Kayako logo
SupportSuite, eSupport and LiveResponse Discussion, troubleshooting and feedback related to Kayako's flagship support desk products SupportSuite, eSupport and LiveResponse.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  (#1) Old
Jamie Edwards Offline
Operations Manager
 
Jamie Edwards's Avatar
 
Posts: 5,664
Join Date: Jan 2006
Location: United Kingdom
Exclamation HtmlTidy html-tidy-logic.php security patch - 19-11-2008, 01:31 AM

We have patched a file that we distribute with SupportSuite, eSupport and LiveResponse to fix a reported security flaw (as well as another one which we have discovered in the same file).

The flaw can only be triggered when register_globals (in the PHP configuration) is turned on. register_globals is turned off by default, and to turn the setting on would go against PHP 4+ installation guidelines and defaults.

Please download the attached file and replace your existing one with it.

In folder:
Code:
\includes\htmlArea\plugins\HtmlTidy\
Attached Files
File Type: php html-tidy-logic.php (2.3 KB, 61 views)


Jamie Edwards (jamie.edwards ]at[ kayako.com)
----------------------------------------------------------------
---
   
Reply With Quote
  (#2) Old
John Haugeland Offline
Developer
 
John Haugeland's Avatar
 
Posts: 800
Join Date: Dec 2007
Location: Idaho
19-11-2008, 08:25 PM

This patch has been pushed upstream to the HTML Tidy maintainers.


John Haugeland (john.haugeland ]at[ kayako.com)
----------------------------------------------------------------
---
   
Reply With Quote
  (#3) Old
John Haugeland Offline
Developer
 
John Haugeland's Avatar
 
Posts: 800
Join Date: Dec 2007
Location: Idaho
20-11-2008, 07:30 AM

I was incorrect to attribute this source file to HTML Tidy; this source file is in fact our own code. Whereas the defect was correctly identified and repaired, the origin of the source in question was not.

This was a Kayako defect, not a Tidy defect.


John Haugeland (john.haugeland ]at[ kayako.com)
----------------------------------------------------------------
---
   
Reply With Quote
  (#4) Old
GoneShootin Offline
Member
 
GoneShootin's Avatar
 
Posts: 215
Join Date: Jan 2008
20-11-2008, 12:12 PM

Is there an email security bulletin service that we can subscribe to for this kind of notification? Thanks for the update.

Last edited by GoneShootin; 20-11-2008 at 12:14 PM..
   
Reply With Quote
  (#5) Old
craigbrass Online
Senior Member
 
Posts: 5,922
Join Date: Jun 2005
Location: Cumbria, UK
20-11-2008, 03:01 PM

You can subscribe to the news and announcements board on this forum. Go to http://forums.kayako.com/subscriptio...bscription&f=3 to do so.


Craig Brass - Kayako Forum Squatter (Note: I am NOT a staff member)

Icon Headquarters - Its Elixir - Web2Messenger
   
Reply With Quote
  (#6) Old
GoneShootin Offline
Member
 
GoneShootin's Avatar
 
Posts: 215
Join Date: Jan 2008
20-11-2008, 03:18 PM

Quote:
Originally Posted by craigbrass View Post
You can subscribe to the news and announcements board on this forum. Go to http://forums.kayako.com/subscriptio...bscription&f=3 to do so.
Nice one. Cheers.
   
Reply With Quote
  (#7) Old
John Haugeland Offline
Developer
 
John Haugeland's Avatar
 
Posts: 800
Join Date: Dec 2007
Location: Idaho
20-11-2008, 08:07 PM

Actually, I'm now getting mixed responses from parties which should all be giving the same answer about the origin of the defect. At this time I withdraw any claim to knowledge of the origin of the source containing the defect, pending further investigation.

The defect is fixed in our copy of the source; however, it remains unclear at this time whether other parties use this source, and whether or not they are affected.

I will keep this thread up to date as I get a clearer picture of what's going on. Someone is confused (I certainly am, but I mean among the people I'm discussing this with), but I don't know who it is yet.

Regardless, this defect is closed at least in our copy of this source.


John Haugeland (john.haugeland ]at[ kayako.com)
----------------------------------------------------------------
---
   
Reply With Quote
  (#8) Old
John Haugeland Offline
Developer
 
John Haugeland's Avatar
 
Posts: 800
Join Date: Dec 2007
Location: Idaho
20-11-2008, 09:29 PM

I understand the problem now. There is a third party wrapper for HTML Tidy which, confusingly, uses the name HTML Tidy. The reason I believed that we acquired this source from HTML Tidy is that we did; I just was unaware of that there were two products going under this name.

The C library and the PHP bindings - that is, the major product called HTML Tidy - is not subject to this defect.

The third party PHP wrapper, which is a plugin module for htmlArea, is the vulnerable package. Kayako is escalating this issue to the other HTML Tidy group; however, as that plugin is considered unsupported, it remains unclear the expected response.

This defect is resolved in all Kayako products with the patch provided in this thread, and that patch will be reflected in the upcoming 3.30.03 stable, expected promptly (with other bugfixes too).




Kayako would like to thank
  • Arnaud DeSitter from the primary HTML Tidy group,
  • Nuno Lopes from the PHP group, and
  • Ben Greenbaum, Keith Rogers and Rob Keith from Symantec / SecurityFocus
for their immediate, thoughtful, thorough and significant responses to this matter.


John Haugeland (john.haugeland ]at[ kayako.com)
----------------------------------------------------------------
---

Last edited by John Haugeland; 20-11-2008 at 09:33 PM.. Reason: Missed a name in the thank yous; fixed
   
Reply With Quote
Reply

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
Free HTML/Outlook Tickets and Queue Signature Problems - Solved! Matthew Modifications & Addon Releases 10 02-12-2008 09:10 AM
Security Threat in 3.30 STABLE - HTML in ticket preview NC Software SupportSuite, eSupport and LiveResponse 16 16-08-2008 12:48 AM



Powered by vBulletin® Version 3.7.5
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.2.0
Help desk software by Kayako.


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48