Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 90213 - www-apps/phpBB: 2.0.15 includes security fixes
Summary: www-apps/phpBB: 2.0.15 includes security fixes
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://www.securityfocus.com/bid/1334...
Whiteboard: B4? [glsa] lewk
Keywords:
: 90214 (view as bug list)
Depends on:
Blocks:
 
Reported: 2005-04-24 03:24 UTC by Adir Abraham
Modified: 2005-05-14 08:34 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Adir Abraham 2005-04-24 03:24:23 UTC
from securityfocus.com:

phpBB is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

Reproducible: Always
Steps to Reproduce:
1.
2.
3.
Comment 1 Adir Abraham 2005-04-24 03:31:00 UTC
phpBB 2.0beta1 up up to phpBB 2.0.14 are vulnerable.
Comment 2 Luke Macken (RETIRED) gentoo-dev 2005-04-24 07:10:13 UTC
*** Bug 90214 has been marked as a duplicate of this bug. ***
Comment 3 Luke Macken (RETIRED) gentoo-dev 2005-04-24 07:11:33 UTC
[merged from bug 90214]

from securityfocus.com:

phpBB is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

Versions 2.0beta1 up to 2.0.14 are vulnerable
Comment 4 Luke Macken (RETIRED) gentoo-dev 2005-04-24 07:12:44 UTC
web-apps, please advise.
Comment 5 Aaron Walker (RETIRED) gentoo-dev 2005-04-25 02:44:34 UTC
Unfortunately (or fortunately?) I don't know PHP so I am unable to try and patch it.  If anyone else wants to take a stab, feel free.  Otherwise, we'll have to wait on upstream.
Comment 6 Luke Macken (RETIRED) gentoo-dev 2005-04-25 07:47:00 UTC
Some snippets from my conversation on IRC
- - -
09:27 <@NeoThermic> lewk^: It has been noted and investigated, but as far as I
                    can see its only a bug rather than a secuirty issue.
                    Granted though, if you know diffrent, or we find diffrent,
                    we will let everyone know :)
09:28 <@NeoThermic> lewk^: and as for the line posting to admin_forums.php, a)
                    you need admin for that, and b) its always been that the
                    admin can put any HTML in the forum description. Its not
                    even a bug that one.
09:32 <@NeoThermic> without confiring with the teams, I can't say anything
                    offical about them, since they might have more to say. But
                    in my view the former one over \[ in the url is a bug, and
                    the latter one requires admin access anyway, so its a bit
                    of a strech, don't you think?

09:34 <@NeoThermic> I'll put it this way, if it was a secuirty risk, we would
                    have new packages out in a matter of hours :)
- - -

I guess we could sit on this bug for a bit and see if upstream makes a new release soon.  Audit Team, anyone willing to take a look?
Comment 7 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-05-08 00:08:29 UTC
phpBB 2.0.15 released:

http://www.phpbb.com/phpBB/viewtopic.php?f=14&t=288194

Though not sure it fixes this vulnerability it fixes a serious issue in includes/bbcode.php

web-apps please bump.

Lewk please check wether it fixes the original issue and the impact of the current issue.

Comment 8 Aaron Walker (RETIRED) gentoo-dev 2005-05-08 06:32:25 UTC
2.0.15 in CVS.  Lewk, if you think everything's A-OK, then go ahead and CC ppc@ if you would.
Comment 9 Jakub Moc (RETIRED) gentoo-dev 2005-05-08 15:12:26 UTC
2.0.15 does not exist on any sourceforge mirror - pretty hard to test... :-)
Comment 11 Jakub Moc (RETIRED) gentoo-dev 2005-05-08 15:25:24 UTC
Hmmm - the digest obviously needs fix...

!!! Digest verification Failed:
!!!    /usr/portage/distfiles/phpBB-2.0.15.tar.bz2
!!! Reason: Filesize does not match recorded size

# ls -ls /usr/portage/distfiles | grep phpBB-2.0.15
  436 -rw-r--r--  1 root portage   443750 May  7 16:21 phpBB-2.0.15.tar.bz2

# cat /usr/portage/www-apps/phpBB/files/digest-phpBB-2.0.15
MD5 a8e71358ccc758ec3b7aa98dfe504497 phpBB-2.0.15.tar.bz2 443698
Comment 12 Aaron Walker (RETIRED) gentoo-dev 2005-05-08 17:55:20 UTC
hmmm well I downloaded the tarball from a SF mirror....
Comment 13 Jakub Moc (RETIRED) gentoo-dev 2005-05-09 02:15:22 UTC
Works now, tnx. ;-)
Comment 14 Stefan Cornelius (RETIRED) gentoo-dev 2005-05-09 08:01:05 UTC
according to <@NeoThermic> in #phpbb, 2.0.15 fixes the original issue (XSS-Vulns, btw no real security issue) and the more serious problem in includes/bbcode.php.
Comment 15 Thierry Carrez (RETIRED) gentoo-dev 2005-05-12 05:43:57 UTC
ppc: please test and mark 2.0.15 stable
Comment 16 Lars Weiler (RETIRED) gentoo-dev 2005-05-12 12:18:07 UTC
Tested and marked stable on ppc.
Comment 17 Matthias Geerdsen (RETIRED) gentoo-dev 2005-05-12 13:00:18 UTC
http://securitytracker.com/alerts/2005/May/1013918.html

security, pls vote on GLSA need
Comment 18 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-05-12 13:45:34 UTC
I vote YES.
Comment 19 Thierry Carrez (RETIRED) gentoo-dev 2005-05-13 01:29:03 UTC
I vote yes too. Any idea of the impact ?
Comment 20 Stefan Cornelius (RETIRED) gentoo-dev 2005-05-14 02:37:54 UTC
http://securitytracker.com/alerts/2005/May/1013918.html says the following about Impact:  A remote user may be able to cause arbitrary scripting code to be executed by the target user's browser.
Comment 21 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-05-14 08:34:51 UTC
GLSA 200505-10