See how snoopy compares to other vendors in security performance
CVE-2008-4796 describes a command execution flaw in the Snoopy library. A similar fix exists for headers:
http://snoopy.cvs.sourceforge.net/viewvc/snoopy/Snoopy/Snoopy.class.php?view=log#rev1.27
The header fix has been assigned CVE-2008-7313 (as an incomplete fix for CVE-2008-4796).
It was later reported that the CVE-2008-4796 fix was incomplete and command execution was still possible:
http://mstrokin.com/sec/feed2js-magpierss-0day-vulnerability-not-really-it-is-actually-cve-2005-3330-cve-2008-4796/
And fixed with the following:
http://snoopy.cvs.sourceforge.net/viewvc/snoopy/Snoopy/Snoopy.class.php?view=log#rev1.28
This has been assigned CVE-2014-5008 (as an incomplete fix for CVE-2008-4796).
However, the CVE-2014-5008 fix was also incomplete:
https://github.com/cogdog/feed2js/pull/12#issuecomment-48283706
This was fixed with the following:
http://snoopy.cvs.sourceforge.net/viewvc/snoopy/Snoopy/Snoopy.class.php?view=log#rev1.29
And assigned CVE-2014-5009 (as an incomplete fix for CVE-2014-5008).
References:
http://www.openwall.com/lists/oss-security/2014/07/09/11
Snoopy allows remote attackers to execute arbitrary commands. NOTE: this vulnerability exists due to an incomplete fix for CVE-2014-5008.
Snoopy allows remote attackers to execute arbitrary commands.
The httpsrequest function in Snoopy 1.2, as used in products such as (1) MagpieRSS, (2) WordPress, (3) Ampache, and (4) Jinzora, allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTPS URL to an SSL protected web page, which is not properly handled by the fetch function.
CVE-2008-4796 describes a command execution flaw in the Snoopy library. A similar fix exists for headers:
http://snoopy.cvs.sourceforge.net/viewvc/snoopy/Snoopy/Snoopy.class.php?view=log#rev1.27
The header fix has been assigned CVE-2008-7313 (as an incomplete fix for CVE-2008-4796).
It was later reported that the CVE-2008-4796 fix was incomplete and command execution was still possible:
http://mstrokin.com/sec/feed2js-magpierss-0day-vulnerability-not-really-it-is-actually-cve-2005-3330-cve-2008-4796/
And fixed with the following:
http://snoopy.cvs.sourceforge.net/viewvc/snoopy/Snoopy/Snoopy.class.php?view=log#rev1.28
This has been assigned CVE-2014-5008 (as an incomplete fix for CVE-2008-4796).
However, the CVE-2014-5008 fix was also incomplete:
https://github.com/cogdog/feed2js/pull/12#issuecomment-48283706
This was fixed with the following:
http://snoopy.cvs.sourceforge.net/viewvc/snoopy/Snoopy/Snoopy.class.php?view=log#rev1.29
And assigned CVE-2014-5009 (as an incomplete fix for CVE-2014-5008).
References:
http://www.openwall.com/lists/oss-security/2014/07/09/11
Cross-site scripting (XSS) vulnerability in blocks/html/blockhtml.php in Snoopy 1.2.3, as used in Moodle 1.6 before 1.6.9, 1.7 before 1.7.7, 1.8 before 1.8.8, and 1.9 before 1.9.4, allows remote attackers to inject arbitrary web script or HTML via an HTML block, which is not properly handled when the "Login as" feature is used to visit a MyMoodle or Blog page.
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-4796 to the following vulnerability:
The httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in https URLs. NOTE: some of these details are obtained from third party information.
References: http://sourceforge.net/forum/forum.php?forumid=879959 http://jvn.jp/en/jp/JVN20502807/index.html http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000074.html http://www.frsirt.com/english/advisories/2008/2901 http://secunia.com/advisories/32361