EPrints Technical Mailing List Archive
Message: #08535
< Previous (by date) | Next (by date) > | < Previous (in thread) | Next (in thread) > | Messages - Most Recent First | Threads - Most Recent First
Re: [EP-tech] EPrints Security Announcement - February 2020
- To: "eprints-tech@ecs.soton.ac.uk" <eprints-tech@ecs.soton.ac.uk>, "Alan.Stiles" <alan.stiles@open.ac.uk>
- Subject: Re: [EP-tech] EPrints Security Announcement - February 2020
- From: John Salter <J.Salter@leeds.ac.uk>
- Date: Wed, 24 Feb 2021 14:35:47 +0000
CAUTION: This e-mail originated outside the University of Southampton.
I was wondering if anyone had integrated any _javascript_ libraries (e.g. https://www.mathjax.org/) to achieve something similar to this?
Cheers,
John
From: eprints-tech-bounces@ecs.soton.ac.uk <eprints-tech-bounces@ecs.soton.ac.uk> on behalf of Alan.Stiles via Eprints-tech <eprints-tech@ecs.soton.ac.uk>
Sent: 24 February 2021 14:03 To: eprints-tech@ecs.soton.ac.uk <eprints-tech@ecs.soton.ac.uk> Subject: Re: [EP-tech] EPrints Security Announcement - February 2020
CAUTION: This e-mail originated outside the University of Southampton.
The patch does leave latex2png empty. We still use this to include e.g. mathematical symbology in item abstracts so we have added some sanitisation to the input parameter in that cgi script rather than removing the function completely (3.3.15 or 16 here).
Alan
From:
<eprints-tech-bounces@ecs.soton.ac.uk> on behalf of "eprints-tech@ecs.soton.ac.uk" <eprints-tech@ecs.soton.ac.uk>
CAUTION: This mail comes from outside the University. Please consider this before opening attachments, clicking links, or acting on the content. CAUTION: This e-mail originated outside the University of Southampton. Hi David,
Thank you very much for bringing this to our attention and providing the solutions.
Shamefully, we are still on 3.3.14 (I promise we are upgrading this year). The patch mentioned works on 3.3.16 and the page says it might work on earlier versions (a brief look through two of the files suggests they're more or less the same as those for 3.3.16)
In my attempt to avoid any problems that could result from "might" are these the files that need altering if I were to do it manually:
/cgi/ajax/phrase : CVE-2021-26703 /cgi/latex2png : CVE-2021-3342 /cgi/toolbox/toolbox : CVE-2021-26704
There also appears to be some changes to be made to XML.pm
Am I interpreting it correctly where it looks as though latex2png will be left as an empty file (deleted) by the end?
I think the page makes it very clear that these are the files that are affected, but I just want to check there aren't any others that the patch addresses. I have looked at the patch, but I try not to underestimate my ability to totally misunderstand the most obvious of things.
My plan is to try the command first on a test EPrints server and if it doesn't work, do it manually. James
On Wed, Feb 24, 2021 at 9:27 AM David R Newman via Eprints-tech <eprints-tech@ecs.soton.ac.uk> wrote:
|
- Follow-Ups:
- Re: [EP-tech] EPrints Security Announcement - February 2020
- From: John Salter <J.Salter@leeds.ac.uk>
- Re: [EP-tech] EPrints Security Announcement - February 2020
- References:
- [EP-tech] EPrints Security Announcement - February 2020
- From: David R Newman <drn@ecs.soton.ac.uk>
- Re: [EP-tech] EPrints Security Announcement - February 2020
- From: James Kerwin <jkerwin2101@gmail.com>
- Re: [EP-tech] EPrints Security Announcement - February 2020
- From: "Alan.Stiles" <alan.stiles@open.ac.uk>
- Re: [EP-tech] EPrints Security Announcement - February 2020
- From: John Salter <J.Salter@leeds.ac.uk>
- [EP-tech] EPrints Security Announcement - February 2020
- Prev by Date: Re: [EP-tech] EPrints Security Announcement - February 2020
- Next by Date: Re: [EP-tech] EPrints Security Announcement - February 2020
- Previous by thread: [EP-tech] Sort view with creators_name and corp_creators
- Index(es):