Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 443500 (CVE-2012-5527) - <mail-client/claws-mail-vcalendar-2.0.13-r1: Local password disclosure in status tray (CVE-2012-5527)
Summary: <mail-client/claws-mail-vcalendar-2.0.13-r1: Local password disclosure in sta...
Status: RESOLVED FIXED
Alias: CVE-2012-5527
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: http://www.thewildbeast.co.uk/claws-m...
Whiteboard: B3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2012-11-16 11:43 UTC by Sean Amoss (RETIRED)
Modified: 2012-12-16 22:02 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sean Amoss (RETIRED) gentoo-dev Security 2012-11-16 11:43:57 UTC
From the upstream bug at $URL:

"In some instances, it might be the case that the only possible way to access a
calendaring service is through https, and in such cases, the only way to
authenticate (at least within the confines of vCalendar) is by embedding the
username:password into the ics URL and/or have a 'private' url that shouldn't
be shared.  

In either case, after configuring a calendar and trying to access it, the full
url is displayed in the status tray when trying to poll the calendar, something
like:

Fetching 'https://user:password@server.example.com/location/of/my/Calendar'...

Thus, use of the vCalendar plugin really isn't suitable or secure for such
configurations!  In the scenarios above, the former is more of a concern but
neither is one you'd necessarily want to expose to prying eyes.  Even a google
calendar "private url", for example, is visible it its entirety within the
status tray."
Comment 1 Christian Faulhammer (RETIRED) gentoo-dev 2012-11-18 11:08:15 UTC
I added a -r1 of 2.0.13 with a fix applied.  2.0.14 is available but does not contain this fix, I will have to bump Claws Mail itself and all plugins, this may take one more day or two.

Arches, please go on.
Comment 2 Sergey Popov gentoo-dev 2012-11-22 13:56:19 UTC
+  22 Nov 2012; Sergey Popov <pinkbyte@gentoo.org>
+  claws-mail-vcalendar-2.0.13-r1.ebuild:
+  Stable on amd64, wrt bug #443500
Comment 3 Anthony Basile gentoo-dev 2012-11-23 15:12:15 UTC
stable ppc ppc64
Comment 4 Agostino Sarubbo gentoo-dev 2012-12-03 20:43:03 UTC
x86 stable
Comment 5 Raúl Porcel (RETIRED) gentoo-dev 2012-12-15 20:13:16 UTC
Its not stable on sparc
Comment 6 Sean Amoss (RETIRED) gentoo-dev Security 2012-12-16 14:36:25 UTC
Thanks, everyone.

GLSA vote: no.
Comment 7 Stefan Behte (RETIRED) gentoo-dev Security 2012-12-16 22:02:53 UTC
Vote: no. Closing noglsa.