Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 737908 (CVE-2020-8226) - <www-apps/phpBB-3.3.1: SSRF Vulnerability (CVE-2020-8226)
Summary: <www-apps/phpBB-3.3.1: SSRF Vulnerability (CVE-2020-8226)
Status: RESOLVED FIXED
Alias: CVE-2020-8226
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: https://www.phpbb.com/community/viewt...
Whiteboard: ~4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2020-08-18 15:47 UTC by John Helmert III
Modified: 2020-08-24 00:26 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2020-08-18 15:47:41 UTC
CVE-2020-8226:

A vulnerability exists in phpBB <v3.2.10 and <v3.3.1 which allowed remote image dimensions check to be used to SSRF.


Versions <3.2.10 and <3.3.1 are vulnerable. Maintainers, please bump.
Comment 1 Larry the Git Cow gentoo-dev 2020-08-23 22:00:30 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=158312052d73276281ba9e49ddaf4c792fe25cd3

commit 158312052d73276281ba9e49ddaf4c792fe25cd3
Author:     James Le Cuirot <chewi@gentoo.org>
AuthorDate: 2020-08-23 21:59:47 +0000
Commit:     James Le Cuirot <chewi@gentoo.org>
CommitDate: 2020-08-23 21:59:47 +0000

    www-apps/phpBB: Drop old and vulnerable 3.2.8
    
    Bug: https://bugs.gentoo.org/717716
    Bug: https://bugs.gentoo.org/737908
    Package-Manager: Portage-3.0.4, Repoman-3.0.1
    Signed-off-by: James Le Cuirot <chewi@gentoo.org>

 www-apps/phpBB/Manifest           |  1 -
 www-apps/phpBB/phpBB-3.2.8.ebuild | 56 ---------------------------------------
 2 files changed, 57 deletions(-)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=88bb953e4c11c2cd8e895fb086f0b48629f3ce87

commit 88bb953e4c11c2cd8e895fb086f0b48629f3ce87
Author:     James Le Cuirot <chewi@gentoo.org>
AuthorDate: 2020-08-23 21:58:49 +0000
Commit:     James Le Cuirot <chewi@gentoo.org>
CommitDate: 2020-08-23 21:58:49 +0000

    www-apps/phpBB: Version bump to 3.3.1
    
    Bug: https://bugs.gentoo.org/717716
    Bug: https://bugs.gentoo.org/737908
    Package-Manager: Portage-3.0.4, Repoman-3.0.1
    Signed-off-by: James Le Cuirot <chewi@gentoo.org>

 www-apps/phpBB/Manifest           |  1 +
 www-apps/phpBB/phpBB-3.3.1.ebuild | 57 +++++++++++++++++++++++++++++++++++++++
 2 files changed, 58 insertions(+)
Comment 2 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2020-08-24 00:26:20 UTC
Tree is clean. No GLSA. All done.