Bug 452539 - (CVE-2008-3330) CVE-2008-3330 horde: XSS in the item names in the object browser
CVE-2008-3330 horde: XSS in the item names in the object browser
Status: CLOSED CURRENTRELEASE
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
source=gentoo,impact=moderate,reporte...
: Security
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2008-06-23 13:04 EDT by Tomas Hoger
Modified: 2016-03-04 06:17 EST (History)
2 users (show)

See Also:
Fixed In Version: horde-3.2.1-1.fc9
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2008-06-29 04:53:41 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Tomas Hoger 2008-06-23 13:04:21 EDT
New horde upstream versions 3.1.8 and 3.2.1 were released to address XSS issue
in the object browser.

Note in upstream changelog:
  SECURITY: Escape item names in the object browser (Bug #6906).

Upstream bug report referenced by changelog message:
  http://bugs.horde.org/ticket/6906

Upstream patch:
http://cvs.horde.org/diff.php/horde/services/obrowser/index.php?r1=1.18&r2=1.19

3.1.8 announcement:
http://lists.horde.org/archives/announce/2008/000415.html
http://cvs.horde.org/diff.php/horde/docs/CHANGES?r1=1.515.2.312.2.5&r2=1.515.2.312.2.10&ty=h

3.2.1 announcement:
http://lists.horde.org/archives/announce/2008/000416.html
http://cvs.horde.org/diff.php/horde/docs/CHANGES?r1=1.515.2.392&r2=1.515.2.413&ty=h

Other references:
http://secunia.com/advisories/30697/

Rawhide already has 3.2.1 (horde-3.2.1-1.fc10), so only F8 and F9 to deal with.
Comment 1 Fedora Update System 2008-06-24 00:26:53 EDT
horde-3.2.1-1.fc8 has been submitted as an update for Fedora 8
Comment 2 Fedora Update System 2008-06-24 00:27:05 EDT
horde-3.2.1-1.fc9 has been submitted as an update for Fedora 9
Comment 3 Nigel Jones 2008-06-24 00:33:54 EDT
(In reply to comment #0)
> Rawhide already has 3.2.1 (horde-3.2.1-1.fc10), so only F8 and F9 to deal with.

Thanks, my plan was to actually wait a couple of days and then push it, it's now
done.

Also EPEL-5 now has an updated version (3.2.1).
Comment 4 Fedora Update System 2008-06-24 22:53:56 EDT
horde-3.2.1-1.fc9 has been pushed to the Fedora 9 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 5 Fedora Update System 2008-06-24 22:54:28 EDT
horde-3.2.1-1.fc8 has been pushed to the Fedora 8 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 6 Nigel Jones 2008-06-29 04:53:41 EDT
The updates system did not close this when it should have, closing.
Comment 7 Tomas Hoger 2008-07-28 04:42:28 EDT
CVE-2008-3330:
Cross-site scripting (XSS) vulnerability in
services/obrowser/index.php in Horde 3.2 and Turba 2.2 allows remote
attackers to inject arbitrary web script or HTML via the contact name.

Note You need to log in before you can comment on or make changes to this bug.