Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 513814 (CVE-2014-3005) - <net-analyzer/zabbix-2.2.5: local file inclusion via XXE attack (CVE-2014-3005)
Summary: <net-analyzer/zabbix-2.2.5: local file inclusion via XXE attack (CVE-2014-3005)
Status: RESOLVED FIXED
Alias: CVE-2014-3005
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: B4 [noglsa]
Keywords:
Depends on: 516840
Blocks:
  Show dependency tree
 
Reported: 2014-06-19 09:21 UTC by Agostino Sarubbo
Modified: 2015-12-31 04:37 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2014-06-19 09:21:13 UTC
From ${URL} :

It was reported [1],[2] that the Zabbix frontend supported an XML data import feature, where on the 
server it used DOMDocument to parse the XML.  By default, DOMDocument also parses the external DTD, 
which could allow a remote attacker to use a crafted XML file causing Zabbix to read an arbitrary 
local file, and send the contents of the specified file to a remote server.

This is fixed upstream via:

* svn://svn.zabbix.com/branches/dev/ZBX-8151-18 r46594 for 1.8
* svn://svn.zabbix.com/branches/dev/ZBX-8151-20 r46600 for 2.0+

[1] https://support.zabbix.com/browse/ZBX-8151
[2] http://www.pnigos.com/?p=273


@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 1 Matthew Marlowe (RETIRED) gentoo-dev 2014-06-25 20:42:53 UTC
newer ebuilds with security patches in tree:
zabbix-2.2.4
zabbix-2.0.12-r1
Comment 2 Yury German Gentoo Infrastructure gentoo-dev 2014-06-26 04:03:26 UTC
Maintainers, please advise when eBuilds have had enough testing, and are ready for stabilization.
Comment 3 Matthew Marlowe (RETIRED) gentoo-dev 2014-08-19 21:23:34 UTC
Zabbix 2.2.5 has had enough testing and should become the new stable.
Bug #516840 is stable request.
Comment 4 Yury German Gentoo Infrastructure gentoo-dev 2014-10-15 02:43:39 UTC
Arches, Thank you for your work
Maintainer(s), please drop the vulnerable version.

GLSA Vote: Yes
Comment 5 Matthew Marlowe (RETIRED) gentoo-dev 2014-10-19 22:17:03 UTC
Older ebuilds removed from CVS.
Comment 6 Yury German Gentoo Infrastructure gentoo-dev 2015-12-31 04:37:49 UTC
(In reply to Yury German from comment #4)
 
> GLSA Vote: Yes

Revising: GLSA Vote: No
Thank you all. Closing as noglsa.