First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 244741
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: eleanor <evangeline.eleanor@gmail.com>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
ktorrent-3.1.3-upload.patch ktorrent-3.1.3-upload.patch text/plain Robert Buchholz 2008-10-28 14:59 0000 734 bytes Details
ktorrent-3.1.3-php-injection.patch ktorrent-3.1.3-php-injection.patch text/plain Robert Buchholz 2008-10-28 14:59 0000 1.21 KB Details
ktorrent-2.2.7-upload.patch ktorrent-2.2.7-upload.patch text/plain Robert Buchholz 2008-10-28 15:00 0000 826 bytes Details
ktorrent-2.2.7-php-injection.patch ktorrent-2.2.7-php-injection.patch text/plain Robert Buchholz 2008-10-28 15:00 0000 1.33 KB Details
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 244741 depends on: Show dependency tree
Bug 244741 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2008-10-28 11:31 0000
Some vulnerabilities have been discovered in KTorrent, which can be exploited
by malicious users to compromise a vulnerable system and malicious people to
bypass certain security restrictions.

1) The web interface plugin does not properly restrict access to the torrent
upload functionality. This can be exploited to upload arbitrary torrent files
by sending specially crafted HTTP POST request to the affected application.

2) The web interface plugin does not properly sanitise request parameters
before passing them to the PHP interpreter. This can be exploited to inject and
execute arbitrary PHP code by passing specially crafted parameters to the PHP
scripts of the web interface.

Successful exploitation of the vulnerabilities requires that the web interface
plugin is enabled (not the default setting).

The vulnerabilities are confirmed in version 3.1.3. Prior versions may also be
affected.

Reproducible: Always




Not a very good solution: update to version 3.1.4.

------- Comment #1 From Craig (Security Padawan) 2008-10-28 12:54:26 0000 -------
http://secunia.com/advisories/32442/
We have 3.1.4 in the tree, the advisory says only 3.x is vulnerable.
Topic and whiteboard should be changed accordingly.
Maintainers: Can we remove the vulnerable version 3.1.3?

Unfortunately, I don't have edit rights.

------- Comment #2 From Robert Buchholz 2008-10-28 14:58:46 0000 -------
Note that the 2.x version of ktorrent is also affected for both issues (file
upload, and php command execution).

The upload issue can be exploited by unauthorized users to start
downloads/seeding for a given torrent. I could not exploit the second issue to
execute code when not authorized to the system.

------- Comment #3 From Robert Buchholz 2008-10-28 14:59:32 0000 -------
Created an attachment (id=170106) [edit]
ktorrent-3.1.3-upload.patch

Upstream 3.1.4 patch for issue (1).

------- Comment #4 From Robert Buchholz 2008-10-28 14:59:47 0000 -------
Created an attachment (id=170108) [edit]
ktorrent-3.1.3-php-injection.patch

Upstream 3.1.4 patch for issue (2).

------- Comment #5 From Robert Buchholz 2008-10-28 15:00:07 0000 -------
Created an attachment (id=170109) [edit]
ktorrent-2.2.7-upload.patch

Backported 2.2.7 patch for issue (1).

------- Comment #6 From Robert Buchholz 2008-10-28 15:00:27 0000 -------
Created an attachment (id=170111) [edit]
ktorrent-2.2.7-php-injection.patch

Backported 2.2.7 patch for issue (2).

------- Comment #7 From Juan Aguado 2008-11-02 10:55:59 0000 -------
FYI, a 2.2.8 version has been released today to fix this problem.

------- Comment #8 From Robert Buchholz 2008-11-02 12:25:26 0000 -------
net-p2p, please bump

------- Comment #9 From Robert Buchholz 2008-11-27 19:05:20 0000 -------
ping

------- Comment #10 From Tomáš Chvátal 2008-11-28 11:50:19 0000 -------
Ok now you can CC archies so they stable 2.2.8 asap and remove 2.2.7.

------- Comment #11 From Robert Buchholz 2008-11-28 15:51:15 0000 -------
Arches, please test and mark stable:
=net-p2p/ktorrent-2.2.8
Target keywords : "amd64 ppc ppc64 sparc x86"

------- Comment #12 From Markus Meier 2008-11-28 20:19:37 0000 -------
amd64/x86 stable

------- Comment #13 From Tobias Scherbaum 2008-11-28 21:56:18 0000 -------
ppc stable

------- Comment #14 From Friedrich Oslage 2008-12-01 22:09:36 0000 -------
sparc stable

------- Comment #15 From Craig (Security Padawan) 2009-01-05 22:57:45 0000 -------
pp64: *ping*

------- Comment #16 From Brent Baude 2009-01-06 02:48:02 0000 -------
ppc64 done

------- Comment #17 From Tomáš Chvátal 2009-01-06 15:36:04 0000 -------
Looks like all archies done, so closing.
Thanks for cooperation :]

------- Comment #18 From Christian Hoffmann 2009-01-06 16:13:34 0000 -------
Please don't simply close security bugs.
C1, if it proves to be correct, requires a GLSA.

------- Comment #19 From Tobias Heinlein 2009-01-06 19:59:17 0000 -------
Thank you, Christian.

... and I vote YES.

------- Comment #20 From Tobias Heinlein 2009-01-06 20:05:52 0000 -------
C1 is correct in my view. This is major severity and needs a GLSA. Request
filed.

------- Comment #21 From Pierre-Yves Rofes 2009-02-23 21:49:10 0000 -------
GLSA 200902-05, sorry for the delay.

First Last Prev Next    No search results available      Search page      Enter new bug