Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <CUEJgQkFPWo3cH/SZsHQjAvasZk@C07ykyUPv6bSEDpjtBW7yGFRb24>
Date: Sun, 26 Aug 2012 23:32:00 +0400
From: Eygene Ryabinkin <rea-sec@...elabs.ru>
To: oss-security@...ts.openwall.com
Cc: Henri Salo <henri@...v.fi>, Moritz Muehlenhoff <jmm@...ian.org>
Subject: Re: CVE-request: Roundcube XSS issues

Mon, Aug 20, 2012 at 10:11:28AM -0600, Kurt Seifried wrote:
> On 08/20/2012 05:24 AM, Jan Lieskovsky wrote:
> > Upon code review, I don't think this issue affects 0.7.x versions, 
> > we ship in Fedora and EPEL (iilc the Larry skin was introduced
> > only in 0.8.x version and in 0.7.x version the related code looks 
> > different).

That's true: the issue is that the $hkey was used in the ternary
operator (copy'n'paste error) and $hkey wasn't initialized at the
point, so the condition will be false, thus the 'show' mode will be
used.  And this code appears only in 0.8-beta and 0.8-rc.  0.8.0 fixes
the issue and it doesn't exist in the 0.7.x, because there were no
processing for the 'valueof' attribute in rcmail_message_headers().

> > I don't have filed RH bug for this based on the above. 
> > Could you have a look and confirm this?
> 
> Please use CVE-2012-3507 for this issue.

At NVD I see that version specification is "prior to 0.8.0",
  http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-3507
though
  http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2012-3507
shows only a stub without details.  The proper version specification
will be "Roundcube from 0.8.x series prior to 0.8.0".
-- 
Eygene

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.