Gentoo Archives: gentoo-announce

From: Luke Macken <lewk@g.o>
To: gentoo-announce@l.g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××××.uk, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200505-01 ] Horde Framework: Multiple XSS vulnerabilities
Date: Sun, 01 May 2005 16:10:19
Message-Id: 20050501161012.GA10060@tomservo.hsd1.ma.comcast.net
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200505-01
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Low
8 Title: Horde Framework: Multiple XSS vulnerabilities
9 Date: May 01, 2005
10 Bugs: #90365
11 ID: 200505-01
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Various modules of the Horde Framework are vulnerable to multiple
19 cross-site scripting (XSS) vulnerabilities.
20
21 Background
22 ==========
23
24 The Horde Framework is a PHP based framework for building web
25 applications. It provides many modules including calendar, address
26 book, CVS viewer and Internet Messaging Program.
27
28 Affected packages
29 =================
30
31 -------------------------------------------------------------------
32 Package / Vulnerable / Unaffected
33 -------------------------------------------------------------------
34 1 www-apps/horde-vacation < 2.2.2 >= 2.2.2
35 2 www-apps/horde-turba < 1.2.5 >= 1.2.5
36 3 www-apps/horde-passwd < 2.2.2 >= 2.2.2
37 4 www-apps/horde-nag < 1.1.3 >= 1.1.3
38 5 www-apps/horde-mnemo < 1.1.4 >= 1.1.4
39 6 www-apps/horde-kronolith < 1.1.4 >= 1.1.4
40 7 www-apps/horde-imp < 3.2.8 >= 3.2.8
41 8 www-apps/horde-accounts < 2.1.2 >= 2.1.2
42 9 www-apps/horde-forwards < 2.2.2 >= 2.2.2
43 10 www-apps/horde-chora < 1.2.3 >= 1.2.3
44 11 www-apps/horde < 2.2.8 >= 2.2.8
45 -------------------------------------------------------------------
46 11 affected packages on all of their supported architectures.
47 -------------------------------------------------------------------
48
49 Description
50 ===========
51
52 Cross-site scripting vulnerabilities have been discovered in various
53 modules of the Horde Framework.
54
55 Impact
56 ======
57
58 These vulnerabilities could be exploited by an attacker to execute
59 arbitrary HTML and script code in context of the victim's browser.
60
61 Workaround
62 ==========
63
64 There is no known workaround at this time.
65
66 Resolution
67 ==========
68
69 All Horde users should upgrade to the latest version:
70
71 # emerge --sync
72 # emerge --ask --oneshot --verbose ">=www-apps/horde-2.2.8"
73
74 All Horde Vacation users should upgrade to the latest version:
75
76 # emerge --sync
77 # emerge --ask --oneshot --verbose ">=www-apps/horde-vacation-2.2.2"
78
79 All Horde Turba users should upgrade to the latest version:
80
81 # emerge --sync
82 # emerge --ask --oneshot --verbose ">=www-apps/horde-turba-1.2.5"
83
84 All Horde Passwd users should upgrade to the latest version:
85
86 # emerge --sync
87 # emerge --ask --oneshot --verbose ">=www-apps/horde-passwd-2.2.2"
88
89 All Horde Nag users should upgrade to the latest version:
90
91 # emerge --sync
92 # emerge --ask --oneshot --verbose ">=www-apps/horde-nag-1.1.3"
93
94 All Horde Mnemo users should upgrade to the latest version:
95
96 # emerge --sync
97 # emerge --ask --oneshot --verbose ">=www-apps/horde-mnemo-1.1.4"
98
99 All Horde Kronolith users should upgrade to the latest version:
100
101 # emerge --sync
102 # emerge --ask --oneshot --verbose
103 # ">=www-apps/horde-kronolith-1.1.4"
104
105 All Horde IMP users should upgrade to the latest version:
106
107 # emerge --sync
108 # emerge --ask --oneshot --verbose ">=www-apps/horde-imp-3.2.8"
109
110 All Horde Accounts users should upgrade to the latest version:
111
112 # emerge --sync
113 # emerge --ask --oneshot --verbose ">=www-apps/horde-accounts-2.1.2"
114
115 All Horde Forwards users should upgrade to the latest version:
116
117 # emerge --sync
118 # emerge --ask --oneshot --verbose ">=www-apps/horde-forwards-2.2.2"
119
120 All Horde Chora users should upgrade to the latest version:
121
122 # emerge --sync
123 # emerge --ask --oneshot --verbose ">=www-apps/horde-chora-1.2.3"
124
125 References
126 ==========
127
128 [ 1 ] Horde Announcement
129 http://marc.theaimsgroup.com/?l=horde-announce&r=1&b=200504&w=2
130
131 Availability
132 ============
133
134 This GLSA and any updates to it are available for viewing at
135 the Gentoo Security Website:
136
137 http://security.gentoo.org/glsa/glsa-200505-01.xml
138
139 Concerns?
140 =========
141
142 Security is a primary focus of Gentoo Linux and ensuring the
143 confidentiality and security of our users machines is of utmost
144 importance to us. Any security concerns should be addressed to
145 security@g.o or alternatively, you may file a bug at
146 http://bugs.gentoo.org.
147
148 License
149 =======
150
151 Copyright 2005 Gentoo Foundation, Inc; referenced text
152 belongs to its owner(s).
153
154 The contents of this document are licensed under the
155 Creative Commons - Attribution / Share Alike license.
156
157 http://creativecommons.org/licenses/by-sa/2.0