First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 59419
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: ChazeFroy <chazefroy@gmail.com>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 59419 depends on: Show dependency tree
Bug 59419 blocks:
Votes: 0    Show votes for this bug    Vote for this bug

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2004-08-04 10:22 0000
Mozilla Firefox 0.9.3 released, fixing several security vulnerabilities.

Bug 253121 - lock icon and certificates spoofable with onunload document.write
Bug 249004 - Importing false CA certificate leading to error -8182 (perm DoS), especially exploitable by email
Bug 251381 - new libpng buffer overflow vulnerabilities
Bug 250906 - null (%00) in filename fakes extension (ftp, file)

Reproducible: Always
Steps to Reproduce:

------- Comment #1 From Thierry Carrez (RETIRED) 2004-08-04 10:35:15 0000 -------
Mozilla team : please bump to 1.7.2 and 0.9.3.

------- Comment #2 From Aron Griffis (RETIRED) 2004-08-04 11:16:56 0000 -------
Ok, I'm working on this

------- Comment #3 From Aron Griffis (RETIRED) 2004-08-04 17:04:47 0000 -------
thunderbird is finished.  mozilla and firefox are still in the works.  In the
case of mozilla enough things have changed that it wasn't a simple bump (at
least one patch of ours no longer applies).  In the case of firefox it doesn't
even build out of the box; they apparently left some files out of the
distribution.

Stay tuned...

------- Comment #4 From Aron Griffis (RETIRED) 2004-08-04 17:05:32 0000 -------
thunderbird is finished.  mozilla and firefox are still in the works.  In the
case of mozilla enough things have changed that it wasn't a simple bump (at
least one patch of ours no longer applies).  And thanks to the haste of our
friends at mozilla.org, neither moz nor ff builds out of the box!  :-(

Stay tuned...

------- Comment #5 From ChazeFroy 2004-08-04 17:39:53 0000 -------
I simply copied the 0.9.1 ebuild to 0.9.3, and it compiled fine on x86.

------- Comment #6 From ChazeFroy 2004-08-04 17:44:00 0000 -------
I simply copied the 0.9.1 ebuild to 0.9.3, and firefox compiled fine on x86.

------- Comment #7 From Aron Griffis (RETIRED) 2004-08-04 19:20:17 0000 -------
mozilla-1.7.2 source package is incomplete
    http://bugzilla.mozilla.org/show_bug.cgi?id=254346

------- Comment #8 From Aron Griffis (RETIRED) 2004-08-04 19:23:43 0000 -------
Thanks Chaze, I'll try that now.  My updated ebuild had some modifications, but
nothing that I thought would cause the build to fail.  It might depend on USE
flags.  Stay tuned...

------- Comment #9 From Aron Griffis (RETIRED) 2004-08-04 19:24:06 0000 -------
*** Bug 59439 has been marked as a duplicate of this bug. ***

------- Comment #10 From Aron Griffis (RETIRED) 2004-08-05 04:50:31 0000 -------
*** Bug 59437 has been marked as a duplicate of this bug. ***

------- Comment #11 From Aron Griffis (RETIRED) 2004-08-05 04:54:56 0000 -------
mozilla-firefox-0.9.3
mozilla-firefox-bin-0.9.3
mozilla-thunderbird-0.7.3
mozilla-thunderbird-bin-0.7.3
mozilla-bin-1.7.2

These are all in portage now, marked ~arch for the moment.  It's still impossible to build mozilla-1.7.2 from source so we're waiting on upstream for that.

------- Comment #12 From Thierry Carrez (RETIRED) 2004-08-05 04:58:29 0000 -------
*** Bug 57380 has been marked as a duplicate of this bug. ***

------- Comment #13 From Aron Griffis (RETIRED) 2004-08-05 04:59:01 0000 -------
*** Bug 59420 has been marked as a duplicate of this bug. ***

------- Comment #14 From Thierry Carrez (RETIRED) 2004-08-05 05:17:09 0000 -------
agriffis: From CVSweb it looks like you bumped mozilla-firefox-0.9.3 directly
with the 0.9.1 keywords, i.e. stable on most arches... I don't think it was
your intention ?

