<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>61510</bug_id>
          
          <creation_ts>2004-08-24 07:00 0000</creation_ts>
          <short_desc>www-apps/egroupware: Security update request: 1.0.0.004 fixes security problem</short_desc>
          <delta_ts>2004-09-02 13:53:42 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Linux</product>
          <component>Security</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://www.egroupware.org/</bug_file_loc>
          <status_whiteboard>B3 [glsa]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>scy-bugs-gentoo@scytale.name</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>vorlon@gentoo.org</cc>
    
    <cc>web-apps@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>scy-bugs-gentoo@scytale.name</who>
            <bug_when>2004-08-24 07:00:39 0000</bug_when>
            <thetext>As told on www.egroupware.org, version 1.0.0.003 contains some security problems which are fixed in 1.0.0.004 (already out and downloadable). The ebuild should be updated and a GLSA should be published.

Reproducible: Always
Steps to Reproduce:</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vorlon@gentoo.org</who>
            <bug_when>2004-08-24 07:17:01 0000</bug_when>
            <thetext>Seems to refer to this posting on bugtraq:

http://www.securityfocus.com/archive/1/372603/2004-08-21/2004-08-27/0


--------------------------------------------------------------------------- 
         Multiple Cross Site Scripting Vulnerabilities 
in eGroupWare 
--------------------------------------------------------------------------- 
 
Author: Joxean Koret 
Date: 2004  
Location: Basque Country 
 
--------------------------------------------------------------------------- 
 
Affected software description: 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 
 
eGroupWare Version 1.0.0.003 
 
eGroupWare is a multi-user, web-based 
groupware suite developed on a custom  
set of PHP-based APIs. Currently available 
modules include: email, addressbook,are so 
equals. 
calendar, infolog (notes, to-do&apos;s, phone calls), 
content management, forum,  
bookmarks, wiki 
 
Web: http://www.egroupware.org 
 
--------------------------------------------------------------------------- 
 
Vulnerabilities: 
~~~~~~~~~~~~~~~~ 
 
A. Multiple Cross Site Scripting Vulnerabilities 
 
I will no explicate certain bugs continuosly 
because all the XSS vulnerabilities  
are equals. 
 
A1. In the calendar module the parameter &quot;date&quot; 
is vulnerable to an XSS  
vulnerability. The error is due to an incorrect 
sanitization of the &quot;date&quot; 
parameter. To try the vulnerability :  
 
http://&lt;site-with-egroupware&gt;/egroupware/index.php?menuaction=calendar.uicalendar.day&amp;date=20040701&quot;&gt;&amp;lt;script&amp;gt;alert(document.cookie)&lt;/script

 
A2. In the calendar module you have an option to 
search any text. The module 
doesn&apos;t makes any sanitization of the user 
pased string. If you insert the  
following text you will see the vulnerability :  
 
	&quot;&gt;&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt; 
 
A3. In the Address book module eGroupWare 
has the same problem. To try the 
vulnerability Click on Address Book (at the top of 
the web page) and in  
the search field insert the following text, in a new 
example :  
 
	&quot;&gt;&lt;h1&gt;That&apos;s fun!&lt;/h1&gt; 
 
These are the parameters that are vulnerables :  
 
At /egroupware/index.php?menuaction=addressbook.uiaddressbook.index : 
 
	Field parameter  
	Filter parameter  
	QField parameter  
	Start parameter  
 
A4. The option to search between projects is 
also vulnerable. Try this :  
 
	1.- Go to 
http://&lt;site-with-egroupware&gt;/egroupware/index.php?menuaction=preferences.uiaclprefs.index&amp;acl_app=projects

	2.- Insert &quot;&gt;&lt;h1&gt;this is new, and other XSS 
vulnerability...&lt;/h1&gt; 
 
A5. In the messenger modules (when 
composing a new message) &quot;Subject&quot;  
field allows potentially dangerous HTML, such 
as, in other new example :  
 
&quot;&gt;hi&lt;img src=&quot;http://localhost/anyimage&quot; 
onload=&quot;javascript:alert(document.cookie)&quot;&gt; 
 
A6. In the Ticket module when making the same 
action (creating a new element) 
the same field (Subject) is also vulnerable.  
 
The fix: 
~~~~~~~~ 
 
