Xymon Multiple XSS

Bug #1092412 reported by Christian Kuersteiner
258
This bug affects 1 person
Affects Status Importance Assigned to Milestone
xymon (Ubuntu)
Fix Released
Undecided
Axel Beckert
Lucid
Fix Released
Undecided
Unassigned
Oneiric
Fix Released
Undecided
Unassigned
Precise
Fix Released
Undecided
Unassigned

Bug Description

Multiple cross-site scripting (XSS) vulnerabilities in the Web UI in Xymon
before 4.3.1 allow remote attackers to inject arbitrary web script or HTML
via unspecified vectors.

information type: Private Security → Public Security
Axel Beckert (xtaran)
Changed in xymon (Ubuntu):
assignee: nobody → Axel Beckert (xtaran)
Revision history for this message
Axel Beckert (xtaran) wrote :

Fixed since version in Quantal.

Changed in xymon (Ubuntu):
status: New → Fix Released
Revision history for this message
Christian Kuersteiner (ckuerste) wrote :

This is a backported patch for precise. It's based on the changes made upstream (from 4.3.0 to 4.3.1). I hope I didn't miss anything. As well please check if the new versioning is right.

Changed in xymon (Ubuntu Precise):
status: New → Confirmed
Revision history for this message
Seth Arnold (seth-arnold) wrote :

Christian, thanks for the patch; it is very nearly there.

Please add DEP-3 tags to the 7-CVE-2011-1716.patch file to document the patch provenance. The guidelines are available at https://wiki.ubuntu.com/PackagingGuide/PatchSystems#Patch_Tagging_Guidelines .

The version number increase looked good to me.

Some of the patches in the series after 7-CVE-2011-1716.patch apply with fuzz; did they apply with fuzz before your patch? Was there a reason to apply this patch at the head of the series?

Please resubscribe ubuntu-security-sponsors and set the status to 'NEW' when the changes are complete.

Thank you

Changed in xymon (Ubuntu Precise):
status: Confirmed → Incomplete
assignee: nobody → Christian Kuersteiner (ckuerste)
tags: added: patch-needswork
Revision history for this message
Christian Kuersteiner (ckuerste) wrote :

Thanks for the review.

Yes some of the other patches apply with fuzz already before my patch added and there was no change in the behavior befor and after my patch.

There is no particular reason for adding my patch at the head of the series other than using 'quilt new xxxxx' which put it on top. I will move it down to the bugfix section.

Revision history for this message
Christian Kuersteiner (ckuerste) wrote :

This is the new patch with the changes according to the feedback.

Changed in xymon (Ubuntu Precise):
status: Incomplete → New
Revision history for this message
Seth Arnold (seth-arnold) wrote :

ACK'd, thanks for the update.

Changed in xymon (Ubuntu Precise):
status: New → Confirmed
assignee: Christian Kuersteiner (ckuerste) → nobody
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package xymon - 4.3.0~beta2.dfsg-9.1ubuntu0.1

---------------
xymon (4.3.0~beta2.dfsg-9.1ubuntu0.1) precise-security; urgency=low

  * SECURITY UPDATE: Multiple cross site scripting (XSS) vulnerabilities
    (LP: #1092412)
    - debian/patches/7-CVE-2011-1716.patch: show user input as html quoted
      output. Based on upstream changes.
    - CVE-2011-1716
 -- Christian Kuersteiner <email address hidden> Sun, 23 Dec 2012 14:08:54 +0700

Changed in xymon (Ubuntu Precise):
status: Confirmed → Fix Released
Revision history for this message
Seth Arnold (seth-arnold) wrote :

I made a few modifications to the debdiff:

- Changed paths in debdiff to apply
- Removed # from patch headers
- Split Author/Origin into two headers

Thanks again Christian

Changed in xymon (Ubuntu Precise):
status: Fix Released → Fix Committed
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package xymon - 4.3.0~beta2.dfsg-9.1ubuntu0.1

---------------
xymon (4.3.0~beta2.dfsg-9.1ubuntu0.1) precise-security; urgency=low

  * SECURITY UPDATE: Multiple cross site scripting (XSS) vulnerabilities
    (LP: #1092412)
    - debian/patches/7-CVE-2011-1716.patch: show user input as html quoted
      output. Based on upstream changes.
    - CVE-2011-1716
 -- Christian Kuersteiner <email address hidden> Sun, 23 Dec 2012 14:08:54 +0700

Changed in xymon (Ubuntu Precise):
status: Fix Committed → Fix Released
Revision history for this message
Christian Kuersteiner (ckuerste) wrote :

Oneiric patch

Revision history for this message
Christian Kuersteiner (ckuerste) wrote :

Lucid patch

Changed in xymon (Ubuntu Oneiric):
status: New → Confirmed
Changed in xymon (Ubuntu Lucid):
status: New → Confirmed
Revision history for this message
Marc Deslauriers (mdeslaur) wrote :

ACK on the debdiffs, thanks!

Changed in xymon (Ubuntu Lucid):
status: Confirmed → Fix Committed
Changed in xymon (Ubuntu Oneiric):
status: Confirmed → Fix Committed
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package xymon - 4.3.0~beta2.dfsg-5ubuntu0.1

---------------
xymon (4.3.0~beta2.dfsg-5ubuntu0.1) lucid-security; urgency=low

  * SECURITY UPDATE: Multiple cross site scripting (XSS) vulnerabilities
    (LP: #1092412)
    - debian/patches/9-CVE-2011-1716.patch: show user input as html quoted
      output. Based on upstream changes.
    - CVE-2011-1716
 -- Christian Kuersteiner <email address hidden> Tue, 15 Jan 2013 13:39:32 +0700

Changed in xymon (Ubuntu Lucid):
status: Fix Committed → Fix Released
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package xymon - 4.3.0~beta2.dfsg-9ubuntu1.1

---------------
xymon (4.3.0~beta2.dfsg-9ubuntu1.1) oneiric-security; urgency=low

  * SECURITY UPDATE: Multiple cross site scripting (XSS) vulnerabilities
    (LP: #1092412)
    - debian/patches/8-CVE-2011-1716.patch: show user input as html quoted
      output. Based on upstream changes.
    - CVE-2011-1716
 -- Christian Kuersteiner <email address hidden> Mon, 14 Jan 2013 14:01:38 +0700

Changed in xymon (Ubuntu Oneiric):
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.