Bug 965573 - (CVE-2016-2228) VUL-0: CVE-2015-8807, CVE-2016-2228: horde5: Two cross-site scripting vulnerabilities
(CVE-2016-2228)
VUL-0: CVE-2015-8807, CVE-2016-2228: horde5: Two cross-site scripting vulnera...
Status: RESOLVED WONTFIX
Classification: openSUSE
Product: openSUSE Distribution
Classification: openSUSE
Component: Security
13.2
Other Other
: P3 - Medium : Normal (vote)
: ---
Assigned To: Denisart Benjamin
Security Team bot
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2016-02-08 09:20 UTC by Sebastian Krahmer
Modified: 2017-01-30 22:32 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sebastian Krahmer 2016-02-08 09:20:49 UTC
From OSS-sec:

>Cross-site scripting in XSS in Horde_Core_VarRenderer_Html:
>https://github.com/horde/horde/commit/11d74fa5a22fe626c5e5a010b703cd46a136f253
>https://bugs.debian.org/813590
>
>horde/framework/Core/lib/Horde/Core/Ui/VarRenderer/Html.php
_renderVarInput_number

Use CVE-2015-8807.


>Reflected cross-site scripting
>https://bugs.horde.org/ticket/14213
>https://github.com/horde/horde/commit/f03301cf6edcca57121a15e80014c4d0f29d99a0
>https://github.com/horde/horde/commit/ab07a1b447de34e13983b4d7ceb18b58c3a358d8
>https://bugs.debian.org/813573

>menu bar
>horde/templates/topbar/_menubar.html.php
>
>searchfield=[XSS]

Use CVE-2016-2228.


References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-2228
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-8807
http://seclists.org/oss-sec/2016/q1/292
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8807
Comment 1 Swamp Workflow Management 2016-02-08 23:00:18 UTC
bugbot adjusting priority
Comment 2 Andreas Stieger 2017-01-30 22:32:45 UTC
This package was dropped from openSUSE Leap 42.1, 42.2. It is fixed in server:php:applications/horde5 (5.2.12), but shall remain unfixed in 13.2 as it is discontinued. Closing.