Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 233175 (CVE-2008-2951) - www-apps/trac < 0.10.5: XSS and cross-site redirection vulnerability (CVE-2008-2951, CVE-2008-3328)
Summary: www-apps/trac < 0.10.5: XSS and cross-site redirection vulnerability (CVE-200...
Status: RESOLVED FIXED
Alias: CVE-2008-2951
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All All
: High minor
Assignee: Gentoo Security
URL: http://secunia.com/advisories/31231/
Whiteboard: B4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2008-07-28 17:35 UTC by Christian Hoffmann (RETIRED)
Modified: 2008-08-04 20:40 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Christian Hoffmann (RETIRED) gentoo-dev 2008-07-28 17:35:58 UTC
Secunia:
A vulnerability has been reported in Trac, which can be exploited by malicious people to conduct cross-site scripting attacks.

Input passed to certain parameters in the wiki engine is not properly sanitised before being returned to a user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.

The vulnerability affects versions prior to 0.10.5.


Upstream ChangeLog [1] also lists this:
  # Fixes a cross-site redirection vulnerability in the quickjump
    function reported by Russ McRee?. 

[1] http://trac.edgewall.org/wiki/ChangeLog#a0.10.5
Comment 1 Christian Hoffmann (RETIRED) gentoo-dev 2008-07-28 17:37:43 UTC
0.10.5 is already in the tree.
net-mail, is this ready to go stable?
Comment 2 Robert Buchholz (RETIRED) gentoo-dev 2008-07-30 00:29:54 UTC
CVE-2008-2951 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2951):
  Open redirect vulnerability in the search script in Trac before 0.10.5 allows
  remote attackers to redirect users to arbitrary web sites and conduct
  phishing attacks via a URL in the q parameter.

CVE-2008-3328 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3328):
  Cross-site scripting (XSS) vulnerability in the wiki engine in Trac before
  0.10.5 allows remote attackers to inject arbitrary web script or HTML via
  unknown vectors.
Comment 3 Gunnar Wrobel (RETIRED) gentoo-dev 2008-08-01 04:39:56 UTC
Targets for 0.10.5:

  amd64 ppc x86
Comment 4 Tobias Scherbaum (RETIRED) gentoo-dev 2008-08-03 17:59:46 UTC
ppc stable
Comment 5 Markus Ullmann (RETIRED) gentoo-dev 2008-08-03 21:03:45 UTC
x86 stable
Comment 6 Tobias Scherbaum (RETIRED) gentoo-dev 2008-08-03 21:08:17 UTC
re-opening ... /me hands Markus a cup of coffee ;)
Comment 7 Tobias Heinlein (RETIRED) gentoo-dev 2008-08-04 16:32:13 UTC
amd64 stable
Comment 8 Tobias Heinlein (RETIRED) gentoo-dev 2008-08-04 16:32:35 UTC
Ready for vote, I vote NO.
Comment 9 Robert Buchholz (RETIRED) gentoo-dev 2008-08-04 20:40:29 UTC
NO, closing.