Re: [Re: XSS vuln in cvsweb]

2019-03-23 Thread Andrew Hewus Fresh
On Fri, Mar 22, 2019 at 01:41:27AM +0100, Ingo Schwarze wrote: > I committed the patches from both of you to > > http://mandoc.bsd.lv/cgi-bin/cvsweb/?cvsroot=cvsweb > http://mandoc.bsd.lv/cvsweb/ Thanks! I hadn't actually realized there was an upstream past the OpenBSD ports tree. Good to

Re: [Re: XSS vuln in cvsweb]

2019-03-21 Thread Ingo Schwarze
Hi, Peter J. Philipp wrote on Sat, Mar 16, 2019 at 07:52:23AM +0100: > On Fri, Mar 15, 2019 at 05:22:47PM -0700, Andrew Hewus Fresh wrote: >> I looked this over and updated the patch to be against the port. It >> seems to be good and I only found a couple other places that needed to >> be

Re: [Re: XSS vuln in cvsweb]

2019-03-16 Thread Peter J. Philipp
On Fri, Mar 15, 2019 at 05:22:47PM -0700, Andrew Hewus Fresh wrote: > > I have produced the patch with 'diff -u cvsweb.orig cvsweb' directly in the > > /var/www/cgi-bin directory. Credit goes to Ezio Paglia for finding this XSS > > vuln. Also the cvsweb at openbsd.org is affected and can be

Re: [Re: XSS vuln in cvsweb]

2019-03-15 Thread Andrew Hewus Fresh
On Fri, Mar 15, 2019 at 02:25:35PM +0100, Peter J. Philipp wrote: > I have have created a patch for cvsweb port that needs review and help in > getting it into the port itself. I'd like to apologize to Marc Espie for > contacting him regarding this port based on his last check-in on this port,

Re: [Re: XSS vuln in cvsweb]

2019-03-15 Thread Stuart Henderson
On 2019/03/15 16:28, Peter J. Philipp wrote: > would this help any? > > https://people.freebsd.org/~scop/cvsweb/ > > There is subsequent versions. Those are the 13 year old ones that Ingo mentioned. > Regards, > > -peter > > On 3/15/19 4:05 PM, Ingo Schwarze wrote: > > Hi, > > > > the

Re: [Re: XSS vuln in cvsweb]

2019-03-15 Thread Peter J. Philipp
would this help any? https://people.freebsd.org/~scop/cvsweb/ There is subsequent versions. Regards, -peter On 3/15/19 4:05 PM, Ingo Schwarze wrote: Hi, the trouble with cvsweb is that it is important OpenBSD project infrastructure (consider cvsweb.openbsd.org) that has been abandoned

Re: [Re: XSS vuln in cvsweb]

2019-03-15 Thread Stuart Henderson
On 2019/03/15 16:05, Ingo Schwarze wrote: > Hi, > > the trouble with cvsweb is that it is important OpenBSD project > infrastructure (consider cvsweb.openbsd.org) that has been abandoned > upstream 13 years ago, our version is 16 years old, and the port > has no maintainer. Does anybody consider

Re: [Re: XSS vuln in cvsweb]

2019-03-15 Thread Ingo Schwarze
Hi, the trouble with cvsweb is that it is important OpenBSD project infrastructure (consider cvsweb.openbsd.org) that has been abandoned upstream 13 years ago, our version is 16 years old, and the port has no maintainer. Does anybody consider it funny to run a software in production that is