Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 560240 (CVE-2015-6939) - <www-apps/joomla-3.4.8: XSS Vulnerability (CVE-2015-6939)
Summary: <www-apps/joomla-3.4.8: XSS Vulnerability (CVE-2015-6939)
Status: RESOLVED FIXED
Alias: CVE-2015-6939
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Low trivial (vote)
Assignee: Gentoo Security
URL: http://developer.joomla.org/security-...
Whiteboard: ~4 [noglsa/cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2015-09-11 21:00 UTC by Dainius Masiliūnas
Modified: 2016-02-14 18:47 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
Patch ebuild from 3.4.3 to 3.4.8 (joomla-3.4.3--3.4.8.patch,1.19 KB, patch)
2016-01-04 16:09 UTC, Harold Anderson
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Dainius Masiliūnas 2015-09-11 21:00:34 UTC
Joomla versions 3.4.0-3.4.3 are affected by a cross-site scripting vulnerability in login module due to inadequate escaping. The issue was fixed in Joomla 3.4.3, which is not yet in Portage.

Reproducible: Always




See the URL for the official Joomla security announcement.
Comment 1 Yury German Gentoo Infrastructure gentoo-dev 2015-09-13 14:30:42 UTC
Thank you for your report. Correction on it Fixed in Joomla-3.4.4.
Comment 2 Dainius Masiliūnas 2015-10-18 11:00:22 UTC
As a heads-up, there's going to be a Joomla update to 3.4.5 on Thursday (22nd October) fixing a yet unnamed, high-profile security issue:
https://www.joomla.org/announcements/release-news/5633-important-security-announcement-pre-release.html
Comment 3 Yury German Gentoo Infrastructure gentoo-dev 2015-11-03 17:13:44 UTC
(In reply to Dainius Masiliūnas from comment #2)
> As a heads-up, there's going to be a Joomla update to 3.4.5 on Thursday
> (22nd October) fixing a yet unnamed, high-profile security issue:

Any updates on this?
Comment 4 Dainius Masiliūnas 2015-11-03 17:28:24 UTC
I submitted a separate bug report for that one: https://bugs.gentoo.org/show_bug.cgi?id=563894
Comment 5 Yury German Gentoo Infrastructure gentoo-dev 2015-12-23 17:52:38 UTC
This got lost, no maintainers were cc'd
Comment 6 Ian Delaney (RETIRED) gentoo-dev 2015-12-30 01:37:01 UTC
Cannot assign a security bug to a proxy maintainer.
CC'd
Comment 7 Harold Anderson 2015-12-30 01:54:13 UTC
I have added joomla-3.4.8 to my overlay hnaparst.  Would the proxy-maint team please review this for inclusion into portage.  I am the maintainer.
Comment 8 Ian Delaney (RETIRED) gentoo-dev 2016-01-04 10:19:49 UTC
1. # Copyright 1999-2015 -> # Copyright 1999-2016
2. Leftover from the prior ebuild
DESCRIPTION="Joomla is a powerful Open Source Content Management System"
The DESCRIPTION should not have the name of the package in it
So not your error
reduce it to "A powerful Open Source Content Management System"

SRC_URI="https://github.com/joomla/joomla-cms/releases/download/${MY_PV}/Joomla_${MY_PV}-Stable-Full_Package.tar.bz2"

is a country mile long. Reduce it at least with 

https://github.com/${PN}/${PN}-cms/  and / or with a MY_PN="${${PN}-cms"
https://github.com/${PN}/${MY_PN}/.....

Similarly the ${MY_PV}/Joomla_${MY_PV}-Stable-Full_Package can be reduced with
M_PN="Joomla_${MY_PV}-Stable-Full_Package"
That would be enough.

DEPEND="${DEPEND}  ????????
Also a leftover from the prior ebuild.
DEPEND="app-arch/unzip" is also now not needed now with  .tar.bz2.
You can delete DEPEND all together it seems.

Rest looks fine.

Rather than have us dish out en abuild from an overlay, can you submit a unified diff as an attachment, not the whole ebuild, here, or a complete git patch asan attachment. The I simply $ git apply <the patch> amd all done.


Thanks
Comment 9 Harold Anderson 2016-01-04 16:09:14 UTC
Created attachment 421900 [details, diff]
Patch ebuild from 3.4.3 to 3.4.8

Changes per Ian Delaney.
Comment 10 Ian Delaney (RETIRED) gentoo-dev 2016-01-05 05:35:46 UTC
commit 905dc2c9cb750fd3dc8a69187aadd99df5863e3c
Author: Ian Delaney <idella4@gentoo.org>
Date:   Tue Jan 5 13:34:14 2016 +0800

    www-apps/joomla: bump to vn. 3.4.8
    
    ebuild prepared by main proxied maintainer, submitted via bugzilla
    
    Gentoo bug: #560240

Package has no stabilised version
Comment 11 Ian Delaney (RETIRED) gentoo-dev 2016-01-05 05:39:01 UTC
commit 905dc2c9cb750fd3dc8a69187aadd99df5863e3c
Author: Ian Delaney <idella4@gentoo.org>
Date:   Tue Jan 5 13:34:14 2016 +0800

    www-apps/joomla: bump to vn. 3.4.8
    
    ebuild prepared by main proxied maintainer, submitted via bugzilla
    
    Gentoo bug: #560240

commit b278d0e2f3a50cf0e0b2b9760a3e149a8c85316b
Author: Ian Delaney <idella4@gentoo.org>
Date:   Tue Jan 5 13:34:14 2016 +0800

    www-apps/joomla: bump to vn. 3.4.8
    
    ebuild prepared by main proxied maintainer, submitted via bugzilla
    
    Gentoo bug: #560240



Package has no stabilised version
Comment 12 Yury German Gentoo Infrastructure gentoo-dev 2016-02-14 18:47:55 UTC
Thank you all. Closing as noglsa.