Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 358973 (CVE-2011-1156) - <dev-python/feedparser-5.0.1: Multiple vulnerabilities (CVE-2011-{1156,1157,1158})
Summary: <dev-python/feedparser-5.0.1: Multiple vulnerabilities (CVE-2011-{1156,1157,1...
Status: RESOLVED FIXED
Alias: CVE-2011-1156
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://code.google.com/p/feedparser/
Whiteboard: B3 [noglsa]
Keywords:
Depends on: 359819
Blocks:
  Show dependency tree
 
Reported: 2011-03-15 04:06 UTC by Tim Sammut (RETIRED)
Modified: 2011-10-08 21:49 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Tim Sammut (RETIRED) gentoo-dev 2011-03-15 04:06:18 UTC
The feedparser homepage at $URL indicates that 5.0.1 includes three security fixes.

Current release: 5.0.1 - February 20, 2011

    * Fix  issue 91  (invalid text in XML declaration causes sanitizer to crash)
    * Fix  issue 254  (sanitization can be bypassed by malformed XML comments)
    * Fix  issue 255  (sanitizer doesn't strip unsafe URI schemes) 


@python, 5.0.1 is already in the tree; thank you. Is it an appropriate target for stabilization?
Comment 1 Paweł Hajdan, Jr. (RETIRED) gentoo-dev 2011-03-21 11:15:21 UTC
Maintainer timeout (short because it's a security issue), let's add arches.

Arches, please stabilize =dev-python/feedparser-5.0.1
Comment 2 Kacper Kowalik (Xarthisius) (RETIRED) gentoo-dev 2011-03-21 11:21:21 UTC
ppc/ppc64 stable
Comment 3 Markos Chandras (RETIRED) gentoo-dev 2011-03-21 11:48:29 UTC
amd64 done
Comment 4 Andreas Schürch gentoo-dev 2011-03-21 17:44:40 UTC
I tested on x86 and found a failing test, if libsoup is installed. Bug 359819
This seems to be a regression.
Comment 5 Thomas Kahle (RETIRED) gentoo-dev 2011-03-22 12:15:44 UTC
Added as a dependency, will wait a bit before stabeling.
Comment 6 Arfrever Frehtes Taifersar Arahesis (RETIRED) gentoo-dev 2011-03-22 12:22:02 UTC
dev-python/feedparser-4.1 doesn't have any tests, so test failures in newer versions are not a regression.
Comment 7 Tim Sammut (RETIRED) gentoo-dev 2011-03-22 23:25:18 UTC
Adding CVE assignment per http://www.openwall.com/lists/oss-security/2011/03/15/11.

> > * Fix issue 91 (invalid text in XML declaration causes sanitizer to
> > crash)
https://code.google.com/p/feedparser/issues/detail?id=91

Use CVE-2011-1156


> > * Fix issue 254 (sanitization can be bypassed by malformed XML
> > comments)
https://code.google.com/p/feedparser/issues/detail?id=254

Use CVE-2011-1157


> > * Fix issue 255 (sanitizer doesn't strip unsafe URI schemes)
https://code.google.com/p/feedparser/issues/detail?id=255

Use CVE-2011-1158
Comment 8 Thomas Kahle (RETIRED) gentoo-dev 2011-03-23 15:26:36 UTC
Oh yeah the good old it's not a regression train. Great. It's still bad, you know... x86 stable.
Comment 9 Tobias Klausmann (RETIRED) gentoo-dev 2011-03-26 19:58:27 UTC
Stable on alpha.
Comment 10 Raúl Porcel (RETIRED) gentoo-dev 2011-04-02 11:54:15 UTC
ia64/sparc stable
Comment 11 Tim Sammut (RETIRED) gentoo-dev 2011-04-02 22:14:43 UTC
Thanks, folks. GLSA Vote: no.
Comment 12 GLSAMaker/CVETool Bot gentoo-dev 2011-06-13 18:21:04 UTC
CVE-2011-1158 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1158):
  Cross-site scripting (XSS) vulnerability in feedparser.py in Universal Feed
  Parser (aka feedparser or python-feedparser) 5.x before 5.0.1 allows remote
  attackers to inject arbitrary web script or HTML via an unexpected URI
  scheme, as demonstrated by a javascript: URI.

CVE-2011-1157 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1157):
  Cross-site scripting (XSS) vulnerability in feedparser.py in Universal Feed
  Parser (aka feedparser or python-feedparser) 5.x before 5.0.1 allows remote
  attackers to inject arbitrary web script or HTML via malformed XML comments.

CVE-2011-1156 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1156):
  feedparser.py in Universal Feed Parser (aka feedparser or python-feedparser)
  before 5.0.1 allows remote attackers to cause a denial of service
  (application crash) via a malformed DOCTYPE declaration.
Comment 13 Pierre-Yves Rofes (RETIRED) gentoo-dev 2011-10-08 21:49:55 UTC
voting no too, and closing.