------- Comment #15 From Thierry Carrez (RETIRED) 2004-08-05 05:43:10 0000 -------
Here are the target keywords :

mozilla-firefox-0.9.3 : "x86 ppc sparc alpha amd64 ia64"
mozilla-firefox-bin-0.9.3 : "x86 amd64"
mozilla-thunderbird-0.7.3 : "x86 ~ppc sparc ~alpha amd64 ia64"
mozilla-thunderbird-bin-0.7.3 : "~x86" (done)
mozilla-bin-1.7.2 : (none, new package)
mozilla-1.7.2 (when available) : "x86 ppc sparc alpha amd64 ia64"

Please test and mark stable for the moment :
x86 : mozilla-firefox-bin-0.9.3 mozilla-thunderbird-0.7.3
ppc : mozilla-firefox-0.9.3
sparc : mozilla-firefox-0.9.3 mozilla-thunderbird-0.7.3
alpha : mozilla-firefox-0.9.3
amd64 : mozilla-firefox-0.9.3 mozilla-firefox-bin-0.9.3 mozilla-thunderbird-0.7.3
ia64 : mozilla-firefox-0.9.3 mozilla-thunderbird-0.7.3

------- Comment #16 From Olivier Crete 2004-08-05 07:15:00 0000 -------
firefox-bin stable on x86.. two more comments on that ebuild: virtual/x11 is
twice in RDEPEND and virtual/libc is in DEPEND but is missing from RDEPEND... 

------- Comment #17 From Tom Martin (RETIRED) 2004-08-05 13:00:10 0000 -------
mozilla-thunderbird-0.7.3 fails with:

gmake[2]: Entering directory `/var/tmp/portage/mozilla-thunderbird-0.7.3/work/mozilla/other-licenses/libart_lgpl'
gmake[2]: *** No rule to make target `export'.  Stop.
gmake[2]: Leaving directory `/var/tmp/portage/mozilla-thunderbird-0.7.3/work/mozilla/other-licenses/libart_lgpl'
gmake[1]: *** [tier_1] Error 2

This happened to anyone else?

Revelant USE: "+crypt -debug -gtk2 +java -ldap -moznoxft +mozsvg -xinerama -xprint"

/var/tmp/portage/mozilla-thunderbird-0.7.3/work/mozilla/other-licenses/libart-lgpl is empty for me.

------- Comment #18 From Tom Martin (RETIRED) 2004-08-05 13:10:10 0000 -------
mozilla-firefox and mozilla-firefox-bin 0.9.3 now stable on amd64.. Thunderbird
can wait till I find out what happened with the error up <a
href="http://bugs.gentoo.org/show_bug.cgi?id=59419#c17">here</a>.

------- Comment #19 From Gustavo Zacarias (RETIRED) 2004-08-05 13:32:12 0000 -------
mozilla-firefox-0.9.3 sparc stable.
mozilla-thunderbird-0.7.3 sparc stable thanks to squash.
now waiting for moz 1.7.2.

------- Comment #20 From Joe Jezak 2004-08-05 13:52:53 0000 -------
Same result as Comment #17 on ppc with gcc-3.4.1.

------- Comment #21 From Aron Griffis (RETIRED) 2004-08-05 19:29:42 0000 -------
Slarti, the thunderbird problem you mentioned was bug 59521.  It's fixed now.

------- Comment #22 From Dan Margolis (RETIRED) 2004-08-05 22:11:11 0000 -------
GLSA drafted

------- Comment #23 From Thierry Carrez (RETIRED) 2004-08-06 02:18:56 0000 -------
Back to upstream status waiting for a fix in the 1.7.2 sources bug :
http://bugzilla.mozilla.org/show_bug.cgi?id=254346

------- Comment #24 From Thierry Carrez (RETIRED) 2004-08-06 02:26:08 0000 -------
Link to security fixes, for reference :
http://www.mozilla.org/projects/security/known-vulnerabilities.html

------- Comment #25 From Tom Martin (RETIRED) 2004-08-06 04:06:11 0000 -------
mozilla-thunderbird-0.7.3 now stable on amd64, that's amd64 done for now.

------- Comment #26 From Dan Christensen 2004-08-07 10:00:19 0000 -------
Getting odd errors when clicking on links for files (non-web pages) causes an
odd 'Gecko' titled error dialogs:
XML Parsing Error: not well-formed
Location: chrome://mozapps/content/downloads/unknownContentType.xul
Line Number 1, Column 1:
(2 blank lines)
^
(the carat is red, and like it should point to some code, but is blank)

Sorry if this is in the wrong place.

