First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 170905
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Pierre-Yves Rofes <py@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 170905 depends on: Show dependency tree
Bug 170905 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2007-03-14 17:02 0000
Some vulnerabilities have been reported in PHProjekt, which can be exploited by
malicious users to conduct cross-site scripting, script insertion, cross-site
request forgery, and SQL injection attacks and potentially compromise a
vulnerable system.

1) Input passed to unspecified parameters is not properly sanitised before
being returned to a user. This can be exploited to execute arbitrary HTML and
script code in a user's browser session in context of an affected site.

2) Input passed to unspecified parameters in the calendar module is not
properly sanitised before being used in an SQL query. This can be exploited to
manipulate SQL queries by injecting arbitrary SQL code.

3) Input passed to unspecified parameters in the search module is not properly
sanitised before being used in an SQL query. This can be exploited to
manipulate SQL queries by injecting arbitrary SQL code.

4) Input passed to an unspecified cookie is not properly sanitised before being
used in an SQL query. This can be exploited to manipulate SQL queries by
injecting arbitrary SQL code when the user logs out.

5) An error within the CSRF prevention routine can be exploited to conduct CSRF
attacks.

6) Users can upload files through e.g. the calendar or file management modules.
This can be exploited to execute arbitrary PHP code by uploading a malicious
PHP file.

7) Input passed to unspecified parameters is not properly verified before being
used. This can be exploited to insert HTML and script code, which will executed
in a user's browser session in context of an affected site if malicious data is
viewed.

Successful exploitation of the vulnerabilities reportedly requires that a valid
user is logged in.

The vulnerabilities are reported in version 5.2. Other versions may also be
affected.
Solution: upgrade to 5.2.1

------- Comment #1 From Sune Kloppenborg Jeppesen 2007-03-25 06:48:44 0000 -------
web-apps please advise and bump as necessary.

------- Comment #2 From Pierre-Yves Rofes 2007-04-02 15:46:01 0000 -------
ping web-apps

------- Comment #3 From Pierre-Yves Rofes 2007-04-23 19:30:16 0000 -------
web-apps, please advise.

------- Comment #4 From Matthias Geerdsen 2007-04-24 16:09:10 0000 -------
been over a month without a reaction on this one

web-apps, please provide an updated ebuild, otherwise I propose to mask this in
about a week maybe

------- Comment #5 From Pierre-Yves Rofes 2007-05-10 13:28:50 0000 -------
any news here?

------- Comment #6 From Gunnar Wrobel 2007-05-10 13:44:05 0000 -------
I started going through the open security bugs. No real excuse for the long
delay except an extreme lack of manpower in webapps at the moment. Working
through the bugs following severity.

------- Comment #7 From Renat Lumpau 2007-05-28 01:03:34 0000 -------
5.2.2 in CVS, please wait for the mirrors to pick up the tarball

------- Comment #8 From Sune Kloppenborg Jeppesen 2007-05-28 06:24:25 0000 -------
Thx Renat.

Arches please test and mark stable. Target keywords are:

phprojekt-5.2.2.ebuild:KEYWORDS="ppc x86"

------- Comment #9 From Christian Faulhammer 2007-05-31 10:16:11 0000 -------
x86 stable

------- Comment #10 From nixnut 2007-06-02 20:28:33 0000 -------
Stable on ppc. 

------- Comment #11 From Pierre-Yves Rofes 2007-06-02 21:13:47 0000 -------
ready for GLSA decision. I vote NO.

------- Comment #12 From Sune Kloppenborg Jeppesen 2007-06-03 06:17:36 0000 -------
SQL injection is not nice. Voting YES.

------- Comment #13 From Raphael Marichez 2007-06-07 21:19:06 0000 -------
i vote yes due to the SQL injection issue and PHP execution of code, which make
this bug a B2 (or C2 because of the need of a valid account), then [glsa].

------- Comment #14 From Raphael Marichez 2007-06-19 22:18:33 0000 -------
 GLSA 200706-07, sorry for the delay

First Last Prev Next    No search results available      Search page      Enter new bug