Welcome to Soft32 Linux Forums!
FAQFAQ    SearchSearch      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

Bug#555276: wesnoth: CVE-2007-2383 and CVE-2008-7720 proto..

 
   Soft32 Home -> Linux -> Bugs Dist RSS
Next:  Bug#555270: redmine: embeds prototype.js  
Author Message
Michael Gilbert

External


Since: Nov 21, 2006
Posts: 53



(Msg. 1) Posted: Sun Nov 08, 2009 7:20 pm
Post subject: Bug#555276: wesnoth: CVE-2007-2383 and CVE-2008-7720 prototypejs vulnerabilities
Archived from groups: linux>debian>bugs>dist (more info?)

package: wesnoth
version: 1:1.6.5-1
severity: serious
tags: security

Hi,

Your package contains an embedded version of prototype.js that is
vulnerable to either CVE-2007-2383 (affecting prototype.js before 1.5.1)
[0], CVE-2008-7220 (affecting prototype.js before 1.6.0.2) [1], or both.

Your package embeds the following prototype.js versions:

sid: 1.6.0.1
lenny: N/A
etch: N/A

This is a mass-filing, and the only checking done so far is a version
comparison, so please determine whether or not your package is itself
affected or not. If it is not affected please close the bug with a
message indicating this along with what you did to check.

The version of your package specified above is the earliest version
with the affected embedded code. If this version is in one or both of
the stable releases and you are affected, please coordinate with the
release team to prepare a proposed-update for your package to
stable/oldstable.

There are patches available for CVE-2007-2383 [2] and a backport for
prototypejs 1.5 for CVE-2008-7720 [3].

If you correct the problem in unstable, please make sure to include the
CVE number in your changelog.

Thank you for your attention to this problem.

Mike

[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2383
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-7220
[2] http://dev.rubyonrails.org/ticket/7910
[3] http://prototypejs.org/2008/1/25/prototype-1-6-0-2-bug-fixes-performan...improve



--
To UNSUBSCRIBE, email to debian-bugs-dist-REQUEST DeleteThis @lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster DeleteThis @lists.debian.org
Back to top
Login to vote
Michael Gilbert

External


Since: Nov 21, 2006
Posts: 53



(Msg. 2) Posted: Mon Nov 09, 2009 3:20 pm
Post subject: Bug#555276: wesnoth: CVE-2007-2383 and CVE-2008-7720 prototypejs vulnerabilities [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

On Mon, 9 Nov 2009 20:43:45 +0100, Gerfried Fuchs wrote:
> Can you please run your check also against packages from experimental -
> I am sure you will find at least wesnoth 1.7.6 also to be affected, I
> would expect.

yes, prototype.js is in the wesnoth 1.7.6 source package.

> Actually, the package doesn't really use it. It's used in the stats
> server which isn't shipped or enabled or used in the Debian packages. If
> you feel like removing it from the source tarball might gain us anything
> I can offer to do that, too.

this isn't necessary. as long as the problematic file is not included
in any binary package, then wesnoth can be considered not-affected, and
this bug can be safely closed. since there were so many of these
embeds, i did not have time to individually check to see what each
package was doing.

> [a] well, symlinking. I ship jquery and tablesorter. The former is
> available as package but the later not. Given that the two has to go
> together I chose explicitly not to symlink jquery neither.

this is definitely a problem. since a common version of jquery is
available, it should be used. as for tablesorter you have the option
of either packaging it separately or sticking with the embed (if other
packages use tablesorter, then a separate package should be preferred).

mike



--
To UNSUBSCRIBE, email to debian-bugs-dist-REQUEST RemoveThis @lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster RemoveThis @lists.debian.org
Back to top
Login to vote
Display posts from previous:   
Related Topics:
Bug#435553: Add search on package names - Package: reportbug-ng Version: 0.2007.07.19 Severity: wishlist --- Please enter the report below this line. --- I..

Bug#431170: The way to keep entity is documented in debian.. - Hi, It was a bit ambiguous but debiandoc-sgml-doc has appendix which goes in details how to keep entity. Osamu -- ...

Bug#435552: Doesn't detect debcontrol files in non-debian/.. - Package: vim-runtime Version: 1:7.1-022+1 Severity: minor Tags: patch Hi, "vi control" on a debcon...

Bug#435554: pidgin: Info text in About dialog scrolls down - Package: pidgin Version: 2.1.0-1 Severity: minor -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 When opening the About...

Bug#417674: new versions available - Dear Baishampayan, Please do consider packaging the latest version. Thanks. Kumar -- Kumar Appaiah, 458, Jamuna..

Bug#435556: p7zip-full: 7za should support -sfx - Package: p7zip-full Version: 4.47~dfsg.1-1 Severity: normal On Fedora, the p7zip package only includes the 7za binary....
       Soft32 Home -> Linux -> Bugs Dist All times are: Pacific Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum

Categories:
 Windows
  Linux
 Mac
 PDA


[ Contact us | Terms of Service/Privacy Policy ]