Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 43474 - phpBB 2.0.6d - security fix (viewtopic.php cross-site scripting vulnerability)
Summary: phpBB 2.0.6d - security fix (viewtopic.php cross-site scripting vulnerability)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All All
: Highest critical (vote)
Assignee: Gentoo Web Application Packages Maintainers
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2004-03-02 06:04 UTC by Carsten Lohrke (RETIRED)
Modified: 2011-10-30 22:41 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Carsten Lohrke (RETIRED) gentoo-dev 2004-03-02 06:04:33 UTC
http://www.phpbb.com/phpBB/viewtopic.php?f=14&t=177594
Comment 1 Rajiv Aaron Manglani (RETIRED) gentoo-dev 2004-03-02 07:52:44 UTC
net-www heard, please update. personally i do not think this needs a GLSA.

from the url:

A new release of phpBB 2.0.6 is now available for download, phpBB 2.0.6d. This addresses a vulnerability in viewtopic, a potential issue with login and may address current issues with Zend Optimizer 2.5. 

The viewtopic vulnerability, again released to bugtraq without us first being notified ... sigh, is of the cross-site scripting type. While relatively minor it can allow information to be obtained without the users direct knowledge. Thus we recommend all admins upgrade their board as soon as possible. The relevant fix is noted below. The login issue is similar in nature and has been addressed to counter potential future problems. 
...

bump to latest version, or use the patch available at that url.


Comment 2 Martin Holzer (RETIRED) gentoo-dev 2004-03-02 08:19:14 UTC
2.0.6-r2 is in cvs which is 2.0.6d 

the only problem i see is, the filename is the same

can we close this bug ?
Comment 3 Carsten Lohrke (RETIRED) gentoo-dev 2004-03-02 13:37:12 UTC
Had a look at the code. It's fixed already. Before adding this bug report the latest changelog entry was from december. Hey - you're fast! :)