------- Comment #27 From Oliver Schoett 2004-08-08 01:15:51 0000 -------
The 1.7.2 Mozilla sources have been fixed upstream (Bug
http://bugzilla.mozilla.org/show_bug.cgi?id=254346 has been closed).

------- Comment #28 From Sune Kloppenborg Jeppesen 2004-08-08 12:13:04 0000 -------
Upstream fixed tarballs for Mozilla 1.7.2 back to stable.

------- Comment #29 From Sune Kloppenborg Jeppesen 2004-08-08 12:28:39 0000 -------
Sorry back to ebuild. Still no mozilla ebuild.

------- Comment #30 From Aron Griffis (RETIRED) 2004-08-08 12:58:14 0000 -------
mozilla-1.7.2 is now in portage

------- Comment #31 From Sune Kloppenborg Jeppesen 2004-08-08 13:15:43 0000 -------
Now we have a ebuild for mozilla-1.7.2 to mark stable.

------- Comment #32 From Tom Martin (RETIRED) 2004-08-08 16:58:02 0000 -------
Stable on amd64.

------- Comment #33 From Jason Wever (RETIRED) 2004-08-09 05:27:44 0000 -------
Stable on sparc.

------- Comment #34 From Gustavo Zacarias (RETIRED) 2004-08-09 07:02:04 0000 -------
Please note that at least for sparc epiphany-1.2.7 was bumped to stable since
1.2.6 didn't build against mozilla-1.7.2.

------- Comment #35 From Tim Leslie 2004-08-10 16:17:45 0000 -------
Epiphany and other variant packages should be updated to reflect new version to
allow proper emerges of those packages (they currently break).

------- Comment #36 From Pieter Van den Abeele 2004-08-12 13:01:09 0000 -------
stable on ppc

------- Comment #37 From Bryan Østergaard (RETIRED) 2004-08-13 02:45:33 0000 -------
Stable on alpha.

------- Comment #38 From Robert Davis 2004-08-13 14:39:09 0000 -------
I am getting nsIJVMManager.h: No such file or directory now trying to build
galeon.  Is that another file missing from Mozilla?

------- Comment #39 From Robert Davis 2004-08-13 15:12:03 0000 -------
Hmm. My bad.  Somehow I don't have USE="java".  Either I lost it or now the oji
stuff isn't loaded if you don't have it.

------- Comment #40 From Sune Kloppenborg Jeppesen 2004-08-14 11:54:14 0000 -------
ppc x86 please mark mozilla-1.7.2 stable asap.

------- Comment #41 From Pieter Van den Abeele 2004-08-14 12:00:24 0000 -------
stable on ppc

------- Comment #42 From Tim Yamin (RETIRED) 2004-08-14 15:11:33 0000 -------
Stable on x86.

------- Comment #43 From Dan Margolis (RETIRED) 2004-08-16 10:57:11 0000 -------
It appears Epiphany and Galeon (and any other gecko-based browsers?) may also
be vulnerable to some of these issues (see
http://www.slackware.com/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.667659,
https://rhn.redhat.com/errata/RHSA-2004-421.html). 

Mozilla herd: can you confirm that this bug affects these packages? If so, can
you fix the RDEPEND so that they build against the new patched versions of
Mozilla?

------- Comment #44 From Aron Griffis (RETIRED) 2004-08-18 12:52:47 0000 -------
You're right, galeon and epiphany would be affected.  However the mozilla team
doesn't touch those packages.  The gnome team should update the depends.

------- Comment #45 From foser (RETIRED) 2004-08-18 13:59:17 0000 -------
we'll fix epiphany-1.2.7 to dep hard on moz-1.7.2, needs a bump because it's
already stable on an arch. I'll let you know in a second when epiphany-1.2.7-r1
gets added.

Galeon is maintained by hanno, CC-ing

------- Comment #46 From foser (RETIRED) 2004-08-18 14:05:58 0000 -------
epiphany-1.2.7-r1 added & stable on x86 + sparc

hanno on CC for fixing galeon

------- Comment #47 From Pieter Van den Abeele 2004-08-18 18:22:50 0000 -------
epiphany stable on ppc.

please add ppc again when galeon needs testing.

