Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 473676 (CVE-2013-2182) - <www-servers/monkeyd-1.5.1: Bypass protected directory by Monkey HTTPD (CVE-2013-2182)
Summary: <www-servers/monkeyd-1.5.1: Bypass protected directory by Monkey HTTPD (CVE-2...
Status: RESOLVED FIXED
Alias: CVE-2013-2182
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: http://www.openwall.com/lists/oss-sec...
Whiteboard: B4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2013-06-18 08:52 UTC by Agostino Sarubbo
Modified: 2014-08-04 19:30 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2013-06-18 08:52:56 UTC
From ${URL} :

Monkey HTTPD - Mandril security plugin
Mandril is a plugin which provides a security layer to Monkey through
rules which can be applied to the request URI or by network address.

A vulnerability was found in the way as the URI are validated. The plugin check
the configuration rules against possible encoded URIs.

PoC
---

Configuration sample:
[RULES]
Deny_URL /test/

To bypass such rule, we just need to make a request like:
http://yourhost/%2ftest/


Report
------
http://bugs.monkey-project.com/ticket/186


CREDITS
-------
Felipe Pena


@maintainer(s): after the bump, in case we need to stabilize the package, please say explicitly if it is ready for the stabilization or not.
Comment 1 Anthony Basile gentoo-dev 2014-07-20 14:36:28 UTC
This has been long fix.  See


    https://github.com/monkey/monkey/issues/92
Comment 2 Yury German Gentoo Infrastructure gentoo-dev 2014-07-22 00:07:42 UTC
(In reply to Anthony Basile from comment #1)
> This has been long fix.  See
> 

Do you know what version it was fixed in, just for completeness, before we close.
Comment 3 Anthony Basile gentoo-dev 2014-07-22 00:47:10 UTC
(In reply to Yury German from comment #2)
> (In reply to Anthony Basile from comment #1)
> > This has been long fix.  See
> > 
> 
> Do you know what version it was fixed in, just for completeness, before we
> close.


The commit went in on May 20 and would have been pushed out in 1.5.1.
Comment 4 Yury German Gentoo Infrastructure gentoo-dev 2014-07-26 04:33:58 UTC
Arches and Maintainer(s), Thank you for your work.

GLSA Vote: No
Comment 5 Tobias Heinlein (RETIRED) gentoo-dev 2014-08-04 19:30:10 UTC
NO too, closing. Thanks everyone.