First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 90213
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Adir Abraham <adirab@gmail.com>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 90213 depends on: Show dependency tree
Bug 90213 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2005-04-24 03:24 0000
from securityfocus.com:

phpBB is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

Reproducible: Always
Steps to Reproduce:
1.
2.
3.

------- Comment #1 From Adir Abraham 2005-04-24 03:31:00 0000 -------
phpBB 2.0beta1 up up to phpBB 2.0.14 are vulnerable.

------- Comment #2 From Luke Macken (RETIRED) 2005-04-24 07:10:13 0000 -------
*** Bug 90214 has been marked as a duplicate of this bug. ***

------- Comment #3 From Luke Macken (RETIRED) 2005-04-24 07:11:33 0000 -------
[merged from bug 90214]

from securityfocus.com:

phpBB is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

Versions 2.0beta1 up to 2.0.14 are vulnerable

------- Comment #4 From Luke Macken (RETIRED) 2005-04-24 07:12:44 0000 -------
web-apps, please advise.

------- Comment #5 From Aaron Walker (RETIRED) 2005-04-25 02:44:34 0000 -------
Unfortunately (or fortunately?) I don't know PHP so I am unable to try and
patch it.  If anyone else wants to take a stab, feel free.  Otherwise, we'll
have to wait on upstream.

------- Comment #6 From Luke Macken (RETIRED) 2005-04-25 07:47:00 0000 -------
Some snippets from my conversation on IRC
- - -
09:27 <@NeoThermic> lewk^: It has been noted and investigated, but as far as I
                    can see its only a bug rather than a secuirty issue.
                    Granted though, if you know diffrent, or we find diffrent,
                    we will let everyone know :)
09:28 <@NeoThermic> lewk^: and as for the line posting to admin_forums.php, a)
                    you need admin for that, and b) its always been that the
                    admin can put any HTML in the forum description. Its not
                    even a bug that one.
09:32 <@NeoThermic> without confiring with the teams, I can't say anything
                    offical about them, since they might have more to say. But
                    in my view the former one over \[ in the url is a bug, and
                    the latter one requires admin access anyway, so its a bit
                    of a strech, don't you think?

09:34 <@NeoThermic> I'll put it this way, if it was a secuirty risk, we would
                    have new packages out in a matter of hours :)
- - -

I guess we could sit on this bug for a bit and see if upstream makes a new release soon.  Audit Team, anyone willing to take a look?

------- Comment #7 From Sune Kloppenborg Jeppesen 2005-05-08 00:08:29 0000 -------
phpBB 2.0.15 released:

http://www.phpbb.com/phpBB/viewtopic.php?f=14&t=288194

Though not sure it fixes this vulnerability it fixes a serious issue in includes/bbcode.php

web-apps please bump.

Lewk please check wether it fixes the original issue and the impact of the current issue.


------- Comment #8 From Aaron Walker (RETIRED) 2005-05-08 06:32:25 0000 -------
2.0.15 in CVS.  Lewk, if you think everything's A-OK, then go ahead and CC ppc@
if you would.

------- Comment #9 From Jakub Moc (RETIRED) 2005-05-08 15:12:26 0000 -------
2.0.15 does not exist on any sourceforge mirror - pretty hard to test... :-)

------- Comment #10 From Adir Abraham 2005-05-08 15:16:32 0000 -------
http://www.phpbb.com/files/releases/phpBB-2.0.15.tar.bz2

------- Comment #11 From Jakub Moc (RETIRED) 2005-05-08 15:25:24 0000 -------
Hmmm - the digest obviously needs fix...

!!! Digest verification Failed:
!!!    /usr/portage/distfiles/phpBB-2.0.15.tar.bz2
!!! Reason: Filesize does not match recorded size

# ls -ls /usr/portage/distfiles | grep phpBB-2.0.15
  436 -rw-r--r--  1 root portage   443750 May  7 16:21 phpBB-2.0.15.tar.bz2

# cat /usr/portage/www-apps/phpBB/files/digest-phpBB-2.0.15
MD5 a8e71358ccc758ec3b7aa98dfe504497 phpBB-2.0.15.tar.bz2 443698

------- Comment #12 From Aaron Walker (RETIRED) 2005-05-08 17:55:20 0000 -------
hmmm well I downloaded the tarball from a SF mirror....

------- Comment #13 From Jakub Moc (RETIRED) 2005-05-09 02:15:22 0000 -------
Works now, tnx. ;-)

------- Comment #14 From Stefan Cornelius (RETIRED) 2005-05-09 08:01:05 0000 -------
according to <@NeoThermic> in #phpbb, 2.0.15 fixes the original issue
(XSS-Vulns, btw no real security issue) and the more serious problem in
includes/bbcode.php.

------- Comment #15 From Thierry Carrez (RETIRED) 2005-05-12 05:43:57 0000 -------
ppc: please test and mark 2.0.15 stable

------- Comment #16 From Lars Weiler (RETIRED) 2005-05-12 12:18:07 0000 -------
Tested and marked stable on ppc.

------- Comment #17 From Matthias Geerdsen 2005-05-12 13:00:18 0000 -------
http://securitytracker.com/alerts/2005/May/1013918.html

security, pls vote on GLSA need

------- Comment #18 From Sune Kloppenborg Jeppesen 2005-05-12 13:45:34 0000 -------
I vote YES.

------- Comment #19 From Thierry Carrez (RETIRED) 2005-05-13 01:29:03 0000 -------
I vote yes too. Any idea of the impact ?

------- Comment #20 From Stefan Cornelius (RETIRED) 2005-05-14 02:37:54 0000 -------
http://securitytracker.com/alerts/2005/May/1013918.html says the following
about Impact:  A remote user may be able to cause arbitrary scripting code to
be executed by the target user's browser.

------- Comment #21 From Sune Kloppenborg Jeppesen 2005-05-14 08:34:51 0000 -------
GLSA 200505-10

First Last Prev Next    No search results available      Search page      Enter new bug