Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 264568 - <media-sound/banshee-1.4.3-r2 DAAP Cross-site scripting (CVE-2009-1175)
Summary: <media-sound/banshee-1.4.3-r2 DAAP Cross-site scripting (CVE-2009-1175)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL: http://bugzilla.gnome.org/show_bug.cg...
Whiteboard: B3 [noglsa]
Keywords:
: 272322 (view as bug list)
Depends on:
Blocks:
 
Reported: 2009-04-01 23:33 UTC by Robert Buchholz (RETIRED)
Modified: 2010-08-12 08:10 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Buchholz (RETIRED) gentoo-dev 2009-04-01 23:33:05 UTC
CVE-2009-1175 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-1175):
  Cross-site scripting (XSS) vulnerability in apps/web/vs_diag.cgi in
  the DAAP extension in Banshee 1.4.2 allows remote attackers to inject
  arbitrary web script or HTML via the server parameter, which is not
  properly handled in an error message.
Comment 1 Robert Buchholz (RETIRED) gentoo-dev 2009-04-01 23:35:25 UTC
Our stable 0.12.1 ships similar files to the 1.4.2 in question with relation to the DAAP web service, so I rated this B3. Let's see how upstream comes up with a patch.
Comment 2 Samuli Suominen (RETIRED) gentoo-dev 2009-07-23 09:56:56 UTC
Fixed in 1.5.0 by the looks of it, but it's p.masked by loki_val, with message
"Development version, Work-In-Progress".

<snap>

Comment #4 from Gabriel Burt  (banshee developer, points: 21)
2009-05-04 16:22 UTC [reply]

I have pushed a fix to both the stable branch (from which 1.4.4 will be
released) and master (from which 1.5.0 etc will come).

</snap>
Comment 3 Samuli Suominen (RETIRED) gentoo-dev 2009-07-23 10:04:07 UTC
+*banshee-1.4.3-r2 (23 Jul 2009)
+
+  23 Jul 2009; Samuli Suominen <ssuominen@gentoo.org>
+  +banshee-1.4.3-r2.ebuild, +files/banshee-1.4.3-CVE-2009-1175.patch:
+  Backport patch from upstream git for DAAP Cross-site scripting
+  CVE-2009-1175 wrt #264568.
Comment 4 Samuli Suominen (RETIRED) gentoo-dev 2009-07-23 10:04:52 UTC
*** Bug 272322 has been marked as a duplicate of this bug. ***
Comment 6 Christian Faulhammer (RETIRED) gentoo-dev 2009-07-23 20:31:04 UTC
x86 stable
Comment 7 Markus Meier gentoo-dev 2009-07-27 22:07:21 UTC
amd64 stable
Comment 8 Tobias Heinlein (RETIRED) gentoo-dev 2009-11-26 19:37:09 UTC
ppc, ping
Comment 9 Brent Baude (RETIRED) gentoo-dev 2010-01-24 14:04:45 UTC
ppc done
Comment 10 Alex Legler (RETIRED) archtester gentoo-dev Security 2010-08-12 08:10:31 UTC
XSS → noglsa.