From owner-freebsd-ports-bugs@FreeBSD.ORG Mon Oct 17 07:40:08 2011 Return-Path: Delivered-To: freebsd-ports-bugs@hub.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id A920E1065673 for ; Mon, 17 Oct 2011 07:40:08 +0000 (UTC) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (freefall.freebsd.org [IPv6:2001:4f8:fff6::28]) by mx1.freebsd.org (Postfix) with ESMTP id 8645D8FC0A for ; Mon, 17 Oct 2011 07:40:08 +0000 (UTC) Received: from freefall.freebsd.org (localhost [127.0.0.1]) by freefall.freebsd.org (8.14.4/8.14.4) with ESMTP id p9H7e880089332 for ; Mon, 17 Oct 2011 07:40:08 GMT (envelope-from gnats@freefall.freebsd.org) Received: (from gnats@localhost) by freefall.freebsd.org (8.14.4/8.14.4/Submit) id p9H7e8uZ089331; Mon, 17 Oct 2011 07:40:08 GMT (envelope-from gnats) Resent-Date: Mon, 17 Oct 2011 07:40:08 GMT Resent-Message-Id: <201110170740.p9H7e8uZ089331@freefall.freebsd.org> Resent-From: FreeBSD-gnats-submit@FreeBSD.org (GNATS Filer) Resent-To: freebsd-ports-bugs@FreeBSD.org Resent-Reply-To: FreeBSD-gnats-submit@FreeBSD.org, Fumiyuki Shimizu Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 59E501065670; Mon, 17 Oct 2011 07:38:48 +0000 (UTC) (envelope-from fumifumi@akkan.be) Received: from eyesonly.akkan.be (eyesonly.akkan.be [204.109.63.197]) by mx1.freebsd.org (Postfix) with ESMTP id 0B8208FC15; Mon, 17 Oct 2011 07:38:47 +0000 (UTC) Received: from eyesonly.akkan.be (localhost [127.0.0.1]) by eyesonly.akkan.be (Postfix) with ESMTP id 570BD284D6; Mon, 17 Oct 2011 16:23:12 +0900 (JST) Received: from eyesonly.akkan.be (unknown [127.0.0.1]) by eyesonly.akkan.be (Postfix) with ESMTP id 33204284D5; Mon, 17 Oct 2011 16:23:12 +0900 (JST) Received: by eyesonly.akkan.be (Postfix, from userid 2323) id 11E1E284D0; Mon, 17 Oct 2011 16:23:12 +0900 (JST) Message-Id: <20111017072312.11E1E284D0@eyesonly.akkan.be> Date: Mon, 17 Oct 2011 16:23:12 +0900 (JST) From: Fumiyuki Shimizu To: FreeBSD-gnats-submit@FreeBSD.org X-Send-Pr-Version: 3.113 Cc: secteam@FreeBSD.org Subject: ports/161734: [vuxml] security/vuxml: PivotX -- Remote File Inclusion Vulnerability of TimThumb X-BeenThere: freebsd-ports-bugs@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Ports bug reports List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 17 Oct 2011 07:40:08 -0000 >Number: 161734 >Category: ports >Synopsis: [vuxml] security/vuxml: PivotX -- Remote File Inclusion Vulnerability of TimThumb >Confidential: no >Severity: serious >Priority: high >Responsible: freebsd-ports-bugs >State: open >Quarter: >Keywords: >Date-Required: >Class: change-request >Submitter-Id: current-users >Arrival-Date: Mon Oct 17 07:40:07 UTC 2011 >Closed-Date: >Last-Modified: >Originator: Fumiyuki Shimizu >Release: FreeBSD 8.1-RELEASE i386 >Organization: Abacus Technologies, Inc. >Environment: System: FreeBSD 8.1-RELEASE #0: Mon Jul 19 02:55:53 UTC 2010 >Description: Currentry TimThumb.php remote file inclusion attack is in wild. Port maintainer (secteam@FreeBSD.org) is cc'd. Generated with FreeBSD Port Tools 0.99 >How-To-Repeat: >Fix: --- vuxml-1.1_1.patch begins here --- diff -ruN --exclude=CVS /usr/ports/security/vuxml/vuln.xml /usr/home/fumifumi/vuxml/vuln.xml --- /usr/ports/security/vuxml/vuln.xml 2011-10-17 03:39:44.000000000 +0900 +++ /usr/home/fumifumi/vuxml/vuln.xml 2011-10-17 16:03:06.000000000 +0900 @@ -34,6 +34,40 @@ --> + + PivotX -- Remote File Inclusion Vulnerability of TimThumb + + + pivotx + 2.3.0 + + + + +

The PivotX team reports:

+
+

TimThumb domain name security bypass and insecure cache + handling. PivotX before 2.3.0 includes a vulnerable version + of TimThumb.

+
+
+

If you are still running PivotX 2.2.6, you might be + vulnerable to a security exploit, that was patched + previously. Version 2.3.0 doesn't have this issue, but any + older version of PivotX might be vulnerable.

+
+ +
+ + 45416 + https://secunia.com/advisories/45416/ + + + 2011-08-03 + 2011-10-17 + +
+ OpenTTD -- Multiple buffer overflows in validation of external data --- vuxml-1.1_1.patch ends here --- >Release-Note: >Audit-Trail: >Unformatted: