hoteldruid: CVE-2019-8937

Related Vulnerabilities: CVE-2019-8937   CVE-2019-9084   CVE-2019-9085   CVE-2019-9086   CVE-2019-9087  

Debian Bug report logs - #929136
hoteldruid: CVE-2019-8937

version graph

Reported by: Salvatore Bonaccorso <carnil@debian.org>

Date: Fri, 17 May 2019 20:51:02 UTC

Severity: grave

Tags: security, upstream

Found in version hoteldruid/2.3.0-2

Fixed in version hoteldruid/2.3.2-1

Done: Salvatore Bonaccorso <carnil@debian.org>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, carnil@debian.org, team@security.debian.org, team@security.debian.org, Marco Maria Francesco De Santis <marco@digitaldruid.net>:
Bug#929136; Package src:hoteldruid. (Fri, 17 May 2019 20:51:04 GMT) (full text, mbox, link).


Acknowledgement sent to Salvatore Bonaccorso <carnil@debian.org>:
New Bug report received and forwarded. Copy sent to carnil@debian.org, team@security.debian.org, team@security.debian.org, Marco Maria Francesco De Santis <marco@digitaldruid.net>. (Fri, 17 May 2019 20:51:04 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Salvatore Bonaccorso <carnil@debian.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: hoteldruid: CVE-2019-8937
Date: Fri, 17 May 2019 22:49:21 +0200
Source: hoteldruid
Version: 2.3.2-1
Severity: grave
Tags: security upstream

Hi,

The following vulnerability was published for hoteldruid.

CVE-2019-8937[0]:
| HotelDruid 2.3.0 has XSS affecting the nsextt, cambia1, mese_fine,
| origine, and anno parameters in creaprezzi.php, tabella3.php,
| personalizza.php, and visualizza_tabelle.php.

Unless mistaken, then those are not yet fixed in the 2.3.2 upstream
which fixed CVE-2019-9084, CVE-2019-9085, CVE-2019-9086 and
CVE-2019-9087?

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2019-8937
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-8937
[1] https://www.exploit-db.com/exploits/46429/

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore



Information forwarded to debian-bugs-dist@lists.debian.org, Marco Maria Francesco De Santis <marco@digitaldruid.net>:
Bug#929136; Package src:hoteldruid. (Sat, 18 May 2019 13:39:02 GMT) (full text, mbox, link).


Acknowledgement sent to "Marco M. F. De Santis" <marco@digitaldruid.net>:
Extra info received and forwarded to list. Copy sent to Marco Maria Francesco De Santis <marco@digitaldruid.net>. (Sat, 18 May 2019 13:39:02 GMT) (full text, mbox, link).


Message #10 received at 929136@bugs.debian.org (full text, mbox, reply):

From: "Marco M. F. De Santis" <marco@digitaldruid.net>
To: Salvatore Bonaccorso <carnil@debian.org>, 929136@bugs.debian.org
Subject: Re: Bug#929136: hoteldruid: CVE-2019-8937
Date: Sat, 18 May 2019 15:21:46 +0200
Hello Salvatore,
CVE-2019-8937 is already fixed in hoteldruid 2.3.2 as a consequence of 
the other CVEs. This CVE had not been reported to me when 2.3.2 was 
released.

Regards,
Marco



Marked as found in versions hoteldruid/2.3.0-2. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Sat, 18 May 2019 14:03:02 GMT) (full text, mbox, link).


Information forwarded to debian-bugs-dist@lists.debian.org, Marco Maria Francesco De Santis <marco@digitaldruid.net>:
Bug#929136; Package src:hoteldruid. (Sat, 18 May 2019 14:06:02 GMT) (full text, mbox, link).


Acknowledgement sent to Salvatore Bonaccorso <carnil@debian.org>:
Extra info received and forwarded to list. Copy sent to Marco Maria Francesco De Santis <marco@digitaldruid.net>. (Sat, 18 May 2019 14:06:02 GMT) (full text, mbox, link).


Message #17 received at 929136@bugs.debian.org (full text, mbox, reply):

From: Salvatore Bonaccorso <carnil@debian.org>
To: "Marco M. F. De Santis" <marco@digitaldruid.net>
Cc: 929136@bugs.debian.org, 929136-done@bugs.debian.org
Subject: Re: Bug#929136: hoteldruid: CVE-2019-8937
Date: Sat, 18 May 2019 16:03:14 +0200
Source: hoteldruid
Source-Version: 2.3.2-1

Hi Marco,

On Sat, May 18, 2019 at 03:21:46PM +0200, Marco M. F. De Santis wrote:
> Hello Salvatore,
> CVE-2019-8937 is already fixed in hoteldruid 2.3.2 as a consequence of the
> other CVEs. This CVE had not been reported to me when 2.3.2 was released.

Thanks for your quick followup!

In this case I will update the security-tracker information to
correctly reflect this and close this bug with 2.3.2-1.

Regards,
Salvatore



Reply sent to Salvatore Bonaccorso <carnil@debian.org>:
You have taken responsibility. (Sat, 18 May 2019 14:06:04 GMT) (full text, mbox, link).


Notification sent to Salvatore Bonaccorso <carnil@debian.org>:
Bug acknowledged by developer. (Sat, 18 May 2019 14:06:05 GMT) (full text, mbox, link).


Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Sun, 16 Jun 2019 07:25:39 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 19:00:57 2019; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.