Red Hat Bugzilla – Bug 144127
CAN-2005-0085 XSS vulnerability in htdig 3.2.0b6 on FC3
Last modified: 2015-03-04 20:14:36 EST
Description of problem:
HTML metacharacters included in the config= parameter to htsearch are
displayed unmodified in the error message returned by htdig.
Version-Release number of selected component (if applicable):
Steps to Reproduce:
you get an alertbox that says "foo" in it.
You shouldn't get an alert box.
This error was reported to firstname.lastname@example.org by email@example.com
The actual package revision (left that out on the initial report --
I've also reproduced this on a Fedora Core 1 box with:
This issue should also affect FC2.
Hi Dave; this bug is currently marked as embargoed. We'd like to
share the details with other vendor security teams that may ship
htdig. Have you contacted anyone else about this issue?
Mark: Dave didn't actually discover the issue - firstname.lastname@example.org did. He
recently made about 44 XSS vulnerabilities (including one in Bugzilla)
public at the same time; I don't know if this was among them, or
whether it was a later discovery.
Thanks Gervase; we've spoken to Michael yesterday and he has not yet
disclosed this particular issue, believing it due to site
configuration. We've confirmed that it isn't a template flaw and have
started talking to other vendor security teams to co-ordinate a fix.
Removing embargo - This issue was leaked public early by SUSE.
apologies for not replying sooner, I'm not getting bugmail from
Bugzilla for some reason. I didn't report it anywhere upstream
because I didn't have any non-redhat machines to test it on to verify
it wasn't just a redhat issue. Looks like you've already figured out
that wasn't the case though.
Packages have been built, waiting for signing and push.
Read ya, Phil
Packages signed and pushed, annoucenment email sent.
Read ya, Phil