Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 717716 (CVE-2020-5501, CVE-2020-5502) - <www-apps/phpBB-3.3.1: Multiple vulnerabilities (CVE-2020-{5501,5502})
Summary: <www-apps/phpBB-3.3.1: Multiple vulnerabilities (CVE-2020-{5501,5502})
Status: RESOLVED FIXED
Alias: CVE-2020-5501, CVE-2020-5502
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial
Assignee: Gentoo Security
URL:
Whiteboard: ~4 [noglsa cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2020-04-16 13:44 UTC by GLSAMaker/CVETool Bot
Modified: 2020-08-24 00:27 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2020-04-16 13:44:26 UTC
CVE-2020-5502 (https://nvd.nist.gov/vuln/detail/CVE-2020-5502):
  phpBB 3.2.8 allows a CSRF attack that can approve pending group memberships.

CVE-2020-5501 (https://nvd.nist.gov/vuln/detail/CVE-2020-5501):
  phpBB 3.2.8 allows a CSRF attack that can modify a group avatar.
Comment 1 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-05-14 21:24:22 UTC
@maintainer(s), please bump
Comment 2 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2020-07-30 02:28:19 UTC
Ping
Comment 3 Larry the Git Cow gentoo-dev 2020-08-23 22:00:32 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=158312052d73276281ba9e49ddaf4c792fe25cd3

commit 158312052d73276281ba9e49ddaf4c792fe25cd3
Author:     James Le Cuirot <chewi@gentoo.org>
AuthorDate: 2020-08-23 21:59:47 +0000
Commit:     James Le Cuirot <chewi@gentoo.org>
CommitDate: 2020-08-23 21:59:47 +0000

    www-apps/phpBB: Drop old and vulnerable 3.2.8
    
    Bug: https://bugs.gentoo.org/717716
    Bug: https://bugs.gentoo.org/737908
    Package-Manager: Portage-3.0.4, Repoman-3.0.1
    Signed-off-by: James Le Cuirot <chewi@gentoo.org>

 www-apps/phpBB/Manifest           |  1 -
 www-apps/phpBB/phpBB-3.2.8.ebuild | 56 ---------------------------------------
 2 files changed, 57 deletions(-)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=88bb953e4c11c2cd8e895fb086f0b48629f3ce87

commit 88bb953e4c11c2cd8e895fb086f0b48629f3ce87
Author:     James Le Cuirot <chewi@gentoo.org>
AuthorDate: 2020-08-23 21:58:49 +0000
Commit:     James Le Cuirot <chewi@gentoo.org>
CommitDate: 2020-08-23 21:58:49 +0000

    www-apps/phpBB: Version bump to 3.3.1
    
    Bug: https://bugs.gentoo.org/717716
    Bug: https://bugs.gentoo.org/737908
    Package-Manager: Portage-3.0.4, Repoman-3.0.1
    Signed-off-by: James Le Cuirot <chewi@gentoo.org>

 www-apps/phpBB/Manifest           |  1 +
 www-apps/phpBB/phpBB-3.3.1.ebuild | 57 +++++++++++++++++++++++++++++++++++++++
 2 files changed, 58 insertions(+)
Comment 4 James Le Cuirot gentoo-dev 2020-08-23 22:02:06 UTC
Sorry this took so long.
Comment 5 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2020-08-24 00:27:47 UTC
(In reply to James Le Cuirot from comment #4)
> Sorry this took so long.

No worries!

Tree is clean, no GLSA, all done.