[ 13 posts ] Go to page 1, 2 Next

Eric Miraglia

YUI Contributor

  • Username: miraglia
  • Joined: Tue Sep 02, 2008 10:59 am
  • Posts: 205
  • Location: Los Gatos, CA
  • Twitter: miraglia
  • GitHub: miraglia
  • Gists: miraglia
  • Offline
  • Profile

YUI 2.8.2 and YUI 2.4.0-2.8.1 security bulletin

Post Posted: Mon Oct 25, 2010 11:31 am
+5-
The YUI team released YUI 2.8.2 today, addressing a security issue present in YUI 2.4.0-2.8.1.

If you are a YUI 2 implementer, please review the security bulletin:

http://yuilibrary.com/support/2.8.2/

You can use this forum if you have questions and we'll be happy to help answer them.

tonyquan

  • Joined: Mon Oct 25, 2010 7:27 pm
  • Posts: 2
  • Offline
  • Profile

Re: YUI 2.8.2 and YUI 2.4.0-2.8.1 security bulletin

Post Posted: Mon Oct 25, 2010 7:29 pm
+0-
the MD5 sums listed on the security bulletin webpage appear to be incorrect for YUI 2.5.0. the sums I got were:

MD5 (charts.swf) = dd337b66da67de5d94fb67dd40bd77f6
MD5 (uploader.swf) = aaefcfce0b41a4d3a2d4433441bc7736

could you verify if these are the correct values?

Allen Rabinovich

YUI Developer

  • YUI Developer
  • Offline
  • Profile

Re: YUI 2.8.2 and YUI 2.4.0-2.8.1 security bulletin

Post Posted: Mon Oct 25, 2010 10:01 pm
+0-
tonyquan wrote:
the MD5 sums listed on the security bulletin webpage appear to be incorrect for YUI 2.5.0. the sums I got were:

MD5 (charts.swf) = dd337b66da67de5d94fb67dd40bd77f6
MD5 (uploader.swf) = aaefcfce0b41a4d3a2d4433441bc7736

could you verify if these are the correct values?


I just checked, and the values we have provided in the bulletin are correct. Are you sure your versions of the files haven't been rebuilt locally? If they have, chances are, small differences in the compiler version may have resulted in minute changes to the files, which of course results in a drastically different MD5.

tonyquan

  • Joined: Mon Oct 25, 2010 7:27 pm
  • Posts: 2
  • Offline
  • Profile

Re: YUI 2.8.2 and YUI 2.4.0-2.8.1 security bulletin

Post Posted: Tue Oct 26, 2010 1:03 am
+0-
Allen, there still seems to be something wrong. Here's what I did:

downloaded these two files pointed to by the security bulletin webpage:

http://yuilibrary.com/support/2.8.2/dro ... -2.5.0.zip
http://yuilibrary.com/support/2.8.2/dro ... -2.5.0.zip

unzip each zip file, yielding charts.swf and uploader.swf. ran md5 on the mac and got:

MD5 (charts.swf) = dd337b66da67de5d94fb67dd40bd77f6
MD5 (uploader.swf) = aaefcfce0b41a4d3a2d4433441bc7736

could you double check? When I did this for the 2.7.0 and 2.8.1 files everything was fine.

Matt Parker

YUI Contributor

  • Username: mattatlamplight
  • Joined: Mon Apr 20, 2009 12:03 pm
  • Posts: 466
  • Location: London UK
  • GitHub: mattparker
  • Gists: mattparker
  • Offline
  • Profile

Re: YUI 2.8.2 and YUI 2.4.0-2.8.1 security bulletin

Post Posted: Tue Oct 26, 2010 1:07 am
+0-
Hi,

I think the md5's are of the old files that need replacing, not the replacements. I've put in a request to have both...

Matt

Mike Hatfield

YUI Contributor

  • Username: mikehatfield
  • Joined: Mon Jul 27, 2009 2:57 pm
  • Posts: 2
  • Twitter: mikehatfield
  • GitHub: mikeh
  • Gists: mikeh
  • Offline
  • Profile

Re: YUI 2.8.2 and YUI 2.4.0-2.8.1 security bulletin

Post Posted: Tue Oct 26, 2010 3:41 am
+0-
There are some problems with the YUI 2.8.2 release which seem in part to have been due to the global year update to 2010.

container.js, lines 4789 and 5048
get.js, line 549
yahoo.js, line 298 [comment only]
yuiloader.js, lines 298 [comment only as above], lines 1864, 1865 (refer to v2.8.1 on yahooapis.com)

Also (minor) none of the .css files have been updated to have a v2.8.2 header.

Thanks,
Mike

Eric Miraglia

YUI Contributor

  • Username: miraglia
  • Joined: Tue Sep 02, 2008 10:59 am
  • Posts: 205
  • Location: Los Gatos, CA
  • Twitter: miraglia
  • GitHub: miraglia
  • Gists: miraglia
  • Offline
  • Profile

Re: YUI 2.8.2 and YUI 2.4.0-2.8.1 security bulletin

Post Posted: Tue Oct 26, 2010 8:50 am
+0-
Matt,

I've updated the security bulletin with old/new MD5 values for the files; thanks for the suggestion.

-Eric

Eric Miraglia

YUI Contributor

  • Username: miraglia
  • Joined: Tue Sep 02, 2008 10:59 am
  • Posts: 205
  • Location: Los Gatos, CA
  • Twitter: miraglia
  • GitHub: miraglia
  • Gists: miraglia
  • Offline
  • Profile

Re: YUI 2.8.2 and YUI 2.4.0-2.8.1 security bulletin

Post Posted: Tue Oct 26, 2010 1:10 pm
+0-
Mike,

You're right; we executed a bad regex, and that damaged the 2.8.2 build.

Here's what we've done:

1. The download now points to 2.8.2r1 -- a corrected build.
2. 2.8.2r1 is on the CDN.

Sorry for the additional churn.

-Eric

Damien Pobel

YUI Contributor

  • Username: dpobel
  • Joined: Fri Oct 29, 2010 4:15 am
  • Posts: 8
  • Location: France
  • Twitter: dpobel
  • GitHub: dpobel
  • Gists: dpobel
  • IRC: tigrou
  • Offline
  • Profile

Re: YUI 2.8.2 and YUI 2.4.0-2.8.1 security bulletin

Post Posted: Fri Oct 29, 2010 4:23 am
+0-
Hi,

I've got a question regarding this update. Let's say I have set a far future Expires header on the affected flash files and so many people may have the affected files their browser cache, am I still vulnerable ? What can happen in this case ?

In addition, where can I find some more infos on the security flaw itself ? http://yuilibrary.com/support/2.8.2/ gives instruction on how to update, but nothing what a remote attacker can do exactly.

Regards

Jörg Eichhorn

  • Username: jeichhor
  • Joined: Tue Nov 02, 2010 12:37 am
  • Posts: 1
  • Offline
  • Profile

Re: YUI 2.8.2 and YUI 2.4.0-2.8.1 security bulletin

Post Posted: Tue Nov 02, 2010 1:00 am
+0-
hi,

is my site affected just by hosting the components or by implementing one of the affected components (charts/uploader/swfstore)?

thanks, joerg
  [ 13 posts ] Go to page 1, 2 Next
Display posts from previous:  Sort by  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum