Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 516078 (CVE-2014-4907) - <net-analyzer/pnp4nagios-0.6.24: Error Page Cross-Site Scripting Vulnerability (CVE-2014-4907)
Summary: <net-analyzer/pnp4nagios-0.6.24: Error Page Cross-Site Scripting Vulnerabilit...
Status: RESOLVED FIXED
Alias: CVE-2014-4907
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: http://secunia.com/advisories/59603/
Whiteboard: B4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2014-07-02 16:01 UTC by Agostino Sarubbo
Modified: 2014-11-10 22:21 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2014-07-02 16:01:49 UTC
From ${URL} :

Description

A vulnerability has been reported in PNP4Nagios, which can be exploited by malicious people to 
conduct cross-site scripting attacks.

Certain input is not properly sanitised in "views/kohana_error_page.php" before being returned to 
the user. This can be exploited to execute arbitrary HTML and script code in a user's browser 
session in context of an affected site.

The vulnerability is reported in versions prior to 0.6.22.


Solution:
Update to version 0.6.22.

Provided and/or discovered by:
Originally reported by Peter Österberg in op5 Monitor.

Original Advisory:
http://docs.pnp4nagios.org/pnp-0.6/dwnld


@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 2 Justin Lecher (RETIRED) gentoo-dev 2014-10-24 06:37:42 UTC
+*pnp4nagios-0.6.24 (24 Oct 2014)
+
+  24 Oct 2014; Justin Lecher <jlec@gentoo.org> +pnp4nagios-0.6.24.ebuild:
+  Version BUmp; fixes security issues #516078 & #516140
+
Comment 3 Sean Amoss (RETIRED) gentoo-dev Security 2014-11-10 22:21:32 UTC
Closing noglsa for XSS.
Comment 4 GLSAMaker/CVETool Bot gentoo-dev 2014-11-10 22:21:51 UTC
CVE-2014-4907 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-4907):
  Cross-site scripting (XSS) vulnerability in
  share/pnp/application/views/kohana_error_page.php in PNP4Nagios before
  0.6.22 allows remote attackers to inject arbitrary web script or HTML via a
  parameter that is not properly handled in an error message.