Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 405685 - app-backup/backuppc: Multiple XSS Vulnerabilities (CVE-2011-{4923,5081})
Summary: app-backup/backuppc: Multiple XSS Vulnerabilities (CVE-2011-{4923,5081})
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2012-02-25 01:54 UTC by GLSAMaker/CVETool Bot
Modified: 2015-03-18 17:59 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2012-02-25 01:54:28 UTC
CVE-2011-5081 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-5081):
  Cross-site scripting (XSS) vulnerability in RestoreFile.pm in BackupPC
  3.1.0, 3.2.1, and possibly other earlier versions allows remote attackers to
  inject arbitrary web script or HTML via the share parameter in a RestoreFile
  action to index.cgi.

CVE-2011-4923 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-4923):
  Cross-site scripting (XSS) vulnerability in View.pm in BackupPC 3.0.0,
  3.1.0, 3.2.0, 3.2.1, and possibly earlier allows remote attackers to inject
  arbitrary web script or HTML via the num parameter in a view action to
  index.cgi, related to the log file viewer, a different vulnerability than
  CVE-2011-3361.
Comment 1 Samuel Damashek (RETIRED) gentoo-dev 2013-12-22 03:33:35 UTC
An update (3.3.0) is available that fixes the XSS vulnerabilities. 02-fix-config.pl-formatting.patch does not run properly on the updated package however. A new patch and ebuild should be created.
Comment 2 Tony Vroon (RETIRED) gentoo-dev 2014-09-18 08:35:07 UTC
+  18 Sep 2014; Tony Vroon <chainsaw@gentoo.org> -backuppc-2.1.2-r1.ebuild,
+  -backuppc-3.2.1-r2.ebuild, -backuppc-3.2.1-r3.ebuild:
+  Remove vulnerable ebuilds for security bug #405685.
Comment 3 Mikle Kolyada (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2015-03-18 17:59:00 UTC
No glsa for XSS.