Bug 1059001 - CVE-2014-1691 horde: unserializing certain form input leads to code execution [fedora-all]
Summary: CVE-2014-1691 horde: unserializing certain form input leads to code execution...
Keywords:
Status: CLOSED WONTFIX
Alias: None
Product: Fedora
Classification: Fedora
Component: horde
Version: 20
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Jason Tibbitts
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: fst_owner=Sparks
Depends On:
Blocks: CVE-2014-1691
TreeView+ depends on / blocked
 
Reported: 2014-01-28 23:58 UTC by Murray McAllister
Modified: 2015-04-02 19:01 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2015-04-02 19:01:48 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Murray McAllister 2014-01-28 23:58:23 UTC
This is an automatically created tracking bug!  It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.

For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.

For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs

When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s).  This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.

Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.

Please note: this issue affects multiple supported versions of Fedora.
Only one tracking bug has been filed; please ensure that it is only closed
when all affected versions are fixed.

[bug automatically created by: add-tracking-bugs]

Comment 1 Murray McAllister 2014-01-28 23:58:35 UTC
Please use the following update submission link to create the Bodhi
request for this issue as it contains the top-level parent bug(s) as well
as this tracking bug.  This will ensure that all associated bugs get
updated when new packages are pushed to stable.

Please also ensure that the "Close bugs when update is stable" option
remains checked.

Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=1059000,1059001

Comment 2 Eric Christensen 2014-08-18 20:37:56 UTC
What's happening with this package?  I believe it's been broken up into other packages and this package is just here for compatibility.  Is it possible to upgrade this?

Comment 3 Fedora Admin XMLRPC Client 2014-08-21 16:47:02 UTC
This package has changed ownership in the Fedora Package Database.  Reassigning to the new owner of this component.

Comment 4 Jason Tibbitts 2014-08-21 16:49:02 UTC
Somehow I ended up owning this package; I was helping out ages ago but I guess everyone else left and I ended up holding the bag.  I really have no interest in this and I've removed myself in pkgdb.

What happened to the horde suite is that upstream completely revamped their distribution methods which allows Fedora to ship and update all of the (100+) components separately.  However, Fedora policies preclude upgrading existing releases so F19 and F20 are stuck with the old code that nobody wants to touch.  I'm not really sure what the best course of action would be.

Comment 5 Eric Christensen 2014-10-27 14:13:36 UTC
...and with no way to tell who actually has this installed there is no way of knowing how many systems are affected.

I'm guessing this is an orphaned package now?

Comment 6 Eric Christensen 2014-11-20 21:20:19 UTC
Package has been retired.  Leaving bug open for anyone that may un-retire the package.

Comment 8 Jason Tibbitts 2015-04-02 17:30:57 UTC
Hmm, how did I get assigned here?  This package should be retired completely.  Horde was a mess in old Fedora; I was doing a bit of helping out but somehow I ended up owning the thing when everyone else dropped the package before I did.  I'm certainly not competent to fix bugs in very old unsupported PHP code.

In F20, the php-horde-horde package (which I do not and never have maintained) provides horde = 5.2.4, but it also conflicts with horde < 5 so I've no real idea what happens.  I believe if you installed (instead of updating) horde after the new version was released, you have the new version and otherwise you still have the old version.  An automatic upgrade isn't possible in any case, but of course they can uninstall and reinstall.  That's all based on my limited understanding of yum would do in that situation.

In any case, even though this was assigned to me, there's nothing I can do here.  Horde can't be brought back and at least there is a way to get it upgraded using only what's in the distro.

Comment 9 Eric Christensen 2015-04-02 18:18:31 UTC
(In reply to Jason Tibbitts from comment #8)
> Hmm, how did I get assigned here?  This package should be retired
> completely.  Horde was a mess in old Fedora; I was doing a bit of helping
> out but somehow I ended up owning the thing when everyone else dropped the
> package before I did.  I'm certainly not competent to fix bugs in very old
> unsupported PHP code.

Ha!  BZ certainly thinks you're the right person [to assign this bug to].  :)

> In any case, even though this was assigned to me, there's nothing I can do
> here.  Horde can't be brought back and at least there is a way to get it
> upgraded using only what's in the distro.

I haven't looked to see if horde is in F21 or beyond (it is in F20).  Can this package be retired if there is no maintenance happening?

Comment 10 Jason Tibbitts 2015-04-02 18:49:01 UTC
Horde in f21 is a virtual provide from php-horde-horde package; the old monolithic horde package was not branched for F21 or later and is dead.package'd in rawhide.

Horde certainly appears to be retired in f20, at least in pkgdb, but I was just in there clicking buttons today so it might not have have been that way until recently.

https://admin.fedoraproject.org/pkgdb/package/horde/

Not sure what else I can do now except either close this or wait for the EOL process to close it.

Comment 11 Eric Christensen 2015-04-02 19:01:48 UTC
Okay, yeah it appears to be retired.  For some reason yum was still able to trudge up some information about it.

Thanks!


Note You need to log in before you can comment on or make changes to this bug.