Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 238077

Summary: www-apps/viewvc-1.0.6 version bump request
Product: Gentoo Linux Reporter: Andrei Ivanov <andrei.ivanov>
Component: New packagesAssignee: Gentoo Web Application Packages Maintainers <web-apps>
Status: RESOLVED FIXED    
Severity: enhancement CC: rbu
Priority: High    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: http://viewvc.tigris.org/servlets/NewsItemView?newsItemID=2175
Whiteboard:
Package list:
Runtime testing required: ---

Description Andrei Ivanov 2008-09-19 07:45:01 UTC
A new release is available, please update.
It even contains a security fix.

Thank you
Comment 1 Wormo (RETIRED) gentoo-dev 2008-09-19 22:16:58 UTC
Thanks for the report, in particular the heads-up about including a security fix -- that was not apparent from the release announcement!
Comment 2 Robert Buchholz (RETIRED) gentoo-dev 2008-09-20 09:57:24 UTC
  * security fix: ignore arbitrary user-provided MIME types (issue #354)
http://viewvc.tigris.org/issues/show_bug.cgi?id=354

I would not consider this a security issue. It allows an attacker to create a URL setting an arbitrary mime-type on a file in the repository, and entice a user to retrieve that file. This might render the link useless, or at worst case crash the browser. But I do not see how this might result in, say, code execution.
Comment 3 Stefan Behte (RETIRED) gentoo-dev Security 2008-10-04 15:32:17 UTC
Isn't Denail of Service also security relevant?
CVE-2008-4325
Comment 4 Robert Buchholz (RETIRED) gentoo-dev 2008-10-04 15:52:54 UTC
Not if it needs a user's assistance and crashes a client application.
Comment 5 Gunnar Wrobel (RETIRED) gentoo-dev 2008-10-11 20:27:18 UTC
in cvs.