Bug 987149

Summary: WebCalendar: multiple flaws fixed in version 1.2.7
Product: [Other] Security Response Reporter: Vincent Danen <vdanen>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: patrick
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: WebCalendar 1.2.7 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2013-08-08 21:19:54 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 987152    
Bug Blocks:    

Description Vincent Danen 2013-07-22 20:01:03 UTC
The upstream releases notes for version 1.2.7 [1] indicate that if fixes several security-relevant bugs:

Version 1.2.7 (22 Jan 2013)
 - Security fix: Do not show the reason for a failed login (i.e. "no such user")
 - Security fix: Escape HTML characters in category name.
 - Security fix: Check all passed in fields (either via HTML form or via
   URL parameter) for certain malicious tags (script, embed, etc.) and
   generate fatal error if found.

Current versions of Fedora are shipping a vulnerable version and should be updated.

[1] http://sourceforge.net/projects/webcalendar/files/webcalendar%201.2/1.2.7/

Comment 1 Vincent Danen 2013-07-22 20:13:55 UTC
Created WebCalendar tracking bugs for this issue:

Affects: fedora-all [bug 987152]

Comment 2 Fedora Update System 2013-08-02 21:50:58 UTC
WebCalendar-1.2.7-1.fc19 has been pushed to the Fedora 19 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 3 Fedora Update System 2013-08-02 22:09:13 UTC
WebCalendar-1.2.7-1.fc18 has been pushed to the Fedora 18 stable repository.  If problems still persist, please make note of it in this bug report.