viewc: Cross-Site Scripting (XSS) vulnerability

Related Vulnerabilities: CVE-2017-5938  

Debian Bug report logs - #854681
viewc: Cross-Site Scripting (XSS) vulnerability

version graph

Package: viewvc; Maintainer for viewvc is Lev Lamberov <dogsleg@debian.org>; Source for viewvc is src:viewvc (PTS, buildd, popcon).

Reported by: Sebastien Delafond <seb@debian.org>

Date: Thu, 9 Feb 2017 13:36:02 UTC

Severity: important

Tags: security

Found in version viewvc/1.1.25+repack-1

Fixed in version viewvc/1.1.26-1

Done: Lev Lamberov <dogsleg@debian.org>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, unknown-package@qa.debian.org:
Bug#854681; Package viewc. (Thu, 09 Feb 2017 13:36:04 GMT) (full text, mbox, link).


Acknowledgement sent to Sebastien Delafond <seb@debian.org>:
New Bug report received and forwarded. Copy sent to unknown-package@qa.debian.org. (Thu, 09 Feb 2017 13:36:04 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Sebastien Delafond <seb@debian.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: viewc: Cross-Site Scripting (XSS) vulnerability
Date: Thu, 09 Feb 2017 14:32:39 +0100
Package: viewc
Severity: important
Tags: security
Control: found 1.1.25+repack-1
Control: notfound 1.1.26-1

XSS vulnerability, identified by CVE-2017-5938. See
https://github.com/viewvc/viewvc/commit/9dcfc7daa4c940992920d3b2fbd317da20e44aad.

-- System Information:
Debian Release: stretch/sid
  APT prefers unstable
  APT policy: (500, 'unstable'), (500, 'testing'), (500, 'stable'), (500, 'oldstable'), (1, 'experimental')
Architecture: amd64 (x86_64)
Foreign Architectures: i386, armel

Kernel: Linux 4.7.0-1-amd64 (SMP w/4 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/bash
Init: sysvinit (via /sbin/init)



Marked as found in versions 1.1.25+repack-1. Request was from Sebastien Delafond <seb@debian.org> to control@bugs.debian.org. (Thu, 09 Feb 2017 13:48:03 GMT) (full text, mbox, link).


Marked as fixed in versions 1.1.26-1. Request was from Sebastien Delafond <seb@debian.org> to control@bugs.debian.org. (Thu, 09 Feb 2017 13:48:05 GMT) (full text, mbox, link).


Information forwarded to debian-bugs-dist@lists.debian.org, unknown-package@qa.debian.org:
Bug#854681; Package viewc. (Thu, 09 Feb 2017 13:51:06 GMT) (full text, mbox, link).


Acknowledgement sent to Adrian Bunk <bunk@debian.org>:
Extra info received and forwarded to list. Copy sent to unknown-package@qa.debian.org. (Thu, 09 Feb 2017 13:51:07 GMT) (full text, mbox, link).


Message #14 received at 854681@bugs.debian.org (full text, mbox, reply):

From: Adrian Bunk <bunk@debian.org>
To: Sebastien Delafond <seb@debian.org>, 854681@bugs.debian.org
Cc: Lev Lamberov <dogsleg@debian.org>
Subject: Re: Bug#854681: viewc: Cross-Site Scripting (XSS) vulnerability
Date: Thu, 9 Feb 2017 15:46:44 +0200
Control: reassign -1 viewvc 1.1.25+repack-1
Control: fixed -1 1.1.26-1

- view*v*c
- fixed, not notfound

On Thu, Feb 09, 2017 at 02:32:39PM +0100, Sebastien Delafond wrote:
> Package: viewc
> Severity: important
> Tags: security
> Control: found 1.1.25+repack-1
> Control: notfound 1.1.26-1
> 
> XSS vulnerability, identified by CVE-2017-5938. See
> https://github.com/viewvc/viewvc/commit/9dcfc7daa4c940992920d3b2fbd317da20e44aad.
> 
> -- System Information:
> Debian Release: stretch/sid
>   APT prefers unstable
>   APT policy: (500, 'unstable'), (500, 'testing'), (500, 'stable'), (500, 'oldstable'), (1, 'experimental')
> Architecture: amd64 (x86_64)
> Foreign Architectures: i386, armel
> 
> Kernel: Linux 4.7.0-1-amd64 (SMP w/4 CPU cores)
> Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
> Shell: /bin/sh linked to /bin/bash
> Init: sysvinit (via /sbin/init)




Bug reassigned from package 'viewc' to 'viewvc'. Request was from Adrian Bunk <bunk@debian.org> to 854681-submit@bugs.debian.org. (Thu, 09 Feb 2017 13:51:07 GMT) (full text, mbox, link).


No longer marked as found in versions 1.1.25+repack-1. Request was from Adrian Bunk <bunk@debian.org> to 854681-submit@bugs.debian.org. (Thu, 09 Feb 2017 13:51:07 GMT) (full text, mbox, link).


No longer marked as fixed in versions 1.1.26-1. Request was from Adrian Bunk <bunk@debian.org> to 854681-submit@bugs.debian.org. (Thu, 09 Feb 2017 13:51:08 GMT) (full text, mbox, link).


Marked as found in versions viewvc/1.1.25+repack-1. Request was from Adrian Bunk <bunk@debian.org> to 854681-submit@bugs.debian.org. (Thu, 09 Feb 2017 13:51:08 GMT) (full text, mbox, link).


Marked as fixed in versions viewvc/1.1.26-1. Request was from Adrian Bunk <bunk@debian.org> to 854681-submit@bugs.debian.org. (Thu, 09 Feb 2017 13:51:09 GMT) (full text, mbox, link).


Reply sent to Lev Lamberov <dogsleg@debian.org>:
You have taken responsibility. (Wed, 13 Feb 2019 11:45:08 GMT) (full text, mbox, link).


Notification sent to Sebastien Delafond <seb@debian.org>:
Bug acknowledged by developer. (Wed, 13 Feb 2019 11:45:08 GMT) (full text, mbox, link).


Message #29 received at 854681-done@bugs.debian.org (full text, mbox, reply):

From: Lev Lamberov <dogsleg@debian.org>
To: 854681-done@bugs.debian.org
Date: Wed, 13 Feb 2019 16:42:28 +0500
Hi,

This bug was fixed in versions viewvc/1.1.22-1+deb8u1 and viewvc/1.1.26-1, the only versions
available in Debian.

Regards,
Lev Lamberov



Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Thu, 14 Mar 2019 07:27:54 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 18:33:54 2019; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.