Gentoo Archives: gentoo-announce

From: Sune Kloppenborg Jeppesen <jaervosz@g.o>
To: gentoo-announce@l.g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××××.uk, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200511-05 ] GNUMP3d: Directory traversal and XSS vulnerabilities
Date: Sun, 06 Nov 2005 16:44:34
Message-Id: 200511061720.18300.jaervosz@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200511-05
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: GNUMP3d: Directory traversal and XSS vulnerabilities
9 Date: November 06, 2005
10 Bugs: #109667
11 ID: 200511-05
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 GNUMP3d is vulnerable to directory traversal and cross-site scripting
19 attacks that may result in information disclosure or the compromise of
20 a browser.
21
22 Background
23 ==========
24
25 GNUMP3d is a streaming server for MP3s, OGG vorbis files, movies and
26 other media formats.
27
28 Affected packages
29 =================
30
31 -------------------------------------------------------------------
32 Package / Vulnerable / Unaffected
33 -------------------------------------------------------------------
34 1 media-sound/gnump3d < 2.9.7 >= 2.9.7
35
36 Description
37 ===========
38
39 Steve Kemp reported about two cross-site scripting attacks that are
40 related to the handling of files (CVE-2005-3424, CVE-2005-3425). Also
41 reported is a directory traversal vulnerability which comes from the
42 attempt to sanitize input paths (CVE-2005-3123).
43
44 Impact
45 ======
46
47 A remote attacker could exploit this to disclose sensitive information
48 or inject and execute malicious script code, potentially compromising
49 the victim's browser.
50
51 Workaround
52 ==========
53
54 There is no known workaround at this time.
55
56 Resolution
57 ==========
58
59 All GNUMP3d users should upgrade to the latest version:
60
61 # emerge --sync
62 # emerge --ask --oneshot --verbose ">=media-sound/gnump3d-2.9.7"
63
64 References
65 ==========
66
67 [ 1 ] CVE-2005-3123
68 http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3123
69 [ 2 ] CVE-2005-3424
70 http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3424
71 [ 3 ] CVE-2005-3425
72 http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3425
73
74 Availability
75 ============
76
77 This GLSA and any updates to it are available for viewing at
78 the Gentoo Security Website:
79
80 http://security.gentoo.org/glsa/glsa-200511-05.xml
81
82 Concerns?
83 =========
84
85 Security is a primary focus of Gentoo Linux and ensuring the
86 confidentiality and security of our users machines is of utmost
87 importance to us. Any security concerns should be addressed to
88 security@g.o or alternatively, you may file a bug at
89 http://bugs.gentoo.org.
90
91 License
92 =======
93
94 Copyright 2005 Gentoo Foundation, Inc; referenced text
95 belongs to its owner(s).
96
97 The contents of this document are licensed under the
98 Creative Commons - Attribution / Share Alike license.
99
100 http://creativecommons.org/licenses/by-sa/2.0