Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 143301
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: R Stephan <ralf@ark.in-berlin.de>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 143301 depends on: Show dependency tree
Bug 143301 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2006-08-09 01:46 0000
Subject says it all. Malicious web sites have an open door, as the option to
turn it off is buried in the preferences. Liferea can use the gnome browser
mechanism, or several other browsers. I have not checked if the option is
promoted to them, but then, if not, why have the option, at all?

------- Comment #1 From R Stephan 2006-08-26 07:25:12 0000 -------
a related security problem was reported in
http://sourceforge.net/tracker/index.php?func=detail&aid=1543623&group_id=87005&atid=581684

and is now fixed in upstream cvs, so I'll close this when this is in the
tarballs and unmasked.

------- Comment #2 From Sune Kloppenborg Jeppesen 2006-09-14 16:03:05 0000 -------
Reassigning to security.

Note to reporter: non security devs are not able to access the bug when you
restrict it to the security group.

------- Comment #3 From Sune Kloppenborg Jeppesen 2006-09-26 09:31:44 0000 -------
Micheal please advise.

------- Comment #4 From Sune Kloppenborg Jeppesen 2006-11-24 12:42:35 0000 -------
Micheal please advise.

------- Comment #5 From Sune Kloppenborg Jeppesen 2007-03-25 11:54:31 0000 -------
Pulling in new maintainer to advise.

------- Comment #6 From Daniel Gryniewicz 2007-03-26 17:06:15 0000 -------
According to that upstream bug, the fix went into 1.1.2; 1.2.x has been in the
tree for a long time, but it can't go stable until xulrunner is stable (ppc64
and sparc holding out there).  I was planning on submitting 1.2.7 for stable
relatively soon, pending that xulrunner issue.

I don't know a whole lot about javascript vulnerabilites.  Are they important? 
I had thought (possibly erroniously) that javascript was fairly safe to have
enabled.  Is a feed reader a serious potential attach vector?  Yes, it's poll,
but the user has to specifically subscribe to feeds.

I guess security's opinion here should matter.

------- Comment #7 From Raphael Marichez 2007-03-30 20:34:48 0000 -------
i don't think that is serious until there is another vulnerability. BTW, is
javascript in liferea really useful??

------- Comment #8 From Pierre-Yves Rofes 2007-08-24 14:32:34 0000 -------
Daniel, do you have any updates about the xulrunner issue which was blocking
stabilization of 1.2.x? btw I agree with falco, Javascript issues are not very
serious in general, though that issue should be fixed anyway.

------- Comment #9 From Daniel Gryniewicz 2007-08-24 18:59:24 0000 -------
xulrunner is now okay; the current blocker is networkmanager.  No version of it
is stable.

------- Comment #10 From Christian Faulhammer 2007-09-08 22:33:01 0000 -------
(In reply to comment #9)
> xulrunner is now okay; the current blocker is networkmanager.  No version of it
> is stable.

 networkmanager is stable on all needed arches, so I propose to call arches
here on 1.2.23 prematurely.

------- Comment #11 From Sune Kloppenborg Jeppesen 2007-09-10 06:20:23 0000 -------
Daniel is 1.2.3 ready for stable marking?

------- Comment #12 From Daniel Gryniewicz 2007-09-10 13:37:25 0000 -------
1.2.23 is fine.  I apparently accidentally committed amd64 stable by accident,
so you can leave amd64 out.

FTR, repoman and pcheck still complain about x86-fbsd and repoman.

------- Comment #13 From Sune Kloppenborg Jeppesen 2007-09-10 16:19:52 0000 -------
Thx Daniel. Arches please test and mark stable. Target keywords are:

liferea-1.2.23.ebuild:KEYWORDS="amd64 ppc ppc64 sparc x86"

Note:amd64 is already stable but cc'ing arch team so they can actually test:-)

------- Comment #14 From Christian Faulhammer 2007-09-10 17:08:04 0000 -------
x86 stable

------- Comment #15 From Daniel Gryniewicz 2007-09-10 17:13:57 0000 -------
(FTR, I'm a member of the amd64 team and have, in fact, tested on amd64...  I
believe this should be sufficient.)

------- Comment #16 From Sune Kloppenborg Jeppesen 2007-09-10 17:43:33 0000 -------
Then let's remove amd64. Though it was not obvious from your first comment that
you had actually tested:-)

------- Comment #17 From Tobias Scherbaum 2007-09-10 18:03:06 0000 -------
ppc stable

------- Comment #18 From Jose Luis Rivero (yoswink) 2007-09-12 09:09:09 0000 -------
seems to work fine in sparc. Stable!

------- Comment #19 From Markus Rothe 2007-09-13 11:32:57 0000 -------
ppc64 stable

(uhmm.. late again. sorry.)

------- Comment #20 From Robert Buchholz 2007-09-13 11:57:51 0000 -------
Voting time!

------- Comment #21 From Pierre-Yves Rofes 2007-09-13 13:23:42 0000 -------
I vote NO.

------- Comment #22 From Sune Kloppenborg Jeppesen 2007-09-24 16:48:02 0000 -------
Voting NO and closing.

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug