Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 468146 - <www-apps/b2evolution-4.1.7 : "show_statuses[]" SQL Injection Vulnerability
Summary: <www-apps/b2evolution-4.1.7 : "show_statuses[]" SQL Injection Vulnerability
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor
Assignee: Gentoo Security
URL: https://secunia.com/advisories/53250/
Whiteboard: C3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2013-05-01 14:47 UTC by Agostino Sarubbo
Modified: 2013-12-16 13:01 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2013-05-01 14:47:37 UTC
From ${URL} :

Description
High-Tech Bridge SA has discovered a vulnerability in b2evolution, which can be exploited by 
malicious users to conduct SQL injection attacks.

Input passed via the "show_statuses[]" GET parameter to admin.php (when "ctrl" is set to "items", 
"tab" is set to "full", and "blog" is set to a valid blog ID) is not properly sanitised before 
being used in a SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary 
SQL code.

Successful exploitation requires the "restricted" or "normal" access to the administration area 
(granted to the "Bloggers" group by default) and the "View all blogs" permission (not granted to 
the "Bloggers" group by default).

The vulnerability is confirmed in version 4.1.6. Prior versions may also be affected.


Solution
Update to version 4.1.7.

Provided and/or discovered by
High-Tech Bridge SA

Original Advisory
https://www.htbridge.com/advisory/HTB23152


@maintainer(s): after the bump, in case we need to stabilize the package, please say explicitly if it is ready for the stabilization or not
Comment 1 Chris Reffett (RETIRED) gentoo-dev Security 2013-09-03 22:04:20 UTC
Maintainer timeout. Security bumped. Arches, please stabilize:
=www-apps/b2evolution-4.1.7
Target arches: amd64 ppc x86. Thanks!
Comment 2 Agostino Sarubbo gentoo-dev 2013-09-04 12:47:22 UTC
amd64 stable
Comment 3 Agostino Sarubbo gentoo-dev 2013-09-12 17:38:42 UTC
ppc stable
Comment 4 Agostino Sarubbo gentoo-dev 2013-09-14 10:14:10 UTC
x86 stable
Comment 5 Sean Amoss (RETIRED) gentoo-dev Security 2013-09-30 23:03:58 UTC
GLSA vote: no.
Comment 6 Sergey Popov (RETIRED) gentoo-dev 2013-12-16 13:01:59 UTC
GLSA vote: no

Closing as noglsa