<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>214816</bug_id>
          
          <creation_ts>2008-03-26 01:51 0000</creation_ts>
          <short_desc>mozilla-firefox &lt;2.0.0.13, mozilla-thunderbird &lt;2.0.0.14, seamonkey &lt;1.1.9,  xulrunner &lt;1.8.1.13 Multiple vulnerabilites (CVE-2007-4879, CVE-2008-{1233,1234,1235,1236,1237,1238,1240,1241})</short_desc>
          <delta_ts>2008-05-20 21:20:14 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://www.mozilla.org/projects/security/known-vulnerabilities.html#firefox2.0.0.13</bug_file_loc>
          <status_whiteboard>A2 [glsa]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>rbu@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>7v5w7go9ub0o@gmail.com</cc>
    
    <cc>arm@gentoo.org</cc>
    
    <cc>mozilla@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-03-26 01:51:10 0000</bug_when>
            <thetext>Firefox 2.0.0.13 is out, security fixes as usual.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>michael.schachtebeck@gmx.de</who>
            <bug_when>2008-03-26 09:36:30 0000</bug_when>
            <thetext>2.0.0.13 fixes (among others) 2 critical vulnerabilities, see http://www.mozilla.org/projects/security/known-vulnerabilities.html#firefox2.0.0.13.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>armin76@gentoo.org</who>
            <bug_when>2008-03-26 13:54:30 0000</bug_when>
            <thetext>=www-client/mozilla-firefox[-bin]-2.0.0.13
=net-libs/xulrunner-1.8.1.13
=www-client/seamonkey[-bin]-1.1.9

in the tree</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-03-26 20:49:56 0000</bug_when>
            <thetext>Arches, please test and mark stable:
=www-client/mozilla-firefox-2.0.0.13
Target keywords : &quot;alpha amd64 arm hppa ia64 ppc ppc64 release sparc x86&quot;

=www-client/mozilla-firefox-bin-2.0.0.13
Target keywords : &quot;amd64 release x86&quot;

=www-client/seamonkey-1.1.9
Target keywords : &quot;alpha amd64 arm hppa ia64 ppc ppc64 release sparc x86&quot;

=www-client/seamonkey-bin-1.1.9
Target keywords : &quot;amd64 release x86&quot;

=net-libs/xulrunner-1.8.1.13
Target keywords : &quot;alpha amd64 arm hppa ia64 ppc ppc64 release sparc x86&quot;</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-03-26 20:51:53 0000</bug_when>
            <thetext>Raul, please note that as long as it&apos;s not p.masked, xulrunner-bin also needs to be upgraded.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>maekke@gentoo.org</who>
            <bug_when>2008-03-27 00:03:23 0000</bug_when>
            <thetext>amd64/x86 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-03-27 02:12:05 0000</bug_when>
            <thetext>(In reply to comment #4)
&gt; Raul, please note that as long as it&apos;s not p.masked, xulrunner-bin also needs
&gt; to be upgraded.

*xulrunner-bin-1.8.1.13 (26 Mar 2008)

  26 Mar 2008; Raúl Porcel &lt;armin76@gentoo.org&gt;
  xulrunner-bin-1.8.1.12.ebuild, +xulrunner-bin-1.8.1.13.ebuild:
  Version bump
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>armin76@gentoo.org</who>
            <bug_when>2008-03-27 12:26:22 0000</bug_when>
            <thetext>alpha/ia64/sparc stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ranger@gentoo.org</who>
            <bug_when>2008-03-27 16:42:07 0000</bug_when>
            <thetext>ppc and ppc64 done</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-03-27 20:46:18 0000</bug_when>
            <thetext>
Description:
CVE-2008-1233 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1233):
  Unspecified vulnerability in Mozilla Firefox before 2.0.0.13, Thunderbird
  before 2.0.0.13, and SeaMonkey before 1.1.9 allows remote attackers to
  execute arbitrary code via &quot;XPCNativeWrapper pollution.&quot;

