Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 217575 (CVE-2008-1840) - www-apps/coppermine <1.4.18 SQL injection vulnerabilities (CVE-2008-{1840,1841,1882})
Summary: www-apps/coppermine <1.4.18 SQL injection vulnerabilities (CVE-2008-{1840,184...
Status: RESOLVED FIXED
Alias: CVE-2008-1840
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL: http://forum.coppermine-gallery.net/i...
Whiteboard: ~3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2008-04-14 01:51 UTC by Patrick
Modified: 2008-08-06 18:46 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Patrick 2008-04-14 01:51:47 UTC
From <http://forum.coppermine-gallery.net/index.php/topic,51787.0.html>:

"The development team is releasing a security update for Coppermine in order to counter a recently discovered sql injection vulnerability. It is important that all users who run version cpg1.4.16 or older update to this latest version as soon as possible."

Reproducible: Always
Comment 1 Robert Buchholz (RETIRED) gentoo-dev 2008-04-14 02:22:27 UTC
Patch:
http://coppermine.svn.sourceforge.net/viewvc/coppermine?view=rev&revision=4372

While we're at it, there's a new SQL injection fixed here:
http://coppermine.svn.sourceforge.net/viewvc/coppermine?view=rev&revision=4381

Let's wait for 1.4.18 then,
Comment 2 Robert Buchholz (RETIRED) gentoo-dev 2008-04-14 22:23:52 UTC
... it's out. Please bump.
Comment 3 Matthias Geerdsen (RETIRED) gentoo-dev 2008-04-17 20:06:15 UTC
CVE-2008-1841   
Summary: SQL injection vulnerability in the session handling functionality in bridge/coppermine.inc.php in Coppermine Photo Gallery (CPG) 1.4.17 and earlier allows remote attackers to execute arbitrary SQL commands via an input field associated with the session_id variable, as exploited in the wild in April 2008. NOTE: the fix for CVE-2008-1840 was intended to address this vulnerability, but is actually inapplicable.

Published: 4/16/2008

CVSS Severity: 6.8 (Medium)

CVE-2008-1840   
Summary: SQL injection vulnerability in upload.php in Coppermine Photo Gallery (CPG) 1.4.16 and earlier allows remote authenticated users or user-assisted remote HTTP servers to execute arbitrary SQL commands via the Content-Type HTTP response header provided by the HTTP server that is used for an upload.

Published: 4/16/2008

CVSS Severity: 6.5 (Medium) 
Comment 4 Robert Buchholz (RETIRED) gentoo-dev 2008-04-17 23:20:39 UTC
CVE-2008-1882 for the bridge/coppermine.inc.php "session handling code" sql injection

http://coppermine.svn.sourceforge.net/viewvc/coppermine?view=rev&revision=4381
Comment 5 Benedikt Böhm (RETIRED) gentoo-dev 2008-04-25 11:25:43 UTC
in cvs, no stable version yet
Comment 6 Robert Buchholz (RETIRED) gentoo-dev 2008-04-25 20:53:57 UTC
Thanks, closing then.