Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 432284 (CVE-2012-2687)

Summary: <www-servers/apache-2.2.23 : Cross-Site Scripting Vulnerabilities (CVE-2012-2687)
Product: Gentoo Security Reporter: Agostino Sarubbo <ago>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: minor CC: apache-bugs, f3d, mail, patrick, pva
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
Whiteboard: A4 [noglsa]
Package list:
Runtime testing required: ---

Description Agostino Sarubbo gentoo-dev 2012-08-22 11:00:30 UTC
From changelog:

SECURITY: CVE-2012-2687 (cve.mitre.org)
mod_negotiation: Escape filenames in variant list to prevent a
possible XSS for a site where untrusted users can upload files to
a location with MultiViews enabled. [Niels Heinen <heinenn google.com>]

This is fixed in 2.2.23
Comment 1 GLSAMaker/CVETool Bot gentoo-dev 2012-08-24 21:58:45 UTC
CVE-2012-2687 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2687):
  Multiple cross-site scripting (XSS) vulnerabilities in the make_variant_list
  function in mod_negotiation.c in the mod_negotiation module in the Apache
  HTTP Server 2.4.x before 2.4.3, when the MultiViews option is enabled, allow
  remote attackers to inject arbitrary web script or HTML via a crafted
  filename that is not properly handled during construction of a variant list.
Comment 2 Agostino Sarubbo gentoo-dev 2012-09-13 16:23:10 UTC
2.2.23 is out!
Comment 3 Patrick Lauer gentoo-dev 2012-10-12 05:35:12 UTC
=app-admin/apache-tools-2.2.23
=www-server/apache-2.2.23

in tree and ready for stabilization
Comment 4 Agostino Sarubbo gentoo-dev 2012-10-13 07:13:18 UTC
Arches, please test and mark stable:
=www-servers/apache-2.2.23
=app-admin/apache-tools-2.2.23
Target keywords : "alpha amd64 arm hppa ia64 ppc ppc64 s390 sh sparc x86"
Comment 5 Agostino Sarubbo gentoo-dev 2012-10-13 08:06:42 UTC
amd64 stable
Comment 6 f3d 2012-10-13 12:50:16 UTC
2.4.3 configure fails with itk or peruser MPM.

Ebuild misses required patches.
Comment 7 f3d 2012-10-13 12:55:53 UTC
Oops... Wrong bug. Sorry!
Comment 8 Anthony Basile gentoo-dev 2012-10-13 18:56:59 UTC
stable ppc ppc64
Comment 9 Jeroen Roovers (RETIRED) gentoo-dev 2012-10-14 17:46:09 UTC
Stable for HPPA.
Comment 10 Anthony Basile gentoo-dev 2012-10-15 01:06:21 UTC
stable arm
Comment 11 Andreas Schürch gentoo-dev 2012-10-16 08:36:19 UTC
x86 done.
Comment 12 Raúl Porcel (RETIRED) gentoo-dev 2012-10-20 16:37:00 UTC
alpha/ia64/s390/sh/sparc stable
Comment 13 Agostino Sarubbo gentoo-dev 2012-10-20 16:43:51 UTC
all done. Please vote.
Comment 14 Sean Amoss (RETIRED) gentoo-dev Security 2012-10-24 00:22:17 UTC
Thanks, everyone.

Closing noglsa for XSS.