Kayako logo
SupportSuite, eSupport and LiveResponse Discussion, troubleshooting and feedback related to Kayako's flagship support desk products SupportSuite, eSupport and LiveResponse.

Kayako develops robust helpdesk software, live chat and real-time visitor monitoring software.
Kayako is trusted by more than 30,000 organizations, including a number of Fortune 500 companies and government institutions.
Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  (#1) Old
Jamie Edwards Offline
Limey
 
Posts: 8,141
Join Date: Jan 2006
Location: England, UK
Exclamation HtmlTidy html-tidy-logic.php security patch - 19-11-2008, 12:31 AM

We have patched a file that we distribute with SupportSuite, eSupport and LiveResponse to fix a reported security flaw (as well as another one which we have discovered in the same file).

The flaw can only be triggered when register_globals (in the PHP configuration) is turned on. register_globals is turned off by default, and to turn the setting on would go against PHP 4+ installation guidelines and defaults.

Please download the attached file and replace your existing one with it.

In folder:
Code:
\includes\htmlArea\plugins\HtmlTidy\
Attached Files
File Type: php html-tidy-logic.php (2.3 KB, 65 views)


Jamie Edwards (jamie.edwards ]at[ kayako.com)
----------------------------------------------------------------
---
   
Reply With Quote
  (#2) Old
John Haugeland Offline
Member
 
Posts: 1,222
Join Date: Dec 2007
Location: Boise, Idaho
19-11-2008, 07:25 PM

This patch has been pushed upstream to the HTML Tidy maintainers.


John used to be a Kayako developer
   
Reply With Quote
  (#3) Old
John Haugeland Offline
Member
 
Posts: 1,222
Join Date: Dec 2007
Location: Boise, Idaho
20-11-2008, 06:30 AM

I was incorrect to attribute this source file to HTML Tidy; this source file is in fact our own code. Whereas the defect was correctly identified and repaired, the origin of the source in question was not.

This was a Kayako defect, not a Tidy defect.


John used to be a Kayako developer
   
Reply With Quote
  (#4) Old
GoneShootin Offline
Member
 
GoneShootin's Avatar
 
Posts: 268
Join Date: Jan 2008
20-11-2008, 11:12 AM

Is there an email security bulletin service that we can subscribe to for this kind of notification? Thanks for the update.

Last edited by GoneShootin; 20-11-2008 at 11:14 AM.
   
Reply With Quote
  (#5) Old
craigbrass Offline
Senior Member
 
Posts: 7,909
Join Date: Jun 2005
Location: Cumbria, UK
20-11-2008, 02:01 PM

You can subscribe to the news and announcements board on this forum. Go to http://forums.kayako.com/subscriptio...bscription&f=3 to do so.


Craig Brass - Kayako Forum Squatter (Note: I am NOT a staff member)

Click here for Kayako Software Development

My Addons: BlackBerry Ticket Client for Kayako - Windows Mobile Live Support Client for Kayako
   
Reply With Quote
  (#6) Old
GoneShootin Offline
Member
 
GoneShootin's Avatar
 
Posts: 268
Join Date: Jan 2008
20-11-2008, 02:18 PM

Quote:
Originally Posted by craigbrass View Post
You can subscribe to the news and announcements board on this forum. Go to http://forums.kayako.com/subscriptio...bscription&f=3 to do so.
Nice one. Cheers.
   
Reply With Quote
  (#7) Old
John Haugeland Offline
Member
 
Posts: 1,222
Join Date: Dec 2007
Location: Boise, Idaho
20-11-2008, 07:07 PM

Actually, I'm now getting mixed responses from parties which should all be giving the same answer about the origin of the defect. At this time I withdraw any claim to knowledge of the origin of the source containing the defect, pending further investigation.

The defect is fixed in our copy of the source; however, it remains unclear at this time whether other parties use this source, and whether or not they are affected.

I will keep this thread up to date as I get a clearer picture of what's going on. Someone is confused (I certainly am, but I mean among the people I'm discussing this with), but I don't know who it is yet.

Regardless, this defect is closed at least in our copy of this source.


John used to be a Kayako developer
   
Reply With Quote
  (#8) Old
John Haugeland Offline
Member
 
Posts: 1,222
Join Date: Dec 2007
Location: Boise, Idaho
20-11-2008, 08:29 PM

I understand the problem now. There is a third party wrapper for HTML Tidy which, confusingly, uses the name HTML Tidy. The reason I believed that we acquired this source from HTML Tidy is that we did; I just was unaware of that there were two products going under this name.

The C library and the PHP bindings - that is, the major product called HTML Tidy - is not subject to this defect.

The third party PHP wrapper, which is a plugin module for htmlArea, is the vulnerable package. Kayako is escalating this issue to the other HTML Tidy group; however, as that plugin is considered unsupported, it remains unclear the expected response.

This defect is resolved in all Kayako products with the patch provided in this thread, and that patch will be reflected in the upcoming 3.30.03 stable, expected promptly (with other bugfixes too).




Kayako would like to thank
  • Arnaud DeSitter from the primary HTML Tidy group,
  • Nuno Lopes from the PHP group, and
  • Ben Greenbaum, Keith Rogers and Rob Keith from Symantec / SecurityFocus
for their immediate, thoughtful, thorough and significant responses to this matter.


John used to be a Kayako developer

Last edited by John Haugeland; 20-11-2008 at 08:33 PM. Reason: Missed a name in the thank yous; fixed
   
Reply With Quote
Reply

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Free HTML/Outlook Tickets and Queue Signature Problems - Solved! Matthew Modifications & Extensions 10 02-12-2008 08:10 AM
Security Threat in 3.30 STABLE - HTML in ticket preview NC Software SupportSuite, eSupport and LiveResponse 16 15-08-2008 11:48 PM



Powered by vBulletin® Version 3.8.3
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.3.2


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83