Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 189614 - www-apps/{viewcvs ,viewvc} possible XSS
Summary: www-apps/{viewcvs ,viewvc} possible XSS
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2007-08-20 16:39 UTC by Markus Ullmann (RETIRED)
Modified: 2007-10-27 07:30 UTC (History)
5 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
0001-Merge-security-fix-made-in-r1446-from-1.0.x-to-trunk.patch (0001-Merge-security-fix-made-in-r1446-from-1.0.x-to-trunk.patch,1.99 KB, patch)
2007-09-17 11:50 UTC, Markus Ullmann (RETIRED)
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Markus Ullmann (RETIRED) gentoo-dev 2007-08-20 16:39:38 UTC
While some grep in Changelog I found that: 

Version 1.0.3 (released 13-Oct-2006)

  * fix bug in path shown for Subversion deleted-under-copy items (issue #265)
  * security fix: declare charset for views to avoid IE UTF7 XSS attac

(http://viewvc.tigris.org/source/browse/viewvc/trunk/CHANGES?rev=HEAD)

noting that sources.g.o uses old viewcvs
Comment 1 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-08-24 13:25:25 UTC
setting status and cc'ing maintainer and infra liaisons since it's a possible breach. also, restricting bug for now until we have more infos.
Comment 2 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-08-24 19:37:18 UTC
This is already public for almost a year so I really see no point in restricting this one.
Comment 3 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-09-08 15:47:10 UTC
(In reply to comment #2)
> This is already public for almost a year so I really see no point in
> restricting this one.
> 

Yeah probably, but with the other issue on p.g.o some weeks ago, I prefered to be cautious. Infra, are we affected by this?
Comment 4 Robin Johnson archtester Gentoo Infrastructure gentoo-dev Security 2007-09-08 22:53:29 UTC
can somebody with a PoC and IE7 please test it for existence on the sources.g.o?
Alternatively give me the actual patch that fixed it, and i'll check against the live source.
Comment 5 Markus Ullmann (RETIRED) gentoo-dev 2007-09-17 11:50:41 UTC
Created attachment 131150 [details, diff]
0001-Merge-security-fix-made-in-r1446-from-1.0.x-to-trunk.patch
Comment 6 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-09-29 14:31:42 UTC
robbat2, any news here? is sources.g.o affected?
Comment 7 Robin Johnson archtester Gentoo Infrastructure gentoo-dev Security 2007-10-22 23:26:14 UTC
appears sources.g.o was patched some time ago.
Comment 8 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-10-25 11:26:09 UTC
(In reply to comment #7)
> appears sources.g.o was patched some time ago.
> 

ok so this can be unrestricted now. 
viewvc has 1.0.4 stable so it should be ok, but the viewcvs ebuilds are pre-releases so I don't know if it's affected. web-apps, please advise.
Comment 9 Gunnar Wrobel (RETIRED) gentoo-dev 2007-10-26 13:08:22 UTC
ups, actually viewcvs has been completely replaced with viewvc. 

In principle I'd suggest to mask viewcvs and let people migrate to viewvc. Nevertheless s.g.o still seems to use the older viewCVS.

I'll write a mail to gentoo-dev
Comment 10 Robin Johnson archtester Gentoo Infrastructure gentoo-dev Security 2007-10-26 21:34:28 UTC
s.g.o uses a hacked up middle point, that needs a real upgrade at some point.
Comment 11 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-10-26 21:56:53 UTC
(In reply to comment #9)
> ups, actually viewcvs has been completely replaced with viewvc. 
> 
> In principle I'd suggest to mask viewcvs and let people migrate to viewvc.
> Nevertheless s.g.o still seems to use the older viewCVS.
> 
> I'll write a mail to gentoo-dev
> 

Ok so I guess we can proceed to the glsa-vote.  XSS => no (maybe we could add a rule in the policy for this case).
Comment 12 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-10-27 07:30:59 UTC
Voting NO and ACK on the policy question.