bugtraq
[Top] [All Lists]

Re: [Full-disclosure] ViewCVS 0.9.4 issues

Subject: Re: [Full-disclosure] ViewCVS 0.9.4 issues
From: Moritz Naumann <security@moritz-naumann.com>
Date: Tue, 27 Feb 2007 02:44:53 +0100
Cc: Full Disclosure <full-disclosure@lists.grok.org.uk>, bugtraq@securityfocus.com, moderators@osvdb.org, security@debian.org, security@gentoo.org, dev@viewvc.tigris.org, users@viewvc.tigris.org
Delivered-to: sp-com-lists@consult.net
Delivered-to: bugtraq-list@securepoint.com
Delivered-to: mailing list bugtraq@securityfocus.com
Delivered-to: moderator for bugtraq@securityfocus.com
In-reply-to: <45E351E5.3000806@moritz-naumann.com>
List-help: <mailto:bugtraq-help@securityfocus.com>
List-id: <bugtraq.list-id.securityfocus.com>
List-post: <mailto:bugtraq@securityfocus.com>
List-subscribe: <mailto:bugtraq-subscribe@securityfocus.com>
List-unsubscribe: <mailto:bugtraq-unsubscribe@securityfocus.com>
Mailing-list: contact bugtraq-help@securityfocus.com; run by ezmlm
Openpgp: id=277F060C; url=http://moritz-naumann.com/keys/0x277F060C.asc
Organization: Moritz Naumann IT Consulting & Services
References: <45E351E5.3000806@moritz-naumann.com>
User-agent: Mozilla/5.0 (X11; U; Linux) Thunderbird
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Moritz Naumann wrote:
> This was previously considered a HTTP response splitting vulnerability
> by Jose Antonio Coret (Joxean Koret)
> http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030514.html
> (BID 12112, couldn't find a CVE, AFAICT it is _not_ CAN-2004-1062)
> and, according to him, a patch has been stored on the 1.0-dev CVS
> branch. The 0.9.4 release on viewvc.tigris.org seems to be unpatched and
> it's possible that some Linux distributions and whoever would normally
> care were never patched against this.

I was wrong when I assumed that the 0.9.4 release on viewvc.tigris.org
was unpatched against the issues discovered by Jose Antonio Coret
(Joxean Koret). This issue was actually fixed by the ViewCVS developers
in version 0.9.3. I am sorry for the misconception and the confusion
this has caused.

This does not impact  how much the rest of my report applies. My
findings are now being discussed on the ViewVC developers mailing list
[1]. They apparently also impact ViewVC. Whether and to which degree
what I am reporting can be considered a security issue is, however,
currently subject to discussion.

For now, please follow up there only. I will be back to the security
mailing lists as soon as this has been sufficiently discussed and there
is something noteworthy to be said.

Moritz
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFF440Vn6GkvSd/BgwRApdwAKCL+aPccWHsmq4Y6MP/SzrjMDtpVACbBVUE
bh85P5I1agzH5TdDwk8KxiM=
=Gsp7
-----END PGP SIGNATURE-----

<Prev in Thread] Current Thread [Next in Thread>
  • ViewCVS 0.9.4 issues, Moritz Naumann
    • Re: [Full-disclosure] ViewCVS 0.9.4 issues, Moritz Naumann <=