Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 354345 (CVE-2011-0050) - <net-irc/cgiirc-0.5.10: XSS in R param in nonjs interface (CVE-2011-0050)
Summary: <net-irc/cgiirc-0.5.10: XSS in R param in nonjs interface (CVE-2011-0050)
Status: RESOLVED FIXED
Alias: CVE-2011-0050
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High trivial (vote)
Assignee: Gentoo Security
URL: http://packetstormsecurity.org/files/...
Whiteboard: ~4 [noglsa]
Keywords:
: 417377 (view as bug list)
Depends on:
Blocks:
 
Reported: 2011-02-10 11:01 UTC by Yury German
Modified: 2013-09-03 21:29 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
cgiirc-0.5.10.ebuild (cgiirc-0.5.10.ebuild,981 bytes, text/plain)
2012-09-04 13:01 UTC, Ondrej Grover
no flags Details

Note You need to log in before you can comment on or make changes to this bug.
Description Yury German Gentoo Infrastructure gentoo-dev 2011-02-10 11:01:55 UTC
Michael Brooks (Sitewatch) discovered an XSS issue in the nonjs
interface that allowed HTML injection via a crafted parameter.

0.5.10 is now available. This is actually just 0.5.9 with the
following fix:

- CVE-2011-0050: XSS in R param in nonjs interface

Debian security announcement:
http://packetstormsecurity.org/files/view/98370/dsa-2158-1.txt
Comment 1 GLSAMaker/CVETool Bot gentoo-dev 2011-06-24 00:33:45 UTC
CVE-2011-0050 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-0050):
  Cross-site scripting (XSS) vulnerability in the nonjs interface
  (interfaces/nonjs.pm) in CGI:IRC before 0.5.10 allows remote attackers to
  inject arbitrary web script or HTML via the R parameter.
Comment 2 Ondrej Grover 2012-09-04 08:13:17 UTC
could someone please make this depend on bug #417377 ?
Comment 3 Alex Legler (RETIRED) archtester gentoo-dev Security 2012-09-04 09:15:49 UTC
*** Bug 417377 has been marked as a duplicate of this bug. ***
Comment 4 Ondrej Grover 2012-09-04 13:01:12 UTC
Created attachment 322902 [details]
cgiirc-0.5.10.ebuild

Ok, as bug #417377 has been closed, I will post my new ebuild here.
Essentially I just renamed the 0.5.9 ebuild to 0.5.10 and modified HOMEPAGE and SRC_URI, because it seems that the project has moved off sourceforge.net to some private hosting.
Once it's on the gentoo mirrors, someone please modify the SRC_URI again.
Made manifest, installed and everything works well ;)
Comment 5 Chris Reffett (RETIRED) gentoo-dev Security 2013-09-03 21:29:55 UTC
Maintainer very much timed out. Bumped. Closing noglsa.
+*cgiirc-0.5.10 (03 Sep 2013)
+
+  03 Sep 2013; Chris Reffett <creffett@gentoo.org> +cgiirc-0.5.10.ebuild,
+  -cgiirc-0.5.9.ebuild:
+  Security bump wrt bug 354345
+