First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 195810
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Stephane Bonnell <gentoo.steph@e-bonnell.net>
Add CC:
CC:
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
SiteBar-3.3.8-translator-security.patch SiteBar-3.3.8-translator-security.patch patch Robert Buchholz 2007-10-14 19:14 0000 2.20 KB Details | Diff
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 195810 depends on: Show dependency tree
Bug 195810 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2007-10-14 10:01 0000
Version bump.
This is mainly a security release, please read the change log.

Reproducible: Always

------- Comment #1 From Jakub Moc (RETIRED) 2007-10-14 12:42:35 0000 -------
<snip>
Multiple security issues fixed in the translation module which could be
exploited by user having admin or translation access to SiteBar. A workaround
for version 3.3.8 is to delete the file translator.php, it only used for
translation of SiteBar strings into other languages.
</snip>

CVE-2006-3320 was already fixed in Bug 142597.

------- Comment #2 From Robert Buchholz 2007-10-14 19:13:24 0000 -------
I found two issues in the diff of translator.php:
1) Directory traversal via the $lang parameter that allows chmod'ing
   arbitrary files 0777.
2) Arbitrary PHP command execution via $value parameter.

Both are only exploitable for authenticated users.

------- Comment #3 From Robert Buchholz 2007-10-14 19:14:26 0000 -------
Created an attachment (id=133465) [details]
SiteBar-3.3.8-translator-security.patch

Security relevant parts of the release.

------- Comment #4 From Robert Buchholz 2007-10-14 19:21:44 0000 -------
web-apps, please advise.

------- Comment #5 From Robert Buchholz 2007-10-15 00:07:26 0000 -------
According to upstream, this is only exploitable when not running the default
configuration:
"Those bugs are exploitable by users having access to translations and 
only on installations, where admin granted web server rights to write to 
the locales subdirectories (should not be usually the case by default). 
The users who have access to translations are limited to members of 
Admins and Translators group. Translators group is not created by default."

------- Comment #6 From Gunnar Wrobel 2007-10-16 08:12:23 0000 -------
Yes, this is correct. I've coded a while on sitebar and it would take active
user intervention to open these holes. So this does not really affect security.

Anyhow I bumped to 3.3.9 and dropped the stable keyword on ppc.

Maybe ppc could stabilze that version and we can remove 3.3.8 so no user has to
wonder if sitebar is safe or not.

Thanks!

------- Comment #7 From Robert Buchholz 2007-10-16 11:10:27 0000 -------
(In reply to comment #6)
> Yes, this is correct. I've coded a while on sitebar and it would take active
> user intervention to open these holes. So this does not really affect security.

It still is a privilege escalation when you give people "translation" rights in
the system and they can execute code on the server or change files.

------- Comment #8 From Robert Buchholz 2007-10-18 08:05:19 0000 -------
There were more issues revealed than the ones mentioned in the release notes
and fixed by the patch above. They allow code another way to execute and
retrieve files for arbitrary users, and XSS / redirection flaws for
unauthenticated users.

See: http://www.nth-dimension.org.uk/pub/NDSA20071016.txt.asc

------- Comment #9 From Tobias Scherbaum 2007-10-18 17:03:25 0000 -------
ppc stable

------- Comment #10 From Gunnar Wrobel 2007-10-18 17:13:56 0000 -------
thanks, removing insecure versions. webapps done here

------- Comment #11 From Robert Buchholz 2007-10-18 19:50:54 0000 -------
glsa filed.

------- Comment #12 From Pierre-Yves Rofes 2007-11-06 23:05:39 0000 -------
GLSA 200711-05

First Last Prev Next    No search results available      Search page      Enter new bug