Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 209899
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Robert Buchholz <rbu@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 209899 depends on: Show dependency tree
Bug 209899 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2008-02-12 18:54 0000
CVE-2008-0455 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0455):
  Cross-site scripting (XSS) vulnerability in the mod_negotiation module in the
  Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier
  in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote
  authenticated users to inject arbitrary web script or HTML by uploading a
  file with a name containing XSS sequences and a file extension, which leads
  to injection within a (1) "406 Not Acceptable" or (2) "300 Multiple Choices"
  HTTP response when the extension is omitted in a request for the file.

CVE-2008-0456 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0456):
  CRLF injection vulnerability in the mod_negotiation module in the Apache HTTP
  Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x
  series, and 1.3.39 and earlier in the 1.3.x series allows remote
  authenticated users to inject arbitrary HTTP headers and conduct HTTP
  response splitting attacks by uploading a file with a multi-line name
  containing HTTP header sequences and a file extension, which leads to
  injection within a (1) "406 Not Acceptable" or (2) "300 Multiple Choices"
  HTTP response when the extension is omitted in a request for the file.

------- Comment #1 From Robert Buchholz 2008-02-12 18:58:35 0000 -------
Apache herd, is this already fixed in our stable 2.2.8? I could not find any
info on that.

------- Comment #2 From Benedikt Böhm 2008-02-23 19:45:16 0000 -------
both CVEs affect <=2.2.6 only, only arm s390 and sh missing, but already
requested in bug 205195

------- Comment #3 From Sune Kloppenborg Jeppesen 2008-02-24 13:29:37 0000 -------
We're they stable at the time of filing this bug? If that is the case it should
be closed as invalid. Otherwise I guess we should proceed to glsa? status.

------- Comment #4 From Robert Buchholz 2008-02-24 17:54:13 0000 -------
Our last GLSA marks 2.2.6 as secure, so we can GLSA this together with the
other bugs fixed in 2.2.8. A YES for me.

------- Comment #5 From Sune Kloppenborg Jeppesen 2008-02-25 20:10:31 0000 -------
Voting YES and commented on draft.

------- Comment #6 From Pierre-Yves Rofes 2008-03-11 21:51:35 0000 -------
GLSA 200803-19

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug