Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 509352 (CVE-2014-3207) - <net-misc/sks-1.1.5: reflected cross-site scripting flaw (CVE-2014-3207)
Summary: <net-misc/sks-1.1.5: reflected cross-site scripting flaw (CVE-2014-3207)
Status: RESOLVED FIXED
Alias: CVE-2014-3207
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: ~4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2014-05-02 07:59 UTC by Agostino Sarubbo
Modified: 2014-05-11 12:56 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2014-05-02 07:59:11 UTC
From ${URL} :

A reflected cross-site scripting flaw was reported in Synchronizing Key Server (SKS), and OpenPGP keyserver. A remote attacker could use this flaw to perform a cross-site scripting attack.

References:

https://bugzilla.mozilla.org/show_bug.cgi?id=952077
https://bitbucket.org/skskeyserver/sks-keyserver/issue/26/unfiltered-xss
https://bitbucket.org/skskeyserver/sks-keyserver/pull-request/30/issue26-fix-a-non-persistent-cross-site
https://bitbucket.org/kristianf/sks-keyserver-patches/src/tip/Issue26?at=default
http://seclists.org/oss-sec/2014/q2/225


@maintainer(s): since the package or the affected version has never been marked as stable, we don't need to stabilize it. After the bump, please remove the affected versions from the tree.
Comment 1 Kristian Fiskerstrand (RETIRED) gentoo-dev 2014-05-02 08:08:38 UTC
Indeed. Once we release a 1.1.5 of SKS an ebuild will be created for it.
Comment 2 Kristian Fiskerstrand (RETIRED) gentoo-dev 2014-05-05 10:29:12 UTC
Use CVE-2014-3207 has been assigned to this issue.
Comment 3 Yury German Gentoo Infrastructure gentoo-dev 2014-05-05 17:47:57 UTC
Thank you on the CVE.
Comment 4 Manuel Rüger (RETIRED) gentoo-dev 2014-05-05 22:05:14 UTC
*sks-1.1.5 (05 May 2014)

  05 May 2014; Manuel Rüger <mrueg@gentoo.org> +sks-1.1.5.ebuild,
  -files/bdb_stubs-gentoo.patch, -files/sks-1.1.4-ECC_OID_fix_x86.patch,
  -files/sks-1.1.4-man_url.patch, -sks-1.1.2.ebuild, -sks-1.1.4-r1.ebuild,
  -sks-1.1.4.ebuild:
  Version bump. Cleanup old. Proxy commit for Kristian Fiskerstrand. Fixes bug
  #509352 (CVE-2014-3207).

Recent version in tree. Cleaned up vulnerable ebuilds. No stable version.
Comment 5 Yury German Gentoo Infrastructure gentoo-dev 2014-05-06 00:07:44 UTC
Maintainer(s), Thank you for cleanup!

No GLSA needed as there are no stable versions.