Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 541912 - <dev-tcltk/tcllib-1.15-r2: Cross-Site-Scripting (XSS) in html::textarea
Summary: <dev-tcltk/tcllib-1.15-r2: Cross-Site-Scripting (XSS) in html::textarea
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: B4 [noglsa]
Keywords:
Depends on: 543640
Blocks:
  Show dependency tree
 
Reported: 2015-03-02 15:08 UTC by Agostino Sarubbo
Modified: 2015-04-04 14:54 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2015-03-02 15:08:59 UTC
From ${URL} :

The following flaw was reported against tcllib:

User supplied input is directly inserted into the <textarea> as default value, e.g. a textarea 
named 'ta' with a parameter of ta=XXX results in `<textarea>XXX</textarea>`

This can be used to break out of the <textarea>-context and insert arbitrary HTML content such as 
<script>-Tags.

The attack is possible using HTTP GET requests as well as POST and multipart form encoded POST 
requests.

Upstream Issue:

http://core.tcl.tk/tcllib/tktview/09110adc430de8c91d26015f9697cdd099755e63

Upstream patch:

http://core.tcl.tk/tcllib/vpatch?from=45c988bdfc7b9b74&to=212d1feefe48dcc8


@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 1 Justin Lecher (RETIRED) gentoo-dev 2015-03-03 13:59:53 UTC
+*tcllib-1.15-r2 (03 Mar 2015)
+
+  03 Mar 2015; Justin Lecher <jlec@gentoo.org>
+  +files/tcllib-1.15-XSS-vuln.patch, +files/tcllib-1.15-test.patch,
+  +files/tcllib-1.16-XSS-vuln.patch, +files/tcllib-1.16-test.patch,
+  +tcllib-1.15-r2.ebuild, +tcllib-1.16.ebuild:
+  Version Bump, #531864; fix testfailure, #478216; backport security fix,
+  #541912
+
Comment 2 Justin Lecher (RETIRED) gentoo-dev 2015-03-03 14:02:01 UTC
@arches please go ahead, testsuite included

Target:

dev-tcltk/tcllib-1.15-r2
Comment 3 Agostino Sarubbo gentoo-dev 2015-03-04 09:51:09 UTC
amd64 stable
Comment 4 Jeroen Roovers (RETIRED) gentoo-dev 2015-03-04 23:32:43 UTC
Stable for HPPA.
Comment 5 Sergey Popov gentoo-dev 2015-03-08 14:02:11 UTC
s390 stable
Comment 6 Andreas Schürch gentoo-dev 2015-03-20 15:14:27 UTC
X86 stable, thanks Justin! :-)
Comment 7 Agostino Sarubbo gentoo-dev 2015-03-25 16:07:56 UTC
ia64 stable
Comment 8 Agostino Sarubbo gentoo-dev 2015-03-26 11:22:58 UTC
ppc stable
Comment 9 Agostino Sarubbo gentoo-dev 2015-03-26 11:30:05 UTC
ppc64 stable
Comment 10 Agostino Sarubbo gentoo-dev 2015-03-30 09:51:24 UTC
sparc stable
Comment 11 Agostino Sarubbo gentoo-dev 2015-03-30 10:03:59 UTC
alpha stable.

Maintainer(s), please cleanup.
Security, please vote.
Comment 12 Justin Lecher (RETIRED) gentoo-dev 2015-03-30 15:42:15 UTC
+  30 Mar 2015; Justin Lecher <jlec@gentoo.org> -tcllib-1.15-r1.ebuild:
+  Clean vulnerable
+


cleaned.
Comment 13 Yury German Gentoo Infrastructure gentoo-dev 2015-04-04 14:54:43 UTC
Arches and Maintainer(s), Thank you for your work.

No GLSA's for Cross-Site Scripting (XSS) as per policy. 
Closing noglsa