Debian Bug report logs - #453278
CVE-2007-6110: XSS in htsearch

version graph

Package: htdig; Maintainer for htdig is Debian QA Group <packages@qa.debian.org>; Source for htdig is src:htdig.

Reported by: Steffen Joeris <steffen.joeris@skolelinux.de>

Date: Wed, 28 Nov 2007 09:51:01 UTC

Severity: important

Tags: patch, security

Found in version htdig/1:3.2.0b6-3.1

Fixed in version htdig/1:3.2.0b6-4

Done: Steffen Joeris <white@debian.org>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, Debian QA Group <packages@qa.debian.org>:
Bug#453278; Package htdig. Full text and rfc822 format available.

Acknowledgement sent to Steffen Joeris <steffen.joeris@skolelinux.de>:
New Bug report received and forwarded. Copy sent to Debian QA Group <packages@qa.debian.org>. Full text and rfc822 format available.

Message #5 received at submit@bugs.debian.org (full text, mbox):

From: Steffen Joeris <steffen.joeris@skolelinux.de>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: CVE-2007-6110: XSS in htsearch
Date: Wed, 28 Nov 2007 20:48:16 +1100
Package: htdig
Version: 1:3.2.0b6-3.1
Severity: important
Tags: security

Hi

The following CVE[0] has been issued against htdig.

CVE-2007-6110:

Cross-site scripting (XSS) vulnerability in htsearch in htdig 3.2.0b6
allows remote attackers to inject arbitrary web script or HTML via the
sort parameter.

Please mention the CVE id number in your changelog, when you fix the
problem.

Cheers
Steffen

[0]: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6110




Tags added: patch Request was from William Grant <william.grant@ubuntu.org.au> to control@bugs.debian.org. (Sun, 02 Dec 2007 00:24:04 GMT) Full text and rfc822 format available.

Information forwarded to debian-bugs-dist@lists.debian.org, Debian QA Group <packages@qa.debian.org>:
Bug#453278; Package htdig. Full text and rfc822 format available.

Acknowledgement sent to William Grant <william.grant@ubuntu.org.au>:
Extra info received and forwarded to list. Copy sent to Debian QA Group <packages@qa.debian.org>. Full text and rfc822 format available.

Message #12 received at 453278@bugs.debian.org (full text, mbox):

From: William Grant <william.grant@ubuntu.org.au>
To: 453278@bugs.debian.org
Subject: Re: CVE-2007-6110: XSS in htsearch
Date: Sun, 02 Dec 2007 11:52:00 +1100
[Message part 1 (text/plain, inline)]
I've prepared a patch/NMU using the patch I uploaded to fix this in Ubuntu.

-- 
William Grant
[htdig_3.2.0b6-3.2.diff (text/x-patch, attachment)]
[signature.asc (application/pgp-signature, inline)]

Reply sent to Steffen Joeris <white@debian.org>:
You have taken responsibility. Full text and rfc822 format available.

Notification sent to Steffen Joeris <steffen.joeris@skolelinux.de>:
Bug acknowledged by developer. Full text and rfc822 format available.

Message #17 received at 453278-close@bugs.debian.org (full text, mbox):

From: Steffen Joeris <white@debian.org>
To: 453278-close@bugs.debian.org
Subject: Bug#453278: fixed in htdig 1:3.2.0b6-4
Date: Sun, 02 Dec 2007 10:02:03 +0000
Source: htdig
Source-Version: 1:3.2.0b6-4

We believe that the bug you reported is fixed in the latest version of
htdig, which is due to be installed in the Debian FTP archive:

htdig-doc_3.2.0b6-4_all.deb
  to pool/main/h/htdig/htdig-doc_3.2.0b6-4_all.deb
htdig_3.2.0b6-4.diff.gz
  to pool/main/h/htdig/htdig_3.2.0b6-4.diff.gz
htdig_3.2.0b6-4.dsc
  to pool/main/h/htdig/htdig_3.2.0b6-4.dsc
htdig_3.2.0b6-4_i386.deb
  to pool/main/h/htdig/htdig_3.2.0b6-4_i386.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 453278@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Steffen Joeris <white@debian.org> (supplier of updated htdig package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.7
Date: Sun, 02 Dec 2007 08:21:04 +0000
Source: htdig
Binary: htdig htdig-doc
Architecture: source i386 all
Version: 1:3.2.0b6-4
Distribution: unstable
Urgency: high
Maintainer: Debian QA Group <packages@qa.debian.org>
Changed-By: Steffen Joeris <white@debian.org>
Description: 
 htdig      - WWW search system for an intranet or small internet
 htdig-doc  - Documentation for the htdig package
Closes: 453278
Changes: 
 htdig (1:3.2.0b6-4) unstable; urgency=high
 .
   * QA upload by the testing-security team
   * Fix XSS in htsearch by not displaying the sort type in
     htsearch/Display.cc and libhtdig/ResultFetch.cc anymore, if it is
     unrecognised (Closes: #453278) Thanks to William Grant
     Fixes: CVE-2007-6110
Files: 
 51203989aa308590710757d0d8c6a998 602 web optional htdig_3.2.0b6-4.dsc
 9a4df1dc1ebf2207a133ac945429bdc6 86277 web optional htdig_3.2.0b6-4.diff.gz
 dd6480852932d671cbc6cdd7c553267e 528280 doc optional htdig-doc_3.2.0b6-4_all.deb
 702ffd38a3ca1964f8a3e3e4db1a5e00 1874888 web optional htdig_3.2.0b6-4_i386.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFHUn/Z62zWxYk/rQcRArf0AKC2W55omBZrgteLAY4dH6pehHoN9ACfeL8k
pXutxnJUQbcnV5AiwAVdHLo=
=Dmoy
-----END PGP SIGNATURE-----





Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Thu, 03 Jan 2008 07:43:03 GMT) Full text and rfc822 format available.

Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Thu Apr 24 04:48:26 2014; Machine Name: buxtehude.debian.org

Debian Bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson.