Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 201437 - www-servers/jetty Multiple vulnerabilities (CVE-2007-{5613,5614,5615,6672})
Summary: www-servers/jetty Multiple vulnerabilities (CVE-2007-{5613,5614,5615,6672})
Status: RESOLVED WONTFIX
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High enhancement (vote)
Assignee: Gentoo Security
URL: http://www.kb.cert.org/vuls/id/212984
Whiteboard: ~3 [masked]
Keywords: PMASKED
Depends on:
Blocks:
 
Reported: 2007-12-05 23:31 UTC by Robert Buchholz (RETIRED)
Modified: 2008-01-26 18:44 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Buchholz (RETIRED) gentoo-dev 2007-12-05 23:31:51 UTC
CVE-2007-5615 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-5615):
  CRLF injection vulnerability in Mortbay Jetty before 6.1.6rc0 allows remote
  attackers to inject arbitrary HTTP headers and conduct HTTP response
  splitting attacks via unspecified vectors.
Comment 1 Robert Buchholz (RETIRED) gentoo-dev 2007-12-05 23:33:25 UTC
java herd, please advise.
Comment 2 Robert Buchholz (RETIRED) gentoo-dev 2007-12-05 23:35:16 UTC
CVE-2007-5614:
  Mortbay Jetty before 6.1.6rc1 does not properly handle "certain quote
  sequences" in HTML cookie parameters, which allows remote attackers to hijack
  browser sessions via unspecified vectors.

CVE-2007-5613:
  Cross-site scripting (XSS) vulnerability in Dump Servlet in Mortbay Jetty
  before 6.1.6rc1 allows remote attackers to inject arbitrary web script or HTML
  via unspecified parameters and cookies.
Comment 3 William L. Thomson Jr. (RETIRED) gentoo-dev 2007-12-06 18:00:38 UTC
This package is presently unmaintained. I have briefly mentioned to nelcheal about us co-maintaining it. Since I maintain Tomcat, and he maintains Resin. Jetty is the other popular servlet container. So it's up our allies, but neither of us use it, or have a direct interest in it. Other than other ebuilds/projects using some Jetty stuff.

Not sure what we will do on this. Likely p.mask or etc. Maybe remove entirely, but don't have anything to put in it's place. Last effort to update Jetty from source, was over 1.5 years ago by nichoj. So likely would have to start from almost scratch to get a current version packaged. Not likely to happen anytime soon.
Comment 4 Krzysztof Pawlik (RETIRED) gentoo-dev 2007-12-06 18:10:28 UTC
Only two packages depend on jetty:

virtual/httpd-basic-0
virtual/httpd-cgi-0

I'm for p.mask for now - on next Java team meeting we'll decide what to do with Jetty.
Comment 5 Petteri Räty (RETIRED) gentoo-dev 2007-12-06 18:28:33 UTC
(In reply to comment #4)
> Only two packages depend on jetty:
> 
> virtual/httpd-basic-0
> virtual/httpd-cgi-0
> 
> I'm for p.mask for now - on next Java team meeting we'll decide what to do with
> Jetty.
> 

Update the pkg_postinst messages in mx4j-tools too.
Comment 6 Robert Buchholz (RETIRED) gentoo-dev 2007-12-07 00:03:36 UTC
thanks for taking care, please let us know once you decide. no maskglsa since this is ~arch only.
Comment 7 Robert Buchholz (RETIRED) gentoo-dev 2008-01-05 02:49:15 UTC
New vulnerability:
  http://secunia.com/advisories/28322/

Java, was there a decision what to do with jetty?
Comment 8 William L. Thomson Jr. (RETIRED) gentoo-dev 2008-01-05 03:29:54 UTC
We are going to mask it and deal with any deps for now. Got a contributor slowly working on a packaging a current version. Hopefully one not effected by exploits. But that work hasn't even been committed to an overlay. I will try to get on this tomorrow. Don't have any time for it tonight.
Comment 9 Robert Buchholz (RETIRED) gentoo-dev 2008-01-09 01:23:12 UTC
CVE-2007-6672 was assigned to the latest issue.
Comment 10 Robert Buchholz (RETIRED) gentoo-dev 2008-01-09 01:24:21 UTC
Last-rited:
  http://article.gmane.org/gmane.linux.gentoo.devel.announce/83
Comment 11 William L. Thomson Jr. (RETIRED) gentoo-dev 2008-01-26 18:44:54 UTC
Closing bug. Removed from tree, till we get a maintainer and current version from source.