Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 228505 (CVE-2008-6746) - <www-apps/horde-turba-2.2.1 XSS vulnerability in contact view (CVE-2008-6746)
Summary: <www-apps/horde-turba-2.2.1 XSS vulnerability in contact view (CVE-2008-6746)
Status: RESOLVED FIXED
Alias: CVE-2008-6746
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High trivial
Assignee: Gentoo Security
URL: http://lists.horde.org/archives/annou...
Whiteboard: ~4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2008-06-20 11:20 UTC by Matthias Geerdsen (RETIRED)
Modified: 2009-08-14 12:31 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Matthias Geerdsen (RETIRED) gentoo-dev 2008-06-20 11:20:49 UTC
from the 2.2.1 announcement:
"This is a bugfix release that also fixes an XSS (cross site scripting)
vulnerability in the contact view."

http://secunia.com/advisories/30704/
Comment 1 Matthias Geerdsen (RETIRED) gentoo-dev 2008-06-20 12:09:55 UTC
I did not check if 2.1.7 is affected too, thus leaving the ranking at ?4
Could someone please check that and see if a fix is available in case it is affected as well.
Comment 2 Gunnar Wrobel (RETIRED) gentoo-dev 2008-06-24 11:13:01 UTC
Added horde-turba-2.2.1, removed vulnerable horde-turba-2.2 as it was unstable on all arches. webapps-done.
Comment 3 Arnaud Launay 2008-12-10 20:20:16 UTC
BTW, is there a plan to stabilize horde-* to the newer versions ?
Comment 4 Alex Legler (RETIRED) archtester gentoo-dev Security 2009-08-14 12:30:21 UTC
CVE-2008-6746 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-6746):
  Cross-site scripting (XSS) vulnerability in the contact display view
  in Turba Contact Manager H3 before 2.2.1 allows remote attackers to
  inject arbitrary web script or HTML via the contact name.
Comment 5 Alex Legler (RETIRED) archtester gentoo-dev Security 2009-08-14 12:31:33 UTC
(In reply to comment #1)
> I did not check if 2.1.7 is affected too, thus leaving the ranking at ?4
> Could someone please check that and see if a fix is available in case it is
> affected as well.
> 

It is not. The vulnerable code is in contact.php which is not there in 2.1.7.