<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>203085</bug_id>
          
          <creation_ts>2007-12-22 21:34 0000</creation_ts>
          <short_desc>sys-cluster/ganglia &lt; 3.0.6 Multiple cross-site scripting issues (CVE-2007-6465)</short_desc>
          <delta_ts>2008-01-05 18:12:54 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://sourceforge.net/project/shownotes.php?release_id=562168</bug_file_loc>
          <status_whiteboard>B4 [noglsa]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>minor</bug_severity>
          <target_milestone>---</target_milestone>
          <dependson>172206</dependson>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>rbu@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>hp-cluster@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2007-12-22 21:34:23 0000</bug_when>
            <thetext>CVE-2007-6465 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-6465):
  Multiple cross-site scripting (XSS) vulnerabilities in ganglia-web in Ganglia
  before 3.0.6 allow remote attackers to inject arbitrary web script or HTML
  via the (1) c and (2) h parameters to (a) web/host_gmetrics.php; the (3) G,
  (4) me, (5) x, (6) n, (7) v, (8) l, (9) vl, and (10) st parameters to (b)
  web/graph.php; and the (11) c, (12) G, (13) h, (14) r, (15) m, (16) s, (17)
  cr, (18) hc, (19) sh, (20) p, (21) t, (22) jr, (23) js, (24) gw, (25) z, and
  (26) gs parameters to (c) web/get_context.php.  NOTE: some of these details
  are obtained from third party information.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2007-12-22 21:36:54 0000</bug_when>
            <thetext>HP-Cluster herd, please advise.

Bug 172206 contains updated ebuilds.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-01-05 00:18:56 0000</bug_when>
            <thetext>ping.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jsbronder@gentoo.org</who>
            <bug_when>2008-01-05 01:36:34 0000</bug_when>
            <thetext>ganglia-3.0.6 added to cvs.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-01-05 02:14:10 0000</bug_when>
            <thetext>Thanks a lot.

Arches, please test and mark stable sys-cluster/ganglia-3.0.6.
Target keywords : &quot;x86&quot;
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>maekke@gentoo.org</who>
            <bug_when>2008-01-05 11:34:48 0000</bug_when>
            <thetext>x86 stable, last arch.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-01-05 12:59:16 0000</bug_when>
            <thetext>It&apos;s a vote.

NO for me.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2008-01-05 18:12:54 0000</bug_when>
            <thetext>Voting NO and closing.</thetext>
          </long_desc>
      
    </bug>

</bugzilla>