Bug 452539 (CVE-2008-3330) - CVE-2008-3330 horde: XSS in the item names in the object browser
Summary: CVE-2008-3330 horde: XSS in the item names in the object browser
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: CVE-2008-3330
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2008-06-23 17:04 UTC by Tomas Hoger
Modified: 2019-09-29 12:25 UTC (History)
2 users (show)

Fixed In Version: horde-3.2.1-1.fc9
Clone Of:
Environment:
Last Closed: 2008-06-29 08:53:41 UTC
Embargoed:


Attachments (Terms of Use)

Description Tomas Hoger 2008-06-23 17:04:21 UTC
New horde upstream versions 3.1.8 and 3.2.1 were released to address XSS issue
in the object browser.

Note in upstream changelog:
  SECURITY: Escape item names in the object browser (Bug #6906).

Upstream bug report referenced by changelog message:
  http://bugs.horde.org/ticket/6906

Upstream patch:
http://cvs.horde.org/diff.php/horde/services/obrowser/index.php?r1=1.18&r2=1.19

3.1.8 announcement:
http://lists.horde.org/archives/announce/2008/000415.html
http://cvs.horde.org/diff.php/horde/docs/CHANGES?r1=1.515.2.312.2.5&r2=1.515.2.312.2.10&ty=h

3.2.1 announcement:
http://lists.horde.org/archives/announce/2008/000416.html
http://cvs.horde.org/diff.php/horde/docs/CHANGES?r1=1.515.2.392&r2=1.515.2.413&ty=h

Other references:
http://secunia.com/advisories/30697/

Rawhide already has 3.2.1 (horde-3.2.1-1.fc10), so only F8 and F9 to deal with.

Comment 1 Fedora Update System 2008-06-24 04:26:53 UTC
horde-3.2.1-1.fc8 has been submitted as an update for Fedora 8

Comment 2 Fedora Update System 2008-06-24 04:27:05 UTC
horde-3.2.1-1.fc9 has been submitted as an update for Fedora 9

Comment 3 Nigel Jones 2008-06-24 04:33:54 UTC
(In reply to comment #0)
> Rawhide already has 3.2.1 (horde-3.2.1-1.fc10), so only F8 and F9 to deal with.

Thanks, my plan was to actually wait a couple of days and then push it, it's now
done.

Also EPEL-5 now has an updated version (3.2.1).

Comment 4 Fedora Update System 2008-06-25 02:53:56 UTC
horde-3.2.1-1.fc9 has been pushed to the Fedora 9 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 5 Fedora Update System 2008-06-25 02:54:28 UTC
horde-3.2.1-1.fc8 has been pushed to the Fedora 8 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 6 Nigel Jones 2008-06-29 08:53:41 UTC
The updates system did not close this when it should have, closing.

Comment 7 Tomas Hoger 2008-07-28 08:42:28 UTC
CVE-2008-3330:
Cross-site scripting (XSS) vulnerability in
services/obrowser/index.php in Horde 3.2 and Turba 2.2 allows remote
attackers to inject arbitrary web script or HTML via the contact name.


Note You need to log in before you can comment on or make changes to this bug.