New issue
Advanced search Search tips

Issue 796513 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Dec 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 1
Type: Bug-Security



Sign in to add a comment

Chromium: Vulnerability reported in apache-win32

Project Member Reported by vomit.go...@appspot.gserviceaccount.com, Dec 20 2017

Issue description

Automated analysis has detected that the following third party packages have had vulnerabilities publicly reported. 

NOTE: There may be several bugs listed below - in almost all cases, all bugs can be quickly addressed by upgrading to the latest version of the package.

Package Name: apache-win32
Package Version: [cpe:/a:apache:http_server:2.2.25]

Advisory: CVE-1999-1237
  Details: https://vomit.googleplex.com/advisory?id=CVE/CVE-1999-1237
  CVSS severity score: 10/10.0
  Confidence: high
  Description:

Multiple buffer overflows in smbvalid/smbval SMB authentication library, as used in Apache::AuthenSmb and possibly other modules, allows remote attackers to execute arbitrary commands via (1) a long username, (2) a long password, and (3) other unspecified methods.
Advisory: CVE-2001-0131
  Details: https://vomit.googleplex.com/advisory?id=CVE/CVE-2001-0131
  CVSS severity score: 1.2/10.0
  Confidence: high
  Description:

htpasswd and htdigest in Apache 2.0a9, 1.3.14, and others allows local users to overwrite arbitrary files via a symlink attack.


 
Cc: qyears...@chromium.org
Components: Blink>Infra
Over in Issue 747666, an update of Apache is being looked at. However, these vulnerabilities are from 1999 and 2001 respectively, so it's not clear why their CVEs were updated today or whether whatever change occurred is actually applicable to us.  

https://cs.chromium.org/chromium/src/third_party/apache-win32/README.chromium is a checked-in copy of Apache 2.2.25 for Win 32. It is used by the Blink layout tests.

The change history for these issues shows that the change to the reports on 12/18/2017 was to replace one advisory URL with another. I don't think there's any action required for Chrome.

https://nvd.nist.gov/vuln/detail/CVE-2001-0131#VulnChangeHistoryDiv
https://nvd.nist.gov/vuln/detail/CVE-1999-1237#VulnChangeHistoryDiv
Status: WontFix (was: Unconfirmed)
Project Member

Comment 4 by sheriffbot@chromium.org, Mar 31 2018

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment