Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 231579 (CVE-2008-3225) - www-apps/joomla < 1.5.4: Multiple vulnerabilities (CVE-2008-{3225,3226,3227,3228})
Summary: www-apps/joomla < 1.5.4: Multiple vulnerabilities (CVE-2008-{3225,3226,3227,3...
Status: RESOLVED FIXED
Alias: CVE-2008-3225
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High trivial (vote)
Assignee: Gentoo Security
URL: http://secunia.com/advisories/30974/
Whiteboard: ~4? [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2008-07-12 12:06 UTC by Hanno Böck
Modified: 2008-07-31 21:10 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Hanno Böck gentoo-dev 2008-07-12 12:06:34 UTC
I know joomla is security-masked, but as long as we keep the ebuilds, we should take care of security bugs anyway. From 1.5.4-changelog:

    * LDAP security fix to prevent unauthorized access to administration
    * Added security to file caching to prevent unauthorized access to cached pages
    * User Redirect Spam fix
    * htaccess global variable security fix when SEF is enabled (See .htaccess Security Fix)
Comment 1 Matthias Geerdsen (RETIRED) gentoo-dev 2008-07-12 18:59:07 UTC
thanks Hanno

web-apps, please provide an updated ebuild
Comment 2 Robert Buchholz (RETIRED) gentoo-dev 2008-07-22 15:44:44 UTC
CVE-2008-3225 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3225):
  Joomla! before 1.5.4 allows attackers to access administration functionality,
  which has unknown impact and attack vectors related to a missing "LDAP
  security fix."

CVE-2008-3226 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3226):
  The file caching implementation in Joomla! before 1.5.4 allows attackers to
  access cached pages via unknown attack vectors.

CVE-2008-3227 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3227):
  Unspecified vulnerability in Joomla! before 1.5.4 has unknown impact and
  attack vectors related to a "User Redirect Spam fix," possibly an open
  redirect vulnerability.

CVE-2008-3228 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3228):
  Joomla! before 1.5.4 does not configure .htaccess to apply certain security
  checks that "block common exploits" to SEF URLs, which has unknown impact and
  remote attack vectors.
Comment 3 Gunnar Wrobel (RETIRED) gentoo-dev 2008-07-31 21:04:50 UTC
Bumped to 1.5.5. Removed 1.5.3. webapps done.
Comment 4 Pierre-Yves Rofes (RETIRED) gentoo-dev 2008-07-31 21:10:48 UTC
thanks, closing without glsa.