Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 339168 - <www-apps/horde-gollem-1.1.2: XSS (CVE requested)
Summary: <www-apps/horde-gollem-1.1.2: XSS (CVE requested)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL: http://bugs.horde.org/ticket/9191
Whiteboard: B4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2010-09-29 19:22 UTC by Alex Legler (RETIRED)
Modified: 2010-11-21 16:57 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alex Legler (RETIRED) archtester gentoo-dev Security 2010-09-29 19:22:21 UTC
From $URL:

http://localhost/horde/gollem/view.php?actionID=view_file&type=txt&file=<script>alert("XSS")</script>&dir=../baddir/&driver=file

Vulnerable file : view.php (Line 32 - 46)

Fixed in 1.1.2.
Comment 1 Alex Legler (RETIRED) archtester gentoo-dev Security 2010-09-29 19:24:06 UTC
Arches, please test and mark stable:
=www-apps/horde-gollem-1.1.2
Target keywords : "alpha amd64 hppa ppc sparc x86"
Comment 2 Andreas Schürch gentoo-dev 2010-10-01 11:10:13 UTC
I tested the following things together on x86 with apache (dev-lang/php-5.2.14) and my dovecot imap server. I've seen no problems at all! :-)

www-apps/horde-3.3.9 Bug #336319
www-apps/horde-imp-4.3.8 Bug #307759
www-apps/horde-dimp-1.1.5 Bug #307759
www-apps/horde-gollem-1.1.2 Bug #339168
Comment 3 Tobias Klausmann (RETIRED) gentoo-dev 2010-10-02 14:59:52 UTC
Stable on alpha.
Comment 4 Markos Chandras (RETIRED) gentoo-dev 2010-10-03 16:35:23 UTC
amd64 done
Comment 5 Markus Meier gentoo-dev 2010-10-05 19:52:59 UTC
x86 stable, thanks Andreas
Comment 6 Brent Baude (RETIRED) gentoo-dev 2010-10-08 19:38:40 UTC
ppc done
Comment 7 Raúl Porcel (RETIRED) gentoo-dev 2010-10-10 17:02:07 UTC
sparc stable
Comment 8 Jeroen Roovers (RETIRED) gentoo-dev 2010-10-22 04:01:55 UTC
Stable for HPPA.
Comment 9 Tim Sammut (RETIRED) gentoo-dev 2010-11-19 07:03:48 UTC
GLSA vote: No, XSS.
Comment 10 Stefan Behte (RETIRED) gentoo-dev Security 2010-11-21 16:57:39 UTC
Vote: NO, XSS in webapp. Closing noglsa.