Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 432284 (CVE-2012-2687) - <www-servers/apache-2.2.23 : Cross-Site Scripting Vulnerabilities (CVE-2012-2687)
Summary: <www-servers/apache-2.2.23 : Cross-Site Scripting Vulnerabilities (CVE-2012-2...
Alias: CVE-2012-2687
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
Whiteboard: A4 [noglsa]
Depends on:
Reported: 2012-08-22 11:00 UTC by Agostino Sarubbo
Modified: 2012-10-24 00:22 UTC (History)
5 users (show)

See Also:
Package list:
Runtime testing required: ---


Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2012-08-22 11:00:30 UTC
From changelog:

SECURITY: CVE-2012-2687 (
mod_negotiation: Escape filenames in variant list to prevent a
possible XSS for a site where untrusted users can upload files to
a location with MultiViews enabled. [Niels Heinen <heinenn>]

This is fixed in 2.2.23
Comment 1 GLSAMaker/CVETool Bot gentoo-dev 2012-08-24 21:58:45 UTC
CVE-2012-2687 (
  Multiple cross-site scripting (XSS) vulnerabilities in the make_variant_list
  function in mod_negotiation.c in the mod_negotiation module in the Apache
  HTTP Server 2.4.x before 2.4.3, when the MultiViews option is enabled, allow
  remote attackers to inject arbitrary web script or HTML via a crafted
  filename that is not properly handled during construction of a variant list.
Comment 2 Agostino Sarubbo gentoo-dev 2012-09-13 16:23:10 UTC
2.2.23 is out!
Comment 3 Patrick Lauer gentoo-dev 2012-10-12 05:35:12 UTC

in tree and ready for stabilization
Comment 4 Agostino Sarubbo gentoo-dev 2012-10-13 07:13:18 UTC
Arches, please test and mark stable:
Target keywords : "alpha amd64 arm hppa ia64 ppc ppc64 s390 sh sparc x86"
Comment 5 Agostino Sarubbo gentoo-dev 2012-10-13 08:06:42 UTC
amd64 stable
Comment 6 f3d 2012-10-13 12:50:16 UTC
2.4.3 configure fails with itk or peruser MPM.

Ebuild misses required patches.
Comment 7 f3d 2012-10-13 12:55:53 UTC
Oops... Wrong bug. Sorry!
Comment 8 Anthony Basile gentoo-dev 2012-10-13 18:56:59 UTC
stable ppc ppc64
Comment 9 Jeroen Roovers (RETIRED) gentoo-dev 2012-10-14 17:46:09 UTC
Stable for HPPA.
Comment 10 Anthony Basile gentoo-dev 2012-10-15 01:06:21 UTC
stable arm
Comment 11 Andreas Schürch gentoo-dev 2012-10-16 08:36:19 UTC
x86 done.
Comment 12 Raúl Porcel (RETIRED) gentoo-dev 2012-10-20 16:37:00 UTC
alpha/ia64/s390/sh/sparc stable
Comment 13 Agostino Sarubbo gentoo-dev 2012-10-20 16:43:51 UTC
all done. Please vote.
Comment 14 Sean Amoss (RETIRED) gentoo-dev Security 2012-10-24 00:22:17 UTC
Thanks, everyone.

Closing noglsa for XSS.