AlphaOne Technology Support Forums
Welcome, Guest. Please login or register.
December 03, 2008, 06:42:48 PM

Login with username, password and session length
Search:     Advanced search
1733 Posts in 827 Topics by 4767 Members
Latest Member: CleosMM
* Home Help Search Login Register
AlphaOne Technology Support Forums  |  IMPORTANT ANNOUNCEMENTS  |  Security Announcements  |  PhpBB Alerts  |  Topic: PHPBB Security Alert! 0 Members and 1 Guest are viewing this topic. « previous next »
Pages: [1] Go Down Print
Author Topic: PHPBB Security Alert!  (Read 2281 times)
AlphaWolf
AOT Administrator
Administrator
Hero Member
*****
Offline Offline

Posts: I am a geek!!



View Profile WWW
PHPBB Security Alert!
« on: February 23, 2005, 09:09:52 AM »

 K-OTik Security Advisory : KOTIK/ADV-2005-0194
CVE Reference : CAN-2005-0258 - CAN-2005-0259
Rated as : Moderate
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2005-02-23

 * Technical Description *

Two vulnerabilities were identified in phpBB, and may be exploited by remote attackers to read or deleted arbitrary system files. The first flaw is due to an input validation error when handling specially crafted requests to upload avatars, which may be exploited by attackers to read arbitrary system files. The second vulnerability is due to a directory traversal error when handling the "avatarselect" return value, which may be exploited by attackers to unlink arbitrary system files.

 * Affected Products *

phpBB version 2.0.11 and prior

 * Solution *

phpBB version 2.0.12 :
http://www.phpbb.com/downloads.php

 * References *

http://www.k-otik.com/english/advisories/2005/0194
http://idefense.com/application/poi/display?id=204&type=vulnerabilities
http://idefense.com/application/poi/display?id=205&type=vulnerabilities
« Last Edit: February 28, 2005, 12:12:47 PM by AlphaWolf » Logged

AlphaOne Tech Webmaster Resources
http://www.alphaone-tech.com/resources/
songdove
Guest


Email
Re: PHPBB Security Alert!
« Reply #1 on: February 24, 2005, 09:55:47 PM »

I wonder if this affects PNphpBB2 at all.
Logged
apache
Tech Team
Full Member
********
Offline Offline

Posts: 15


View Profile
Re: PHPBB Security Alert!
« Reply #2 on: February 24, 2005, 10:16:33 PM »

I wonder if this affects PNphpBB2 at all.

Hey songdove,

I would suggest you check both the Phpbb and the Post Nuke support forums to be sure.

Thanks,
Apache
Logged
songdove
Guest


Email
Re: PHPBB Security Alert!
« Reply #3 on: February 25, 2005, 12:37:18 AM »

Yeah, am over at the PNphpBB2 site now and 1.2h will have the security updates in it.

I have a task and a half ahead of me when I go to upgrade however.  But good to know the security fixes will be there.
Logged
AlphaWolf
AOT Administrator
Administrator
Hero Member
*****
Offline Offline

Posts: I am a geek!!



View Profile WWW
Re: PHPBB Security Alert!
« Reply #4 on: February 25, 2005, 03:25:11 AM »

When will this release be out?

Since we will be moving everyone except two sites off of Alpha 2 by March 13th at the latest, (tribforcehq.com being one of those we are holding off on moving as we need to make sure you have fixed the DNS problems by then & that we have a complete listing of all the necessary symlinks).  But Alpha 2 will close down permanently by the 20th of March and we have concerns about moving over unsecured sites.  Since your site has never previously been a problem even when it was left unsecured a few months back, we would take the chance and move you as long as we had an approximate CLOSE date when the patch would be available and when you could install it.

peace

Wolf
Logged

AlphaOne Tech Webmaster Resources
http://www.alphaone-tech.com/resources/
songdove
Guest


Email
Re: PHPBB Security Alert!
« Reply #5 on: February 25, 2005, 02:00:52 PM »

The DNS issue has been dealt with by finally being able to move all subdomains to cpanel. Yaaaaaaaaaa.  That has also resulted in faster load times for the site(naturally).  Our current version of PNphpBB2, 1.2d, didn't have the vulnerability quirk in it that 1.2g does, so we're fine that way for now.

So all subdomains needing symlinking are now in our subdomain list in cpanel.  So that issue is finally where it can be dealt with properly.

As for upgrading PNphpBB2, I've asked about a release date for 1.2h today and am waiting on a response. 

I've also asked if there is any easier way to do the upgrade, as 1.2g demanded that we remove the current skin on the site before completing the upgrade, as it doesn't work with autothemes.  I'm hoping that isn't an issue with 1.2h.  I may be pulling an allnighter to get it done too as the existing files have to be removed before the new files are put up.  Not fun!

:-(
Logged
AlphaWolf
AOT Administrator
Administrator
Hero Member
*****
Offline Offline

Posts: I am a geek!!



View Profile WWW
Re: PHPBB Security Alert!
« Reply #6 on: February 25, 2005, 06:59:54 PM »

The DNS issue has been dealt with by finally being able to move all subdomains to cpanel. Yaaaaaaaaaa.  That has also resulted in faster load times for the site(naturally).  Our current version of PNphpBB2, 1.2d, didn't have the vulnerability quirk in it that 1.2g does, so we're fine that way for now.

So all subdomains needing symlinking are now in our subdomain list in cpanel.  So that issue is finally where it can be dealt with properly.

As for upgrading PNphpBB2, I've asked about a release date for 1.2h today and am waiting on a response. 

I've also asked if there is any easier way to do the upgrade, as 1.2g demanded that we remove the current skin on the site before completing the upgrade, as it doesn't work with autothemes.  I'm hoping that isn't an issue with 1.2h.  I may be pulling an allnighter to get it done too as the existing files have to be removed before the new files are put up.  Not fun!

:-(

Ugh - my sympathies Songdove!  We are going through something similar and it IS a nightmare sometimes to upgrade a very customized site.

Glad to hear your DNS is now being handled by us.  All that will mean for you is once we notify you the move for tribforcehq is complete, you will need to change the DNS name servers at the registrar.

peace

Wolf
Logged

AlphaOne Tech Webmaster Resources
http://www.alphaone-tech.com/resources/
songdove
Tribforce Tribble, I mean Tribbie
Full Member
***
Offline Offline

Posts: 16


Top tribble at Trib


View Profile
Re: PHPBB Security Alert!
« Reply #7 on: February 26, 2005, 06:09:00 PM »

Well, the people over at the PNphpBB2 board aren't being very helpful, treating my situation as if its child's play.  I'm now told the security issues for phpBB version 2.0.12 are considered minor by the PNphpBB2 staff, as apparently, the only major issue was covered by a patch they had to make for 1.2g of PNphpBB2, claiming that 1.2h is only going to be a minor upgrade from 1.2g.

Soooooo, I guess that means I have to try to redo the 1.2g upgrade.  I uploaded a nonautotheme skin to all of the subsites last night, so hopefully everything will go smoothly.  I can't pull an allnighter tonight, so this will have to wait till the end of next week.   Hopefully it won't take too long to do.
Logged

We sacrifice all that we are and all that we love for the greater good, the One above. Visit me at http://tribforcehq.com, http://tribkids.com, http://teshuvatrumpet.org, http://sswat.uni.cc, http://planetlogos.now.nu
AlphaWolf
AOT Administrator
Administrator
Hero Member
*****
Offline Offline

Posts: I am a geek!!



View Profile WWW
Re: PHPBB Security Alert!
« Reply #8 on: February 26, 2005, 08:10:09 PM »

Well, the people over at the PNphpBB2 board aren't being very helpful, treating my situation as if its child's play.  I'm now told the security issues for phpBB version 2.0.12 are considered minor by the PNphpBB2 staff, as apparently, the only major issue was covered by a patch they had to make for 1.2g of PNphpBB2, claiming that 1.2h is only going to be a minor upgrade from 1.2g.

Soooooo, I guess that means I have to try to redo the 1.2g upgrade.  I uploaded a nonautotheme skin to all of the subsites last night, so hopefully everything will go smoothly.  I can't pull an allnighter tonight, so this will have to wait till the end of next week.   Hopefully it won't take too long to do.

Not a problem SongDove - I pulled a moron and failed to check that the time to lives had been altered in all the domain's DNS zones, (need to do that 36 hours before a move in server), so we have had to back off and schedule the majority of the Alpha 2 move for late Sunday - Tuesday.  We have one customer we are moving on the 10th, so you really have until about the 9th to get it ready.

peace

Wolf
Logged

AlphaOne Tech Webmaster Resources
http://www.alphaone-tech.com/resources/
Pages: [1] Go Up Print 
AlphaOne Technology Support Forums  |  IMPORTANT ANNOUNCEMENTS  |  Security Announcements  |  PhpBB Alerts  |  Topic: PHPBB Security Alert! « previous next »
Jump to:  

Powered by MySQL Powered by PHP AlphaOne Technology Support Forums | Powered by SMF 1.0.7.
© 2001-2005, Lewis Media. All Rights Reserved.
Valid XHTML 1.0! Valid CSS!