
infra has already verified our installation of bugzilla is unaffected by any of
the exploits listed.

------- Comment #3 From Jakub Moc (RETIRED) 2007-08-26 07:14:57 0000 -------
*** Bug 190267 has been marked as a duplicate of this bug. ***

------- Comment #4 From Gunnar Wrobel 2007-09-03 07:24:57 0000 -------
2.20.5, 2.22.3 and 3.0.1 have been added to the tree.

2.20.5 should be stabilized on

alpha amd64 ia64 ppc ppc64 sparc x86

(alternatively the arches can also stabilize the higher 2.22.3)

2.22.3 should be stabilized on

ia64 ppc64 sparc x86

Is there a specific reason to keep 2.18.6 in the tree? There is no update
available for this branch and I guess users of this branch should then upgrade
to 2.20.5.

------- Comment #5 From Pierre-Yves Rofes 2007-09-03 08:02:56 0000 -------
(In reply to comment #4)
> 2.20.5, 2.22.3 and 3.0.1 have been added to the tree.
> 
> 2.20.5 should be stabilized on
> 
> alpha amd64 ia64 ppc ppc64 sparc x86
> 
> (alternatively the arches can also stabilize the higher 2.22.3)
> 
> 2.22.3 should be stabilized on
> 
> ia64 ppc64 sparc x86
> 
> Is there a specific reason to keep 2.18.6 in the tree? There is no update
> available for this branch and I guess users of this branch should then upgrade
> to 2.20.5.
> 

Thanks Gunnar. cc'ing arches for stabilization.

------- Comment #6 From Markus Rothe 2007-09-03 08:07:56 0000 -------
quick update, quick test, quick stabilization: ppc64 stable

------- Comment #7 From Tobias Scherbaum 2007-09-03 18:09:55 0000 -------
ppc stable

------- Comment #8 From Christian Faulhammer 2007-09-04 06:55:02 0000 -------
x86 stable

------- Comment #9 From Jose Luis Rivero (yoswink) 2007-09-04 16:49:56 0000 -------
Sparc stable (2.20.5 and 2.23)

------- Comment #10 From Raúl Porcel 2007-09-04 18:24:36 0000 -------
alpha/ia64 stable

------- Comment #11 From Steve Dibb 2007-09-08 01:40:24 0000 -------
amd64 stable

------- Comment #12 From Gunnar Wrobel 2007-09-10 04:59:09 0000 -------
Removed insecure versions. webapps done here.

------- Comment #13 From Robin Johnson 2007-09-26 23:20:27 0000 -------
unsubbing our bugzilla alias, since bugs.g.o is not affected.

------- Comment #14 From Raphael Marichez 2007-09-30 22:04:39 0000 -------
GLSA 200709-18

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug