Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 262107 - <dev-java/echo2-2.1.1: Information disclosure (CVE-2009-5135)
Summary: <dev-java/echo2-2.1.1: Information disclosure (CVE-2009-5135)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High trivial (vote)
Assignee: Gentoo Security
URL: https://www.sec-consult.com/files/200...
Whiteboard: ~4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2009-03-11 11:19 UTC by Alex Legler (RETIRED)
Modified: 2013-05-09 11:33 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alex Legler (RETIRED) archtester gentoo-dev Security 2009-03-11 11:19:56 UTC
From Secunia:

A vulnerability has been reported in Echo2, which can be exploited by malicious people to disclose sensitive information.

Input passed as XML to the Echo Engine is not properly verified before being used. This can be exploited to e.g. disclose arbitrary files on an affected system by sending a request containing a specially crafted entity declaration.

The vulnerability is reported in version 2.1.0.rc2. Other versions may also be affected.

Solution:
Update to version 2.1.1.
Comment 1 Serkan Kaba (RETIRED) gentoo-dev 2009-03-11 11:49:24 UTC
Upstream announcement: http://echo.nextapp.com/site/node/5742
Comment 2 Serkan Kaba (RETIRED) gentoo-dev 2009-04-22 19:43:50 UTC
Bumped in CVS.
Comment 3 Robert Buchholz (RETIRED) gentoo-dev 2009-04-23 09:23:10 UTC
thanks, ~arch only.
Comment 4 GLSAMaker/CVETool Bot gentoo-dev 2013-05-09 11:33:58 UTC
CVE-2009-5135 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-5135):
  The Java XML parser in Echo before 2.1.1 and 3.x before 3.0.b6 allows remote
  attackers to read arbitrary files via a request containing an external
  entity declaration in conjunction with an entity reference, related to an
  XML External Entity (XXE) issue.