Gentoo Archives: gentoo-announce

From: Pierre-Yves Rofes <py@g.o>
To: gentoo-announce@l.g.o
Cc: full-disclosure@××××××××××××××.uk, bugtraq@×××××××××××××.com, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200711-05 ] SiteBar: Multiple issues
Date: Tue, 06 Nov 2007 23:10:17
Message-Id: 4730F024.4090002@gentoo.org
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
5 Gentoo Linux Security Advisory GLSA 200711-05
6 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
7 http://security.gentoo.org/
8 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
9
10 Severity: High
11 Title: SiteBar: Multiple issues
12 Date: November 06, 2007
13 Bugs: #195810
14 ID: 200711-05
15
16 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
17
18 Synopsis
19 ========
20
21 Multiple issues have been identified in SiteBar that might allow
22 execution of arbitrary code and arbitrary file disclosure.
23
24 Background
25 ==========
26
27 SiteBar is a PHP application that allows users to store their bookmarks
28 on a web server.
29
30 Affected packages
31 =================
32
33 -------------------------------------------------------------------
34 Package / Vulnerable / Unaffected
35 -------------------------------------------------------------------
36 1 www-apps/sitebar < 3.3.9 >= 3.3.9
37
38 Description
39 ===========
40
41 Tim Brown discovered these multiple issues: the translation module does
42 not properly sanitize the value to the "dir" parameter (CVE-2007-5491,
43 CVE-2007-5694); the translation module also does not sanitize the
44 values of the "edit" and "value" parameters which it passes to eval()
45 and include() (CVE-2007-5492, CVE-2007-5693); the log-in command does
46 not validate the URL to redirect users to after logging in
47 (CVE-2007-5695); SiteBar also contains several cross-site scripting
48 vulnerabilities (CVE-2007-5692).
49
50 Impact
51 ======
52
53 An authenticated attacker in the "Translators" or "Admins" group could
54 execute arbitrary code, read arbitrary files and possibly change their
55 permissions with the privileges of the user running the web server by
56 passing a specially crafted parameter string to the "translator.php"
57 file. An unauthenticated attacker could entice a user to browse a
58 specially crafted URL, allowing for the execution of script code in the
59 context of the user's browser, for the theft of browser credentials or
60 for a redirection to an arbitrary web site after login.
61
62 Workaround
63 ==========
64
65 There is no known workaround at this time.
66
67 Resolution
68 ==========
69
70 All SiteBar users should upgrade to the latest version:
71
72 # emerge --sync
73 # emerge --ask --oneshot --verbose ">=www-apps/sitebar-3.3.9"
74
75 References
76 ==========
77
78 [ 1 ] CVE-2007-5491
79 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5491
80 [ 2 ] CVE-2007-5492
81 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5492
82 [ 3 ] CVE-2007-5692
83 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5692
84 [ 4 ] CVE-2007-5693
85 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5693
86 [ 5 ] CVE-2007-5694
87 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5694
88 [ 6 ] CVE-2007-5695
89 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5695
90
91 Availability
92 ============
93
94 This GLSA and any updates to it are available for viewing at
95 the Gentoo Security Website:
96
97 http://security.gentoo.org/glsa/glsa-200711-05.xml
98
99 Concerns?
100 =========
101
102 Security is a primary focus of Gentoo Linux and ensuring the
103 confidentiality and security of our users machines is of utmost
104 importance to us. Any security concerns should be addressed to
105 security@g.o or alternatively, you may file a bug at
106 http://bugs.gentoo.org.
107
108 License
109 =======
110
111 Copyright 2007 Gentoo Foundation, Inc; referenced text
112 belongs to its owner(s).
113
114 The contents of this document are licensed under the
115 Creative Commons - Attribution / Share Alike license.
116
117 http://creativecommons.org/licenses/by-sa/2.5
118 -----BEGIN PGP SIGNATURE-----
119 Version: GnuPG v1.4.7 (GNU/Linux)
120 Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org
121
122 iD8DBQFHMPAkuhJ+ozIKI5gRAvKjAKCiMhRJqgEJquBfFZPwj4DoroF3awCfW9cO
123 2q2WsvEZzXcBRSQbH05oKbA=
124 =OTlc
125 -----END PGP SIGNATURE-----
126 --
127 gentoo-announce@g.o mailing list