------- Comment #48 From Sune Kloppenborg Jeppesen 2004-08-23 06:44:01 0000 -------
GLSA 200408-22

hanno please fix galeon

------- Comment #49 From Joshua J. Berry (CondorDes) (RETIRED) 2004-08-24 11:41:33 0000 -------
I recommend we strip the relevant bullet point from the GLSA, but do not
reissue.

----------
Subject: [Full-Disclosure] RE: [ GLSA 200408-22 ] Mozilla, Firefox,
Thunderbird: New releases fix vulnerabilities
Date: Tuesday 24 August 2004 11:04
From: Gervase Markham <gerv@gerv.net>
To: klieber@gentoo.org
Cc: bugtraq@securityfocus.com;, full-disclosure@lists.netsys.com;,
security-alerts@linuxsecurity.com

As has been pointed out to the author of the relevant "advisory" several
times, Mozilla has neither a "local zone" nor "predictable cache file
locations". The author assumed that the random string generated for his
cache file location was the same as everyone else's.

I wonder how Gentoo can have fixed, QAed and tested the fix for a
vulnerability which doesn't exist?

(Note: none of the referenced CVE numbers in the advisory refer to this
"issue".)

Gerv

------- Comment #50 From Joshua J. Berry (CondorDes) (RETIRED) 2004-08-24 11:43:22 0000 -------
ooh.  I forgot to mention that when I went back and looked, I couldn't find any
reference to the file cache vulnerabilities referenced in the GLSA, either on
Mozilla's website or in any of the CVEs.  So I think it's fairly safe to assume
he's right and the vulnerability doesn't exist.

------- Comment #51 From Sune Kloppenborg Jeppesen 2004-08-24 12:27:48 0000 -------
GLSA updated and not reissued.

------- Comment #52 From Hanno Boeck 2004-08-24 13:45:20 0000 -------
galeon-1.3.17 added and depends on >=mozilla-1.7.2-r1

------- Comment #53 From Danny van Dyk (RETIRED) 2004-08-25 13:24:35 0000 -------
Removing amd64@g.o from cc

------- Comment #54 From Bryan Østergaard (RETIRED) 2004-08-25 16:50:38 0000 -------
Galeon stable on alpha.

------- Comment #55 From Sune Kloppenborg Jeppesen 2004-08-28 15:56:43 0000 -------
Arches please mark Galeon 1.3.17 stable.

------- Comment #56 From Pieter Van den Abeele 2004-08-28 16:31:12 0000 -------
stable on ppc

------- Comment #57 From Gustavo Zacarias (RETIRED) 2004-08-31 14:17:45 0000 -------
sparc was done but not removed, removing...

------- Comment #58 From Thierry Carrez (RETIRED) 2004-09-02 06:44:39 0000 -------
amd64: please mark galeon-1.3.17 stable

------- Comment #59 From Danny van Dyk (RETIRED) 2004-09-02 13:15:27 0000 -------
galeon-1.3.17 marked stable on amd64.

------- Comment #60 From Thierry Carrez (RETIRED) 2004-09-02 13:39:49 0000 -------
Ready for a Galeon/Epiphany GLSA... Or an update of the other one

------- Comment #61 From Sune Kloppenborg Jeppesen 2004-09-03 02:52:02 0000 -------
Thx everybody.

GLSA 200408-22 updated and reissued

------- Comment #62 From Danny van Dyk (RETIRED) 2006-05-31 07:52:30 0000 -------
GLSA 200408-22 contains format bug:
    <package name="net-www/epiphany" auto="yes" arch="*">
      <unaffected range="ge">1.2.7-r1</unaffected>
      <vulnerable range="lt"> 1.2.7-r1</vulnerable>
    </package>
Please remove the space before the version-spec in vulnerable tag.

------- Comment #63 From Stefan Cornelius (RETIRED) 2006-05-31 07:58:00 0000 -------
Thanks, fixed in CVS

------- Comment #64 From Thierry Carrez (RETIRED) 2006-05-31 10:17:14 0000 -------
and closed again

First Last Prev Next    No search results available      Search page      Enter new bug