Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 395005 (CVE-2011-4615) - <net-analyzer/zabbix-1.8.10-r1: Script Insertion Vulnerabilities (CVE-2011-4615)
Summary: <net-analyzer/zabbix-1.8.10-r1: Script Insertion Vulnerabilities (CVE-2011-4615)
Status: RESOLVED FIXED
Alias: CVE-2011-4615
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: http://secunia.com/advisories/47216/
Whiteboard: B4 [noglsa]
Keywords:
Depends on: CVE-2011-5027
Blocks: CVE-2011-4674
  Show dependency tree
 
Reported: 2011-12-16 21:51 UTC by Michael Harrison
Modified: 2012-02-21 02:56 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Michael Harrison 2011-12-16 21:51:41 UTC
1) Input passed to "host groups" names is not properly sanitised before being used. This can be exploited to insert HTML and script code, which will be executed in a user's browser session in context of an affected site if malicious data is viewed.

Successful exploitation of this vulnerability requires access rights to modify "host group" names.

2) Certain unspecified input to the profiler is not properly sanitised before being used. This can be exploited to insert HTML and script code, which will be executed in a user's browser session in context of an affected site if malicious data is viewed.

Solution:Fixed in version 1.8.10rc

Original Advisory:
http://www.zabbix.com/rn1.8.10rc1.php
https://support.zabbix.com/browse/ZBX-4015
Comment 1 Matthew Marlowe (RETIRED) gentoo-dev 2011-12-16 22:20:42 UTC
I'll have an ebuild for 1.8.10rc1 in the tree shortly.  I'm a little leery of stabilizing it because it's a release candidate and not a release yet -- I'm not sure how much zabbix sa has tested it, but the changelog shows nothing except for bugfixes so I wouldn't expect any issues.
Comment 2 Michael Harrison 2011-12-16 22:22:49 UTC
Thank You Matthew
Comment 3 Matthew Marlowe (RETIRED) gentoo-dev 2011-12-16 23:21:18 UTC
1.8.10rc1 in tree with testing keywords: ~amd64, ~x86.
Releases equal or less than 1.8.6 were removed and 1.8.7 -> 1.8.9 retained.
Comment 4 Tim Sammut (RETIRED) gentoo-dev 2011-12-17 00:12:42 UTC
(In reply to comment #3)
> 1.8.10rc1 in tree with testing keywords: ~amd64, ~x86.
> Releases equal or less than 1.8.6 were removed and 1.8.7 -> 1.8.9 retained.

Thanks, Matthew. Do you have an idea when 1.8.10 will be released?
Comment 5 Matthew Marlowe (RETIRED) gentoo-dev 2011-12-17 01:51:54 UTC
1.8 release candidates usually get followed by real releases within a week or two, or worst case a follow-up candidate.  In general, zabbix is pushing out new releases for 1.8 roughly once/month.  So, I'd think we'd see 1.8.10 no later than the first week of January, and possibly next week, but I haven't spoken to the dev team and I'd doubt they'd give us any commitment even if we asked.  The zabbix guys are pretty good about following the "it will be done when its done" dev model.
Comment 6 Tim Sammut (RETIRED) gentoo-dev 2011-12-17 04:18:56 UTC
Ok, thanks. I think it makes sense to wait a little while for a full release. I'd rather not wait too long though.
Comment 7 Lars Wendler (Polynomial-C) (RETIRED) gentoo-dev 2011-12-30 08:30:37 UTC
+*zabbix-1.8.10 (30 Dec 2011)
+
+  30 Dec 2011; Lars Wendler <polynomial-c@gentoo.org>
+  -zabbix-1.8.10_rc1.ebuild, +zabbix-1.8.10.ebuild:
+  non-maintainer commit: Version bump (with kind permission from bonsaikitten).
+  Removed old. This fixes bug #395975 and should help solving bug #396495.
+
Comment 8 Tim Sammut (RETIRED) gentoo-dev 2012-01-08 19:57:46 UTC
Unless I am mistaken, this too is a XSS vulnerability. Rerating B4, and closing noglsa. Please reopen if you disagree. Thanks!
Comment 9 GLSAMaker/CVETool Bot gentoo-dev 2012-02-21 01:24:42 UTC
CVE-2011-4615 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-4615):
  Multiple cross-site scripting (XSS) vulnerabilities in Zabbix before 1.8.10
  allow remote attackers to inject arbitrary web script or HTML via the gname
  parameter (aka host groups name) to (1) hostgroups.php and (2) usergrps.php,
  the update action to (3) hosts.php and (4) scripts.php, and (5)
  maintenance.php.
Comment 10 Matthew Marlowe (RETIRED) gentoo-dev 2012-02-21 02:56:07 UTC
Now that we've had enough time using 1.8.10, and for nearly everyone to migrate, I've removed any of the older ebuilds that might be impacted by vulnerabilities.   1.8.10-r1 is the only ebuild for the 1.8.x tree now.