Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 242700 (CVE-2008-4571) - net-zope/plone <3.0.4 XSS in LiveSearch (CVE-2008-4571)
Summary: net-zope/plone <3.0.4 XSS in LiveSearch (CVE-2008-4571)
Status: RESOLVED FIXED
Alias: CVE-2008-4571
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL: http://dev.plone.org/plone/ticket/7439
Whiteboard: B4 [noglsa]
Keywords:
Depends on: 243270 245786
Blocks:
  Show dependency tree
 
Reported: 2008-10-19 03:12 UTC by Stefan Behte (RETIRED)
Modified: 2008-12-14 13:03 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Stefan Behte (RETIRED) gentoo-dev Security 2008-10-19 03:12:00 UTC
CVE-2008-4571 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-4571):
  Cross-site scripting (XSS) vulnerability in the LiveSearch module in
  Plone before 3.0.4 allows remote attackers to inject arbitrary web
  script or HTML via the Description field for search results, as
  demonstrated using the onerror Javascript even in an IMG tag.
Comment 1 Stefan Behte (RETIRED) gentoo-dev Security 2008-10-19 03:26:47 UTC
I'm not 100% sure if our versions in the tree are vulnerable. Zope team, can you check that, the URL has a POC.
Comment 2 Tupone Alfredo gentoo-dev 2008-10-19 13:02:20 UTC
From http://www.securityfocus.com/bid/27098 it appears that none of the version that are in the tree are affected by this issue
Comment 3 Robert Buchholz (RETIRED) gentoo-dev 2008-10-19 20:36:36 UTC
correcting title and whiteboard. Tupone, the bugtraq link lists 2.5.5 in neither of "vulnerable" nor "not vulnerable", so that is not reliable information.

According to http://plone.org/products/plone/releases/2.5.5 the 2.5.5 series is not supported upstream anymore, so from a general POV I would suggest we mark stable a newer versions. Are there any blockers or regressions that have to be resolved before that?
Comment 4 Robert Buchholz (RETIRED) gentoo-dev 2008-10-24 10:38:00 UTC
xss is b4, not b2
Comment 5 Tupone Alfredo gentoo-dev 2008-10-24 14:55:11 UTC
Working on stabilizing a newer version. I need net-zope/zope-2.10.6 for which a stabilization request as been done and net-zope/plone-3.1.{maybe 6?} for which I'd wait for 1 month without bugs before filing a request
Comment 6 Robert Buchholz (RETIRED) gentoo-dev 2008-10-27 20:39:30 UTC
Since we are dealing with a possible security bug, I'd like to get this fixed sooner than 4 weeks away from now. The plone 3 series is in the tree for months now, so let's target 2 weeks after the 3.1.6 commit -- Nov. 6.
Comment 7 Robert Buchholz (RETIRED) gentoo-dev 2008-11-09 13:04:05 UTC
tupone, usually we do security stablings right on the security bugs. but thanks for opening the bug anyway :-)
Comment 8 Pierre-Yves Rofes (RETIRED) gentoo-dev 2008-12-13 15:49:07 UTC
time for GLSA decision. XSS => no.
Comment 9 Robert Buchholz (RETIRED) gentoo-dev 2008-12-14 13:03:40 UTC
no as well