Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 264568

Summary: <media-sound/banshee-1.4.3-r2 DAAP Cross-site scripting (CVE-2009-1175)
Product: Gentoo Security Reporter: Robert Buchholz (RETIRED) <rbu>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: minor CC: sound
Priority: High    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: http://bugzilla.gnome.org/show_bug.cgi?id=577270
Whiteboard: B3 [noglsa]
Package list:
Runtime testing required: ---

Description Robert Buchholz (RETIRED) gentoo-dev 2009-04-01 23:33:05 UTC
CVE-2009-1175 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-1175):
  Cross-site scripting (XSS) vulnerability in apps/web/vs_diag.cgi in
  the DAAP extension in Banshee 1.4.2 allows remote attackers to inject
  arbitrary web script or HTML via the server parameter, which is not
  properly handled in an error message.
Comment 1 Robert Buchholz (RETIRED) gentoo-dev 2009-04-01 23:35:25 UTC
Our stable 0.12.1 ships similar files to the 1.4.2 in question with relation to the DAAP web service, so I rated this B3. Let's see how upstream comes up with a patch.
Comment 2 Samuli Suominen (RETIRED) gentoo-dev 2009-07-23 09:56:56 UTC
Fixed in 1.5.0 by the looks of it, but it's p.masked by loki_val, with message
"Development version, Work-In-Progress".

<snap>

Comment #4 from Gabriel Burt  (banshee developer, points: 21)
2009-05-04 16:22 UTC [reply]

I have pushed a fix to both the stable branch (from which 1.4.4 will be
released) and master (from which 1.5.0 etc will come).

</snap>
Comment 3 Samuli Suominen (RETIRED) gentoo-dev 2009-07-23 10:04:07 UTC
+*banshee-1.4.3-r2 (23 Jul 2009)
+
+  23 Jul 2009; Samuli Suominen <ssuominen@gentoo.org>
+  +banshee-1.4.3-r2.ebuild, +files/banshee-1.4.3-CVE-2009-1175.patch:
+  Backport patch from upstream git for DAAP Cross-site scripting
+  CVE-2009-1175 wrt #264568.
Comment 4 Samuli Suominen (RETIRED) gentoo-dev 2009-07-23 10:04:52 UTC
*** Bug 272322 has been marked as a duplicate of this bug. ***
Comment 6 Christian Faulhammer (RETIRED) gentoo-dev 2009-07-23 20:31:04 UTC
x86 stable
Comment 7 Markus Meier gentoo-dev 2009-07-27 22:07:21 UTC
amd64 stable
Comment 8 Tobias Heinlein (RETIRED) gentoo-dev 2009-11-26 19:37:09 UTC
ppc, ping
Comment 9 Brent Baude (RETIRED) gentoo-dev 2010-01-24 14:04:45 UTC
ppc done
Comment 10 Alex Legler (RETIRED) archtester gentoo-dev Security 2010-08-12 08:10:31 UTC
XSS → noglsa.