First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 61510
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Tim Weber <scy-bugs-gentoo@scytale.name>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
egroupware-1.0.00.004.ebuild egroupware-1.0.00.004.ebuild text/plain Bjarke Istrup Pedersen 2004-08-24 15:57 0000 1.28 KB Details
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 61510 depends on: Show dependency tree
Bug 61510 blocks:
Votes: 0    Show votes for this bug    Vote for this bug

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2004-08-24 07:00 0000
As told on www.egroupware.org, version 1.0.0.003 contains some security
problems which are fixed in 1.0.0.004 (already out and downloadable). The
ebuild should be updated and a GLSA should be published.

Reproducible: Always
Steps to Reproduce:

------- Comment #1 From Matthias Geerdsen 2004-08-24 07:17:01 0000 -------
Seems to refer to this posting on bugtraq:

http://www.securityfocus.com/archive/1/372603/2004-08-21/2004-08-27/0


--------------------------------------------------------------------------- 
         Multiple Cross Site Scripting Vulnerabilities 
in eGroupWare 
--------------------------------------------------------------------------- 
 
Author: Joxean Koret 
Date: 2004  
Location: Basque Country 
 
--------------------------------------------------------------------------- 
 
Affected software description: 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 
 
eGroupWare Version 1.0.0.003 
 
eGroupWare is a multi-user, web-based 
groupware suite developed on a custom  
set of PHP-based APIs. Currently available 
modules include: email, addressbook,are so 
equals. 
calendar, infolog (notes, to-do's, phone calls), 
content management, forum,  
bookmarks, wiki 
 
Web: http://www.egroupware.org 
 
--------------------------------------------------------------------------- 
 
Vulnerabilities: 
~~~~~~~~~~~~~~~~ 
 
A. Multiple Cross Site Scripting Vulnerabilities 
 
I will no explicate certain bugs continuosly 
because all the XSS vulnerabilities  
are equals. 
 
A1. In the calendar module the parameter "date" 
is vulnerable to an XSS  
vulnerability. The error is due to an incorrect 
sanitization of the "date" 
parameter. To try the vulnerability :  
 
http://<site-with-egroupware>/egroupware/index.php?menuaction=calendar.uicalendar.day&date=20040701">&lt;script&gt;alert(document.cookie)</script

 
A2. In the calendar module you have an option to 
search any text. The module 
doesn't makes any sanitization of the user 
pased string. If you insert the  
following text you will see the vulnerability :  
 
	">&lt;script&gt;alert(document.cookie)&lt;/script&gt; 
 
A3. In the Address book module eGroupWare 
has the same problem. To try the 
vulnerability Click on Address Book (at the top of 
the web page) and in  
the search field insert the following text, in a new 
example :  
 
	"><h1>That's fun!</h1> 
 
These are the parameters that are vulnerables :  
 
At /egroupware/index.php?menuaction=addressbook.uiaddressbook.index : 
 
	Field parameter  
	Filter parameter  
	QField parameter  
	Start parameter  
 
A4. The option to search between projects is 
also vulnerable. Try this :  
 
	1.- Go to 
http://<site-with-egroupware>/egroupware/index.php?menuaction=preferences.uiaclprefs.index&acl_app=projects

	2.- Insert "><h1>this is new, and other XSS 
vulnerability...</h1> 
 
A5. In the messenger modules (when 
composing a new message) "Subject"  
field allows potentially dangerous HTML, such 
as, in other new example :  
 
">hi<img src="http://localhost/anyimage" 
onload="javascript:alert(document.cookie)"> 
 
A6. In the Ticket module when making the same 
action (creating a new element) 
the same field (Subject) is also vulnerable.  
 
The fix: 
~~~~~~~~ 
 
Vendor is not yet contacted or I have no 
response 
 
--------------------------------------------------------------------------- 
Contact: 
~~~~~~~~ 
 
	Joxean Koret at 
joxeanpiti<<<<<<<<@>>>>>>>>yah00<<<<<<dot>>>>>es 

------- Comment #2 From Sune Kloppenborg Jeppesen 2004-08-24 12:23:32 0000 -------
web-apps please bump to 1.0.0.004

------- Comment #3 From Bjarke Istrup Pedersen 2004-08-24 15:54:56 0000 -------
Just rename the ebuild and build a digest.
Submitting new ebuild in a sec.

------- Comment #4 From Bjarke Istrup Pedersen 2004-08-24 15:57:06 0000 -------
Created an attachment (id=38123) [details]
egroupware-1.0.00.004.ebuild

ebuild

------- Comment #5 From Renat Lumpau 2004-08-25 01:35:45 0000 -------
In CVS

------- Comment #6 From Sune Kloppenborg Jeppesen 2004-08-25 01:44:34 0000 -------
alpha and amd64 please mark stable

------- Comment #7 From Bryan Østergaard (RETIRED) 2004-08-25 14:30:10 0000 -------
Stable on alpha.

------- Comment #8 From Sune Kloppenborg Jeppesen 2004-08-31 14:19:35 0000 -------
***bump***
amd64 please mark stable
***bump***

------- Comment #9 From Travis Tilley (RETIRED) 2004-09-01 09:27:53 0000 -------
stable on amd64

------- Comment #10 From Sune Kloppenborg Jeppesen 2004-09-01 09:39:09 0000 -------
Security this one is ready for GLSA, please draft.

Upgrading to B3 as it is a XSS.

------- Comment #11 From Luke Macken (RETIRED) 2004-09-01 13:37:59 0000 -------
GLSA drafted.

------- Comment #12 From Luke Macken (RETIRED) 2004-09-02 05:46:48 0000 -------
The security update 1.0.00.004 break the functionality from the Email
application.  1.0.00.004-2 has been released to fix this problem. 

web-apps please bump to 1.0.00.004-2

------- Comment #13 From Thierry Carrez (RETIRED) 2004-09-02 05:48:04 0000 -------
Back to ebuild status

------- Comment #14 From Thierry Carrez (RETIRED) 2004-09-02 05:49:42 0000 -------
Apparently our 1.0.00.004 ebuild already uses that -2 subversion, so we're OK.
Back to GLSA.

------- Comment #15 From Sune Kloppenborg Jeppesen 2004-09-02 13:53:42 0000 -------
GLSA 200409-06

First Last Prev Next    No search results available      Search page      Enter new bug