Vendor is not yet contacted or I have no 
response 
 
--------------------------------------------------------------------------- 
Contact: 
~~~~~~~~ 
 
	Joxean Koret at 
joxeanpiti&lt;&lt;&lt;&lt;&lt;&lt;&lt;&lt;@&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;yah00&lt;&lt;&lt;&lt;&lt;&lt;dot&gt;&gt;&gt;&gt;&gt;es 
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2004-08-24 12:23:32 0000</bug_when>
            <thetext>web-apps please bump to 1.0.0.004</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gurligebis@gentoo.org</who>
            <bug_when>2004-08-24 15:54:56 0000</bug_when>
            <thetext>Just rename the ebuild and build a digest.
Submitting new ebuild in a sec.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gurligebis@gentoo.org</who>
            <bug_when>2004-08-24 15:57:06 0000</bug_when>
            <thetext>Created an attachment (id=38123)
egroupware-1.0.00.004.ebuild

ebuild</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rl03@gentoo.org</who>
            <bug_when>2004-08-25 01:35:45 0000</bug_when>
            <thetext>In CVS</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2004-08-25 01:44:34 0000</bug_when>
            <thetext>alpha and amd64 please mark stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kloeri@gentoo.org</who>
            <bug_when>2004-08-25 14:30:10 0000</bug_when>
            <thetext>Stable on alpha.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2004-08-31 14:19:35 0000</bug_when>
            <thetext>***bump***
amd64 please mark stable
***bump***</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>lv@gentoo.org</who>
            <bug_when>2004-09-01 09:27:53 0000</bug_when>
            <thetext>stable on amd64</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2004-09-01 09:39:09 0000</bug_when>
            <thetext>Security this one is ready for GLSA, please draft.

Upgrading to B3 as it is a XSS.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>lewk@gentoo.org</who>
            <bug_when>2004-09-01 13:37:59 0000</bug_when>
            <thetext>GLSA drafted.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>lewk@gentoo.org</who>
            <bug_when>2004-09-02 05:46:48 0000</bug_when>
            <thetext>The security update 1.0.00.004 break the functionality from the Email application.  1.0.00.004-2 has been released to fix this problem. 

web-apps please bump to 1.0.00.004-2</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-09-02 05:48:04 0000</bug_when>
            <thetext>Back to ebuild status</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-09-02 05:49:42 0000</bug_when>
            <thetext>Apparently our 1.0.00.004 ebuild already uses that -2 subversion, so we&apos;re OK. Back to GLSA.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2004-09-02 13:53:42 0000</bug_when>
            <thetext>GLSA 200409-06</thetext>
          </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="0"
              isprivate="0"
          >
            <attachid>38123</attachid>
            <date>2004-08-24 15:57 0000</date>
            <desc>egroupware-1.0.00.004.ebuild</desc>
            <filename>egroupware-1.0.00.004.ebuild</filename>
            <type>text/plain</type>
            <data encoding="base64">IyBDb3B5cmlnaHQgMTk5OS0yMDA0IEdlbnRvbyBGb3VuZGF0aW9uCiMgRGlzdHJpYnV0ZWQgdW5k
ZXIgdGhlIHRlcm1zIG9mIHRoZSBHTlUgR2VuZXJhbCBQdWJsaWMgTGljZW5zZSB2MgojICRIZWFk
ZXI6IC92YXIvY3Zzcm9vdC9nZW50b28teDg2L3d3dy1hcHBzL2Vncm91cHdhcmUvZWdyb3Vwd2Fy
ZS0xLjAuMDAuMDAzLmVidWlsZCx2IDEuMSAyMDA0LzA4LzE5IDEzOjEzOjI0IHJsMDMgRXhwICQK
CmluaGVyaXQgd2ViYXBwCgpNWV9QPWVHcm91cFdhcmUtJHtQVn0tMgpTPSR7V09SS0RJUn0vJHtQ
Tn0KCkRFU0NSSVBUSU9OPSJXZWItYmFzZWQgR3JvdXBXYXJlIHN1aXRlLiBJdCBjb250YWlucyBt
YW55IG1vZHVsZXMiCkhPTUVQQUdFPSJodHRwOi8vd3d3LmVHcm91cFdhcmUub3JnLyIKU1JDX1VS
ST0ibWlycm9yOi8vc291cmNlZm9yZ2UvJHtQTn0vJHtNWV9QfS50YXIuYnoyIgoKTElDRU5TRT0i
R1BMLTIiCktFWVdPUkRTPSJ+eDg2IH5wcGMgfmFscGhhIH5hbWQ2NCB+c3BhcmMgfmhwcGEiCklV
U0U9ImxkYXAiCgpERVBFTkQ9IiRERVBFTkQiClJERVBFTkQ9InZpcnR1YWwvcGhwCgl8fCAoID49
ZGV2LWRiL215c3FsLTMuMjMgPj1kZXYtZGIvcG9zdGdyZXNxbC03LjIgKQoJbGRhcD8gKCBuZXQt
bmRzL29wZW5sZGFwICkKCW5ldC13d3cvYXBhY2hlIgoKcGtnX3NldHVwICgpIHsKCXdlYmFwcF9w
a2dfc2V0dXAKCWVpbmZvICJQbGVhc2UgbWFrZSBzdXJlIHRoYXQgeW91ciBQSFAgaXMgY29tcGls
ZWQgd2l0aCBMREFQIChpZiB1c2luZyBvcGVubGRhcCksIElNQVAsIGFuZCBNeVNRTHxQb3N0Z3Jl
U1FMIHN1cHBvcnQiCgllaW5mbwoJZWluZm8gIkNvbnNpZGVyIGluc3RhbGxpbmcgYW4gTVRBIGlm
IHlvdSB3YW50IHRvIHRha2UgYWR2YW50YWdlIG9mIGVHVydzIG1haWwgY2FwYWJpbGl0aWVzLiIK
CXNsZWVwIDcKfQoKcGtnX2NvbXBpbGUoKSB7Cgk6Owp9CgpzcmNfaW5zdGFsbCgpIHsKCXdlYmFw
cF9zcmNfcHJlaW5zdAoJY2QgJHtTfQoJIyByZW1vdmUgQ1ZTIGRpcmVjdG9yaWVzCglmaW5kIC4g
LXR5cGUgZCAtbmFtZSAnQ1ZTJyAtcHJpbnQgfCB4YXJncyBybSAtcmYKCWNwIC1yIC4gJHtEfS8k
e01ZX0hURE9DU0RJUn0KCgl3ZWJhcHBfc2VydmVyb3duZWQgJHtNWV9IVERPQ1NESVJ9L2Z1ZGZv
cnVtCgl3ZWJhcHBfc2VydmVyb3duZWQgJHtNWV9IVERPQ1NESVJ9L3BocGd3YXBpL2ltYWdlcwoK
CSMgYWRkIHBvc3QtaW5zdGFsbGF0aW9uIGluc3RydWN0aW9ucwoJd2ViYXBwX3Bvc3RpbnN0X3R4
dCBlbiAke0ZJTEVTRElSfS9wb3N0aW5zdGFsbC1lbi50eHQKCgl3ZWJhcHBfc3JjX2luc3RhbGwK
fQo=
</data>        

          </attachment>
    </bug>

</bugzilla>