Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 390787 (CVE-2011-4321) - <www-apps/joomla-1.5.25: Weak RNG leads to password weakness (CVE-2011-4321)
Summary: <www-apps/joomla-1.5.25: Weak RNG leads to password weakness (CVE-2011-4321)
Status: RESOLVED FIXED
Alias: CVE-2011-4321
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: http://developer.joomla.org/security/...
Whiteboard: ~3 [noglsa]
Keywords:
: 391929 (view as bug list)
Depends on:
Blocks:
 
Reported: 2011-11-17 04:24 UTC by Tim Sammut (RETIRED)
Modified: 2011-12-14 06:03 UTC (History)
4 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
patch for upgrade (joomla-1.5.25.patch,515 bytes, patch)
2011-12-08 23:39 UTC, Olivier Huber
no flags Details | Diff
patch for upgrade (joomla-1.7.3.patch,513 bytes, patch)
2011-12-08 23:39 UTC, Olivier Huber
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Tim Sammut (RETIRED) gentoo-dev 2011-11-17 04:24:01 UTC
From the upstream advisory at $URL:

Description

Weak random number generation during password reset leads to possibility of changing a user's password.

Affected Installs

Joomla! version 1.5.24 and all earlier 1.5 versions

Solution

Upgrade to the latest Joomla! 1.5 version (1.5.25 or later)
Comment 1 Olivier Huber 2011-11-17 09:23:29 UTC
First thank you for your work on making gentoo more secure.
I've already notify fauli about this. So the bump is on it's way.
But he's very busy right now.

Please note that 1.6.X and <1.7.3 are also affected by this vulnerability.
url: http://developer.joomla.org/security/news/374-20111102-core-password-change.html
Also 1.6.X and <1.7.3 are affected by a XSS vuln
url: http://developer.joomla.org/security/news/373-20111101-core-xss-vulnerability.html
This concerns us since we have 1.7.2 in the tree.
Comment 2 Christian Faulhammer (RETIRED) gentoo-dev 2011-11-17 20:50:45 UTC
Before end of November I will not come to this.  Bump it yourself please, should be straightforward.
Comment 3 Tim Sammut (RETIRED) gentoo-dev 2011-11-28 06:13:00 UTC
*** Bug 391929 has been marked as a duplicate of this bug. ***
Comment 4 Olivier Huber 2011-12-08 23:39:00 UTC
Created attachment 295231 [details, diff]
patch for upgrade

Somebody can apply this to bump joomla 1.5 in the tree
Comment 5 Olivier Huber 2011-12-08 23:39:59 UTC
Created attachment 295233 [details, diff]
patch for upgrade

Somebody can use this to bump Joomla 1.7
Comment 6 GLSAMaker/CVETool Bot gentoo-dev 2011-12-13 00:17:29 UTC
CVE-2011-4321 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-4321):
  The password reset functionality in Joomla! 1.5.x through 1.5.24 uses weak
  random numbers, which makes it easier for remote attackers to change the
  passwords of arbitrary users via unspecified vectors.
Comment 7 Christian Faulhammer (RETIRED) gentoo-dev 2011-12-13 19:46:38 UTC
ebuild added, thanks for the patience.
Comment 8 Tim Sammut (RETIRED) gentoo-dev 2011-12-14 06:03:13 UTC
Thanks, Christian. Closing noglsa.