Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 392325 (CVE-2011-4357)

Summary: dev-libs/clearsilver format string flaw vulnerability (CVE-2011-4357)
Product: Gentoo Security Reporter: Agostino Sarubbo <ago>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: normal CC: proxy-maint, treecleaner, web-apps
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=649322
Whiteboard: B2 [noglsa]
Package list:
Runtime testing required: ---

Description Agostino Sarubbo gentoo-dev 2011-11-28 21:19:49 UTC
From debian bugzilla at $URL:

Description:

A remote attacker could provide a specially-crafted input, which once processed by an application, using the Python language API of ClearSilver neo_cgi module, could lead to that particular application crash, or, potentially arbitrary code
execution with the privileges of the user running the application.

Solution:
There is a proposed patch:
https://bugzilla.redhat.com/attachment.cgi?id=537196
Comment 1 GLSAMaker/CVETool Bot gentoo-dev 2011-12-12 23:53:19 UTC
CVE-2011-4357 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-4357):
  Format string vulnerability in the p_cgi_error function in python/neo_cgi.c
  in the Python CGI Kit (neo_cgi) module for Clearsilver 0.10.5 and earlier
  allows remote attackers to cause a denial of service (crash) and possibly
  execute arbitrary code via format string specifiers that are not properly
  handled when creating CGI error messages using the cgi_error API function.
Comment 2 Kristian Fiskerstrand (RETIRED) gentoo-dev 2014-08-05 19:20:49 UTC
This is fixed upstream in http://code.google.com/p/clearsilver/source/detail?r=919 but there has been no release since then. Recommended to patch using the provided patch  in comment 0 / upstream patch.
Comment 3 Aaron Bauman (RETIRED) gentoo-dev 2016-02-29 14:05:54 UTC
still no movement on a patch or release from upstream. candidate for tree cleaning with no rdeps.
Comment 4 Aaron Bauman (RETIRED) gentoo-dev 2016-03-05 00:15:33 UTC
# Aaron Bauman <bman@gentoo.org> (05 Mar 2016)
# Per security bug #392325 this package is vulnerable
# and unmaintained.  Removal in 30 days.
dev-libs/clearsilver