roundup: CVE-2019-10904

Related Vulnerabilities: CVE-2019-10904  

Debian Bug report logs - #926587
roundup: CVE-2019-10904

version graph

Package: roundup; Maintainer for roundup is Kai Storbeck <kai@xs4all.nl>; Source for roundup is src:roundup (PTS, buildd, popcon).

Reported by: "Chris Lamb" <lamby@debian.org>

Date: Sun, 7 Apr 2019 12:03:02 UTC

Severity: grave

Tags: security

Found in version roundup/1.4.20-1.1+deb8u1

Fixed in version 1.4.20-1.1+deb8u2

Done: "Chris Lamb" <lamby@debian.org>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, team@security.debian.org, Kai Storbeck <kai@xs4all.nl>:
Bug#926587; Package roundup. (Sun, 07 Apr 2019 12:03:04 GMT) (full text, mbox, link).


Acknowledgement sent to "Chris Lamb" <lamby@debian.org>:
New Bug report received and forwarded. Copy sent to team@security.debian.org, Kai Storbeck <kai@xs4all.nl>. (Sun, 07 Apr 2019 12:03:04 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: "Chris Lamb" <lamby@debian.org>
To: submit@bugs.debian.org
Subject: roundup: CVE-2019-10904
Date: Sun, 07 Apr 2019 07:58:19 -0400
Package: roundup
Version: 1.4.20-1.1+deb8u1
X-Debbugs-CC: team@security.debian.org
Severity: grave
Tags: security

Hi,

The following vulnerability was published for roundup.

CVE-2019-10904[0]:
| Roundup 1.6 allows XSS via the URI because frontends/roundup.cgi and
| roundup/cgi/wsgi_handler.py mishandle 404 errors.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2019-10904
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10904


Regards,

-- 
      ,''`.
     : :'  :     Chris Lamb
     `. `'`      lamby@debian.org / chris-lamb.co.uk
       `-



Reply sent to "Chris Lamb" <lamby@debian.org>:
You have taken responsibility. (Sun, 07 Apr 2019 12:06:06 GMT) (full text, mbox, link).


Notification sent to "Chris Lamb" <lamby@debian.org>:
Bug acknowledged by developer. (Sun, 07 Apr 2019 12:06:06 GMT) (full text, mbox, link).


Message #10 received at 926587-done@bugs.debian.org (full text, mbox, reply):

From: "Chris Lamb" <lamby@debian.org>
To: 926587-done@bugs.debian.org
Subject: Re: Bug#926587: Acknowledgement (roundup: CVE-2019-10904)
Date: Sun, 07 Apr 2019 08:04:14 -0400
The Debian Bug Tracking System wrote:

> Thank you for filing a new Bug report with Debian.

… aaaand I've just noticed that src:roundup was removed since jessie, so
closing this bug.


Regards,

-- 
      ,''`.
     : :'  :     Chris Lamb
     `. `'`      lamby@debian.org 🍥 chris-lamb.co.uk
       `-



Marked as fixed in versions 1.4.20-1.1+deb8u2. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Sun, 07 Apr 2019 13:30:06 GMT) (full text, mbox, link).


Message sent on to "Chris Lamb" <lamby@debian.org>:
Bug#926587. (Sun, 07 Apr 2019 13:30:09 GMT) (full text, mbox, link).


Message #15 received at 926587-submitter@bugs.debian.org (full text, mbox, reply):

From: Salvatore Bonaccorso <carnil@debian.org>
To: control@bugs.debian.org
Cc: 926587-submitter@bugs.debian.org
Subject: closing 926587
Date: Sun, 07 Apr 2019 15:27:39 +0200
close 926587 1.4.20-1.1+deb8u2
thanks




Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Mon, 06 May 2019 07:28:37 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 18:25:23 2019; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.