<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>202327</bug_id>
          <alias>CVE-2007-5000</alias>
          <creation_ts>2007-12-14 21:06 0000</creation_ts>
          <short_desc>www-servers/apache &lt; 2.2.6-r5 mod_imagemap Cross-site scripting (XSS) vulnerability (CVE-2007-5000)</short_desc>
          <delta_ts>2008-03-06 09:58:47 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://httpd.apache.org/security/vulnerabilities_22.html</bug_file_loc>
          <status_whiteboard>B4 [noglsa]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>minor</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>lars@chaotika.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>apache-bugs@gentoo.org</cc>
    
    <cc>mips@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>lars@chaotika.org</who>
            <bug_when>2007-12-14 21:06:32 0000</bug_when>
            <thetext>CVE-2007-5000 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-5000):
  Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the
  Apache HTTP Server 1.3.0 through 1.3.39 and 2.0.35 through 2.0.61 and the (2)
  mod_imagemap module in the Apache HTTP Server 2.2.0 through 2.2.6 allows
  remote attackers to inject arbitrary web script or HTML via unspecified
  vectors.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>lars@chaotika.org</who>
            <bug_when>2007-12-14 21:28:28 0000</bug_when>
            <thetext>maintainers - please advice</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jakub@gentoo.org</who>
            <bug_when>2007-12-14 21:49:21 0000</bug_when>
            <thetext>*** Bug 202326 has been marked as a duplicate of this bug. ***</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>hollow@gentoo.org</who>
            <bug_when>2007-12-14 22:01:03 0000</bug_when>
            <thetext>mod_imap/mod_imagemap is not installed by default, but can be enabled via
/etc/apache2/apache2-builtin-mods (&lt;2.2.6-r4) or APACHE2_MODULES (&gt;=2.2.6-r4)

i&apos;m not sure what the security policy is here, but i assume very little usage
of mod_imap/mod_imagemap

nevertheless, i will provide a fix for 2.2 asap</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2007-12-14 22:06:33 0000</bug_when>
            <thetext>It is installed, but not enabled by default, you mean?

Policy is to treat common packages (which Apache is) as &quot;A&quot; in default configurations, &quot;B&quot; otherwise. That means, we still need to fix this, it only decreases priority (target delay is 20 days) and chances of getting a GLSA.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>hollow@gentoo.org</who>
            <bug_when>2007-12-14 22:09:26 0000</bug_when>
            <thetext>yes, that&apos;s what i meant ...</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>hollow@gentoo.org</who>
            <bug_when>2007-12-14 22:37:36 0000</bug_when>
            <thetext>apache-2.2.6-r5 in cvs, ready for stabilization, 2.0 support ends before the target delay, no fixes.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2007-12-14 22:43:56 0000</bug_when>
            <thetext>That&apos;s your call.

Arches, please test and mark stable www-servers/apache-2.2.6-r5.
Target keywords : &quot;alpha amd64 arm hppa ia64 mips ppc ppc64 s390 sh sparc x86&quot;
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>hollow@gentoo.org</who>
            <bug_when>2007-12-14 22:56:43 0000</bug_when>
            <thetext>even if it does not really belong here, i especially ask arm, mips, s390 and sh to stabilize too ASAP, 2.0 support ends on 31-12-2007 and will leave those archs with no stable apache.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>hollow@gentoo.org</who>
            <bug_when>2007-12-15 14:35:39 0000</bug_when>
            <thetext>FYI, this is also fixed in 2.2.6-r6 now (the first unmasked USE_EXPAND version, do not stabilize!)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jer@gentoo.org</who>
            <bug_when>2007-12-15 17:57:27 0000</bug_when>
            <thetext>Stable for HPPA.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dertobi123@gentoo.org</who>
            <bug_when>2007-12-15 20:03:16 0000</bug_when>
            <thetext>ppc stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>armin76@gentoo.org</who>
            <bug_when>2007-12-16 12:41:04 0000</bug_when>
            <thetext>alpha/ia64/sparc/x86 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>corsair@gentoo.org</who>
            <bug_when>2007-12-16 17:14:05 0000</bug_when>
            <thetext>ppc64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>welp@gentoo.org</who>
            <bug_when>2007-12-16 17:37:17 0000</bug_when>
            <thetext>amd64 done.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>lars@chaotika.org</who>
            <bug_when>2007-12-17 10:56:00 0000</bug_when>
            <thetext>This one here is ready for glsa decision</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-01-05 03:24:13 0000</bug_when>
            <thetext>Voting NO.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2008-01-05 21:47:45 0000</bug_when>
            <thetext>no too, and closing without glsa.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>pva@gentoo.org</who>
            <bug_when>2008-03-06 09:58:47 0000</bug_when>
            <thetext>Does not affect current (2008.0) release. Removing release.</thetext>
          </long_desc>
      
    </bug>

</bugzilla>