Bug 892328 (CVE-2014-5269) - VUL-0: CVE-2014-5269: perl-Plack: trailing slashes removed leading to source code disclosure
Summary: VUL-0: CVE-2014-5269: perl-Plack: trailing slashes removed leading to source ...
Status: RESOLVED FIXED
Alias: CVE-2014-5269
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other openSUSE 13.1
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/105118/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2014-08-18 09:56 UTC by Alexander Bergmann
Modified: 2014-12-18 14:56 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2014-08-18 09:56:46 UTC
Via rh#1128978:

Plack 1.0031 fixes the following security issue:

- Plack::App::File would previously strip trailing slashes off
provided paths. This in combination with the common pattern
of serving files with Plack::Middleware::Static could allow
an attacker to bypass a whitelist of generated files (avar) #446

Upstream fix:

https://github.com/avar/Plack/commit/bc1731dbb53850c380875ad683cd87c8ec99eee3

CVE-2014-5269 was assigned to this issue.

References:
https://github.com/plack/Plack/issues/405
http://seclists.org/oss-sec/2014/q3/345
https://bugzilla.redhat.com/show_bug.cgi?id=1128978
Comment 1 Swamp Workflow Management 2014-08-18 22:00:20 UTC
bugbot adjusting priority
Comment 2 Michal Marek 2014-12-03 13:35:12 UTC
Anna is on parental leave. Also, this package has only been part of 13.1, so the bug can be moved to openSUSE.
Comment 4 Vítězslav Čížek 2014-12-03 16:23:15 UTC
13.1 update submitted. Reassigning to security-team.
Comment 5 Bernhard Wiedemann 2014-12-03 17:00:26 UTC
This is an autogenerated message for OBS integration:
This bug (892328) was mentioned in
https://build.opensuse.org/request/show/263876 13.2+13.1 / perl-Plack
Comment 6 Swamp Workflow Management 2014-12-15 12:06:38 UTC
openSUSE-SU-2014:1639-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 892328
CVE References: CVE-2014-5269
Sources used:
openSUSE 13.2 (src):    perl-Plack-1.0031-4.1
openSUSE 13.1 (src):    perl-Plack-1.0028-2.4.1
Comment 7 Marcus Meissner 2014-12-18 14:56:47 UTC
released