CVE-2008-1234 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1234):
  Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0.0.13,
  Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9 allows remote
  attackers to inject arbitrary web script or HTML via event handlers, aka
  &quot;Universal XSS using event handlers.&quot;

CVE-2008-1235 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1235):
  Unspecified vulnerability in Mozilla Firefox before 2.0.0.13, Thunderbird
  before 2.0.0.13, and SeaMonkey before 1.1.9 allows remote attackers to
  execute arbitrary code via unknown vectors that cause JavaaScript to execute
  with the wrong principal, aka &quot;Privilege escalation via incorrect principals.&quot;

CVE-2008-1236 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1236):
  Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.13,
  Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9 allow remote
  attackers to cause a denial of service (crash) and possibly execute arbitrary
  code via unknown vectors related to the layout engine.

CVE-2008-1237 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1237):
  Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.13,
  Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9 allow remote
  attackers to cause a denial of service (crash) and possibly execute arbitrary
  code via unknown vectors related to the JavaScript engine.

CVE-2008-1238 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1238):
  Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9, when generating
  the HTTP Referer header, does not list the entire URL when it contains Basic
  Authentication credentials without a username, which makes it easier for
  remote attackers to bypass application protection mechanisms that rely on
  Referer headers, such as with some Cross-Site Request Forgery (CSRF)
  mechanisms.

CVE-2008-1241 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1241):
  GUI overlay vulnerability in Mozilla Firefox before 2.0.0.13 and SeaMonkey
  before 1.1.9 allows remote attackers to spoof form elements and redirect user
  inputs via a borderless XUL pop-up window from a background tab.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jer@gentoo.org</who>
            <bug_when>2008-03-28 05:03:21 0000</bug_when>
            <thetext>Marked stable for HPPA:
  =www-client/mozilla-firefox-2.0.0.13
  =net-libs/xulrunner-1.8.1.13
  =www-client/seamonkey-1.1.9

None of these passes the Acid3 test, btw. ;-)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>pva@gentoo.org</who>
            <bug_when>2008-03-28 08:09:28 0000</bug_when>
            <thetext>Fixed in release snapshot.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-03-29 19:48:52 0000</bug_when>
            <thetext>GLSA is filed, waiting for Thunderbird :-/</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>caster@gentoo.org</who>
            <bug_when>2008-05-01 23:07:25 0000</bug_when>
            <thetext>*** Bug 219983 has been marked as a duplicate of this bug. ***</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-05-02 09:36:13 0000</bug_when>
            <thetext>As pointed out in the duplicate (see comment 13), Thunderbird 2.0.0.14 has been released.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>armin76@gentoo.org</who>
            <bug_when>2008-05-02 14:28:43 0000</bug_when>
            <thetext>mail-client/mozilla-thunderbird[-bin]-2.0.0.14 in the tree</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>keytoaster@gentoo.org</who>
            <bug_when>2008-05-03 10:47:10 0000</bug_when>
            <thetext>Arches, please test and mark stable:
=mozilla-thunderbird-2.0.0.14
Target keywords: &quot;alpha amd64 ia64 ppc ppc64 release sparc x86&quot;

=mozilla-thunderbird-bin-2.0.0.14
Target keywords: &quot;amd64 release x86&quot;</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>hanno@gentoo.org</who>
            <bug_when>2008-05-03 23:30:21 0000</bug_when>
            <thetext>CC-in archs for thunderbird stabilization.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>maekke@gentoo.org</who>
            <bug_when>2008-05-04 13:30:12 0000</bug_when>
            <thetext>amd64/x86 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>armin76@gentoo.org</who>
            <bug_when>2008-05-04 13:44:16 0000</bug_when>
            <thetext>alpha/ia64/sparc stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>corsair@gentoo.org</who>
            <bug_when>2008-05-05 11:48:50 0000</bug_when>
            <thetext>ppc64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ranger@gentoo.org</who>
            <bug_when>2008-05-05 14:08:11 0000</bug_when>
            <thetext>ppc done</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-05-20 21:20:14 0000</bug_when>
            <thetext>GLSA 200805-18, sorry for the delay</thetext>
          </long_desc>
      
    </bug>

</bugzilla>