Gentoo Archives: gentoo-announce

From: Sune Kloppenborg Jeppesen <jaervosz@g.o>
To: gentoo-announce@l.g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××××.uk, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200606-28 ] Horde Web Application Framework: XSS vulnerability
Date: Thu, 29 Jun 2006 05:19:10
Message-Id: 200606290645.09937.jaervosz@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200606-28
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Low
8 Title: Horde Web Application Framework: XSS vulnerability
9 Date: June 29, 2006
10 Bugs: #136830
11 ID: 200606-28
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 The Horde Web Application Framework is vulnerable to a cross-site
19 scripting vulnerability.
20
21 Background
22 ==========
23
24 The Horde Web Application Framework is a general-purpose web
25 application framework written in PHP, providing classes for handling
26 preferences, compression, browser detection, connection tracking, MIME,
27 and more.
28
29 Affected packages
30 =================
31
32 -------------------------------------------------------------------
33 Package / Vulnerable / Unaffected
34 -------------------------------------------------------------------
35 1 www-apps/horde < 3.1.1-r1 >= 3.1.1-r1
36
37 Description
38 ===========
39
40 Michael Marek discovered that the Horde Web Application Framework
41 performs insufficient input sanitizing.
42
43 Impact
44 ======
45
46 An attacker could exploit these vulnerabilities to execute arbitrary
47 scripts running in the context of the victim's browser.
48
49 Workaround
50 ==========
51
52 There is no known workaround at this time.
53
54 Resolution
55 ==========
56
57 All horde users should upgrade to the latest version:
58
59 # emerge --sync
60 # emerge --ask --oneshot --verbose ">=www-apps/horde-3.1.1-r1"
61
62 References
63 ==========
64
65 [ 1 ] CVE-2006-2195
66 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2195
67
68 Availability
69 ============
70
71 This GLSA and any updates to it are available for viewing at
72 the Gentoo Security Website:
73
74 http://security.gentoo.org/glsa/glsa-200606-28.xml
75
76 Concerns?
77 =========
78
79 Security is a primary focus of Gentoo Linux and ensuring the
80 confidentiality and security of our users machines is of utmost
81 importance to us. Any security concerns should be addressed to
82 security@g.o or alternatively, you may file a bug at
83 http://bugs.gentoo.org.
84
85 License
86 =======
87
88 Copyright 2006 Gentoo Foundation, Inc; referenced text
89 belongs to its owner(s).
90
91 The contents of this document are licensed under the
92 Creative Commons - Attribution / Share Alike license.
93
94 http://creativecommons.org/licenses/by-sa/2.5