Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 399553 (CVE-2012-0790) - <net-analyzer/smokeping-2.6.9 - "displaymode" Cross-Site Scripting Vulnerability (CVE-2012-0790)
Summary: <net-analyzer/smokeping-2.6.9 - "displaymode" Cross-Site Scripting Vulnerabil...
Status: RESOLVED FIXED
Alias: CVE-2012-0790
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://secunia.com/advisories/47678/
Whiteboard: B4 [noglsa]
Keywords:
: 385549 (view as bug list)
Depends on:
Blocks:
 
Reported: 2012-01-20 20:50 UTC by Agostino Sarubbo
Modified: 2013-08-22 09:50 UTC (History)
4 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2012-01-20 20:50:52 UTC
From secunia security advisory at $URL:


Description:
Input passed via the "displaymode" parameter to smokeping_cgi is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.

The vulnerability is reported in version 2.6.6. Prior versions may also be affected.


Solution:
Update to version 2.6.7.
Comment 1 Agostino Sarubbo gentoo-dev 2012-01-20 20:51:20 UTC
*** Bug 385549 has been marked as a duplicate of this bug. ***
Comment 2 Michael Palimaka (kensington) gentoo-dev 2013-05-21 12:12:11 UTC
(In reply to comment #0)
> Solution:
> Update to version 2.6.7.

2.6.8 has been in the tree for a long time so we could request stabilisation.
Comment 3 Sergey Popov gentoo-dev 2013-07-09 08:24:56 UTC
(In reply to Michael Palimaka (kensington) from comment #2)
> 2.6.8 has been in the tree for a long time so we could request stabilisation.

It seems that 2.6.8 requires some additional dependencies:

   net-analyzer/smokeping/smokeping-2.6.8-r1.ebuild: DEPEND: amd64(default/linux/amd64/13.0) ['>=net-analyzer/echoping-6.0.2', 'dev-perl/RadiusPerl', 'dev-perl/Net-OpenSSH']
   net-analyzer/smokeping/smokeping-2.6.8-r1.ebuild: DEPEND: x86(default/linux/x86/13.0) ['dev-perl/RadiusPerl', 'dev-perl/Net-OpenSSH']
Comment 4 Jeroen Roovers (RETIRED) gentoo-dev 2013-07-09 12:14:42 UTC
2013/03/04 - released version 2.6.9

*  be more careful about preventing xss attacks, re http://bugs.debian.org/659899 (tobi)
Comment 5 Jeroen Roovers (RETIRED) gentoo-dev 2013-07-09 12:59:50 UTC
Arch teams, please test and mark stable:

=net-analyzer/smokeping-2.6.9

=dev-perl/RadiusPerl-0.220.0
=dev-perl/Data-HexDump-0.02

=dev-perl/Net-OpenSSH-0.600.0
=dev-perl/Net-SFTP-Foreign-1.730.0

=net-analyzer/echoping-6.0.2-r2

Stable KEYWORDS : amd64 x86
Comment 6 Agostino Sarubbo gentoo-dev 2013-07-10 05:18:03 UTC
amd64 stable
Comment 7 Agostino Sarubbo gentoo-dev 2013-07-10 05:18:48 UTC
x86 stable
Comment 8 Stefan Behte (RETIRED) gentoo-dev Security 2013-07-10 12:56:38 UTC
Vote: NO. XS only.
Comment 9 Sergey Popov gentoo-dev 2013-08-22 09:50:30 UTC
GLSA vote: no

Closing as noglsa