Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 237404 (CVE-2008-4102) - www-apps/joomla < 1.5.7 Multiple vulnerabilities (CVE-2008-{4102,4103,4104,4105})
Summary: www-apps/joomla < 1.5.7 Multiple vulnerabilities (CVE-2008-{4102,4103,4104,41...
Status: RESOLVED FIXED
Alias: CVE-2008-4102
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High enhancement (vote)
Assignee: Gentoo Security
URL: http://www.joomla.org/announcements/r...
Whiteboard: ~3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2008-09-11 17:25 UTC by Hanno Böck
Modified: 2008-09-21 14:15 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Hanno Böck gentoo-dev 2008-09-11 17:25:38 UTC
See here:
http://www.joomla.org/announcements/release-news/5212-joomla-157-security-release-now-available.html

Joomla page is currently down, so I can't tell more atm.
Comment 1 Robert Buchholz (RETIRED) gentoo-dev 2008-09-19 15:28:58 UTC
CVE-2008-4102 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-4102):
  Joomla! 1.5 before 1.5.7 initializes PHP's PRNG with a weak seed,
  which makes it easier for attackers to guess the pseudo-random values
  produced by PHP's mt_rand function, as demonstrated by guessing
  password reset tokens, a different vulnerability than CVE-2008-3681.

CVE-2008-4103 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-4103):
  The mailto (aka com_mailto) component in Joomla! 1.5 before 1.5.7
  sends e-mail messages without validating the URL, which allows remote
  attackers to transmit spam.

CVE-2008-4104 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-4104):
  Multiple open redirect vulnerabilities in Joomla! 1.5 before 1.5.7
  allow remote attackers to redirect users to arbitrary web sites and
  conduct phishing attacks via a "passed in" URL.

CVE-2008-4105 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-4105):
  JRequest in Joomla! 1.5 before 1.5.7 does not sanitize variables that
  were set with JRequest::setVar, which allows remote attackers to
  conduct "variable injection" attacks and have unspecified other
  impact.

Comment 2 Gunnar Wrobel (RETIRED) gentoo-dev 2008-09-21 13:24:05 UTC
Added joomla-1.5.7, removed vulnerable joomla-1.5.5, -1.5.6. Unstable on all arches, masked for security reasons anyhow. Webapps done.