Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 102785
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Sune Kloppenborg Jeppesen <jaervosz@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 102785 depends on: Show dependency tree
Bug 102785 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2005-08-16 22:14 0000
phpWebSite 0.10.1 full is vulnerable to an sql injection attack. Full 
description in the URL.

------- Comment #1 From Sune Kloppenborg Jeppesen 2005-08-16 22:15:05 0000 -------
web-apps please advise. 

------- Comment #2 From Sune Kloppenborg Jeppesen 2005-08-17 09:05:29 0000 -------
0.10.2 is due today. web-apps please verify and bump. 

------- Comment #3 From Renat Lumpau 2005-08-17 16:33:54 0000 -------
0.10.2_rc1 in CVS

------- Comment #4 From Sune Kloppenborg Jeppesen 2005-08-17 21:58:38 0000 -------
Arches please test and mark stable. 

------- Comment #5 From Gustavo Zacarias (RETIRED) 2005-08-18 08:39:43 0000 -------
sparc stable.

------- Comment #6 From Jakub Moc (RETIRED) 2005-08-19 02:32:59 0000 -------
*** Bug 103035 has been marked as a duplicate of this bug. ***

------- Comment #7 From Renat Lumpau 2005-08-19 04:36:53 0000 -------
Stable on x86, stabled on ppc by hansmi

------- Comment #8 From Jose Luis Rivero (yoswink) 2005-08-20 08:28:37 0000 -------
Finally you got our sexy alpha mark! 

0.10.2_rc1 stable on alpha.

------- Comment #9 From Stefan Cornelius (RETIRED) 2005-08-20 08:31:17 0000 -------
Ready for GLSA vote, I tend to a no.

------- Comment #10 From Thierry Carrez (RETIRED) 2005-08-21 07:22:51 0000 -------
I vote YES. SQL injection on clearly remote-accessible service.

------- Comment #11 From Stefan Cornelius (RETIRED) 2005-08-21 07:42:48 0000 -------
Ok, correcting my vote, koon is right. I'm now pro-glsa.

------- Comment #12 From Thierry Carrez (RETIRED) 2005-08-21 08:54:19 0000 -------
phpwebsite is probably also vulnerable to the XMLRPC new round of things,
described in bug 102576.

Setting back to upstream and pulling in Wendall (phpwebsite maintainer) for inputs.

------- Comment #13 From Wendall Cada 2005-08-21 11:21:02 0000 -------
Core team is working on an 0.10.2 release with fixes. We actually don't use the
xml-rpc libs, but they are installed with a set of pear packages we use for the
news feeds module. There will be a patched version available tormorrow with both
fixes. I'll post it as soon as it's up.

Wendall

------- Comment #14 From Stuart Herbert (RETIRED) 2005-08-24 12:04:48 0000 -------
Hi Wendall,

Any news on when the next release will happen?

Best regards,
Stu

------- Comment #15 From Wendall Cada 2005-08-24 16:46:47 0000 -------
http://phpwebsite.appstate.edu/downloads/rc/phpwebsite-0.10.2-RC2.tar.gz
Kevin forgot to provide the MD5 hash. Will have him do this first thing in the
morning. Since the core team were unable to reproduce the sql injection
reported, some extra checks were put into place. This has been marked a low
priority for the security team. The pear update is available in the release
candidate. If all testing goes well, I'd expect a full 0.10.2 release by Friday.

Wendall

------- Comment #16 From Renat Lumpau 2005-08-24 19:05:39 0000 -------
rc2 in CVS

------- Comment #17 From Gustavo Zacarias (RETIRED) 2005-08-25 07:51:59 0000 -------
rc2 sparc stable.

------- Comment #18 From Michael Hanselmann (hansmi) (RETIRED) 2005-08-25 11:24:32 0000 -------
Stable on ppc.

------- Comment #19 From Renat Lumpau 2005-08-26 14:18:16 0000 -------
rc2 x86 stable

------- Comment #20 From Jose Luis Rivero (yoswink) 2005-08-30 16:48:46 0000 -------
rc2 stable on alpha

------- Comment #21 From Stefan Cornelius (RETIRED) 2005-08-30 19:43:23 0000 -------
ready for GLSA

------- Comment #22 From Sune Kloppenborg Jeppesen 2005-08-31 07:39:58 0000 -------
GLSA 200508-21 

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug