Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Date: Wed, 02 Mar 2016 13:12:31 +0000
From: Darren Martyn <darren.martyn@...hosresearch.co.uk>
To: oss-security@...ts.openwall.com
Subject: CVE Request(s): VTigerCRM and SugarCRM

Hi List,
Requesting CVE's to be issued as appropriate for the following security
issues.

SugarCRM Incomplete Blacklist leading to shell upload.
This is the exact same issue as CVE-2015-5946, except different product
(CVE-2015-5946 was issued for SuiteCRM, which is a SugarCRM fork).
Unsure if this needs a second CVE issued or not given it is a different
product (same original codebase though).
The version tested was SugarCRM Community Edition version 6.5.22.

VTiger CRM Post-Auth Shell Upload.
Version Tested: vtiger CRM 4.2 Patch 2
This is a similar issue to the original SugarCRM and SuiteCRM issues.
Effectively, the filtering applied to prevent uploading executable files
is insufficient and trivially bypassed, leading to remote code execution.
The checks avoided are a horrible "check if there is PHP in the file"
function, getimagesize(), a MIME type check, and a file extension check.
Given that it is a different code-path entirely to the original SugarCRM
codebase, it probably should be treated as a different issue.

Details are outlined here, to avoid repeating the same information:
http://xiphosresearch.com/2016/03/01/Vulnerability-Inheritance-across-Forks.html

Both issues (SugarCRM and VTigerCRM) require authentication, however
both clearly display bypass of intended security restrictions.

Best regards,
Darren Martyn.



Download attachment "signature.asc" of type "application/pgp-signature" (820 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.