Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 612650 (CVE-2016-9081) - www-apps/joomla: Security Bypass Vulnerability
Summary: www-apps/joomla: Security Bypass Vulnerability
Status: RESOLVED WONTFIX
Alias: CVE-2016-9081
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: https://developer.joomla.org/security...
Whiteboard: ~4 [ebuild+/cve]
Keywords: PMASKED
Depends on:
Blocks:
 
Reported: 2017-03-14 21:00 UTC by D'juan McDonald (domhnall)
Modified: 2017-06-17 08:41 UTC (History)
4 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
joomla-3.6.5.ebuild (joomla-3.6.5.ebuild,1.46 KB, text/plain)
2017-03-18 21:42 UTC, Harold Anderson
no flags Details

Note You need to log in before you can comment on or make changes to this bug.
Description D'juan McDonald (domhnall) 2017-03-14 21:00:41 UTC
from $url

Joomla! 3.4.4 through 3.6.3 allows attackers to reset username, password, and user group assignments and possibly perform other user account modifications via unspecified vectors.
Publish Date : 2017-01-23 Last Update Date : 2017-01-26

http://www.cvedetails.com/cve/CVE-2016-9081/
Comment 1 D'juan McDonald (domhnall) 2017-03-14 21:13:29 UTC
References For CVE-2016-9081

https://developer.joomla.org/security-centre/661-20161003-core-account-modifications.html CONFIRM

http://www.securityfocus.com/bid/93969

BID 93969 Joomla! Core CVE-2016-9081 Security Bypass Vulnerability Release Date:2016-11-04
Comment 2 Harold Anderson 2017-03-18 20:27:08 UTC
I am the maintainer.  I have added www-apps/joomla-3.6.5-ebuild to my overlay, hnaparst and verified that it works.  

I would ask proxy-maint to add this to the main gentoo repository if they find it acceptable.
Comment 3 Thomas Deutschmann (RETIRED) gentoo-dev 2017-03-18 20:29:30 UTC
OK. Please post the URL to the PR once you have created one.
Comment 4 Harold Anderson 2017-03-18 20:32:14 UTC
What is PR an abbreviation for?
Comment 5 Harold Anderson 2017-03-18 20:35:06 UTC
Proxy maintainers can grab whatever they want from here:

https://github.com/hnaparst/overlay/tree/master/www-apps/joomla

This overlay is also listed in layman as hnaparst.
Comment 6 Harold Anderson 2017-03-18 20:35:27 UTC
Proxy maintainers can grab whatever they want from here:

https://github.com/hnaparst/overlay/tree/master/www-apps/joomla

This overlay is also listed in layman as hnaparst.
Comment 7 Thomas Deutschmann (RETIRED) gentoo-dev 2017-03-18 21:15:26 UTC
PR = Pull Request.

Can you please create a PR against Gentoo's GitHub mirror? Otherwise, please create a patch and attach to this bug.
Comment 8 Harold Anderson 2017-03-18 21:42:58 UTC
Created attachment 467474 [details]
joomla-3.6.5.ebuild
Comment 9 Harold Anderson 2017-03-19 02:36:58 UTC
https://github.com/gentoo/gentoo/pull/4243
Comment 10 Thomas Deutschmann (RETIRED) gentoo-dev 2017-05-17 18:42:18 UTC
# Thomas Deutschmann <whissi@gentoo.org> (17 May 2017)
# Multiple unpatched security vulnerabilities (see bug #603756, #610696, #612650 ...)
# Removal in 30 days.
www-apps/joomla
Comment 11 Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2017-06-17 08:41:09 UTC
commit fe7d7445faf698a716e9f542fdc18b771fa42b6a
Author:     Michał Górny <mgorny@gentoo.org>
AuthorDate: Sat Jun 17 10:29:26 2017
Commit:     Michał Górny <mgorny@gentoo.org>
CommitDate: Sat Jun 17 10:39:58 2017

    www-apps/joomla: Remove last-rited pkg