Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 126180 - net-mail/lurker - multiple vulnerabilities (CVE-2006-1062, CVE-2006-1063, CVE-2006-1064)
Summary: net-mail/lurker - multiple vulnerabilities (CVE-2006-1062, CVE-2006-1063, CVE...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard: ~2? [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2006-03-14 09:40 UTC by Carsten Lohrke (RETIRED)
Modified: 2006-03-15 06:27 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Carsten Lohrke (RETIRED) gentoo-dev 2006-03-14 09:40:32 UTC
Unspecified vulnerability in lurker.cgi for Lurker 2.0 and earlier allows attackers to read arbitrary files via unknown vectors.

Unspecified vulnerability in Lurker 2.0 and earlier allows remote attackers to create or overwrite files in any writable directory that is named "mbox".

Multiple cross-site scripting (XSS) vulnerabilities in Lurker 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.
Comment 1 Benjamin Smee (strerror) (RETIRED) gentoo-dev 2006-03-14 09:50:07 UTC
i'm looking into adding lurker 2.1 now.
Comment 2 Thierry Carrez (RETIRED) gentoo-dev 2006-03-14 09:55:09 UTC
setting status
Comment 3 Benjamin Smee (strerror) (RETIRED) gentoo-dev 2006-03-14 12:12:45 UTC
lurker 2.x has changed substantially from 1.x. I am VERY short of time right now so I'm going to have to leave it till tomorrow (another 14 hours or so). If someone else from netmail wants to do this then feel free, but I'm snowed under with work right now.
Comment 4 Benjamin Smee (strerror) (RETIRED) gentoo-dev 2006-03-15 04:19:45 UTC
ok, new lurker version added as 2.1. over to you security, feel free to remove 1.3 from the tree
Comment 5 Stefan Cornelius (RETIRED) gentoo-dev 2006-03-15 06:27:14 UTC
was never stable, no glsa -> done. I'll see if i can ping someone in IRC to remove  1.3.