Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 494022 - <www-apps/ikiwiki-3.20140125: osm plugin does not correctly sanitize parameters
Summary: <www-apps/ikiwiki-3.20140125: osm plugin does not correctly sanitize parameters
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: ~4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2013-12-12 10:49 UTC by Agostino Sarubbo
Modified: 2015-01-03 16:13 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2013-12-12 10:49:19 UTC
From ${URL} :

It was found that the osm plugin for ikiwiki uses htmlscrubber (if enabled) to sanitize some parameters. 
Even when it is enabled, it was found that it still does not correctly escape some fields. In particular, 
the "name" parameter is included verbatim, breaking involuntarily javascript when the name contains a 
single quote/apostrophe ('). Due to this, javascript code injection might become trivial.

References:
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=731797


@maintainer(s): since the package has never been marked as stable, we don't need to stabilize it. After the bump, please remove the affected versions from the tree.
Comment 1 Alice Ferrazzi Gentoo Infrastructure gentoo-dev 2014-01-27 08:56:02 UTC
As from comment in: 
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=731797 
The bug is believed to be fixed in last version: 3.20140125
Comment 2 Manuel Rüger (RETIRED) gentoo-dev 2014-01-29 00:26:09 UTC
Ebuild added to the tree. Clean up old ebuild in a few days.
Comment 3 Yury German Gentoo Infrastructure gentoo-dev 2014-05-21 04:08:06 UTC
Maintainer(s), Thank you for cleanup!

No GLSA needed as there are no stable versions.