<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>226079</bug_id>
          
          <creation_ts>2008-06-12 14:29 0000</creation_ts>
          <short_desc>www-client/opera &lt;9.50 - Multiple vulnerabilities (CVE-2008-{2714,2715,2716})</short_desc>
          <delta_ts>2008-06-23 11:54:29 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://www.opera.com/docs/changelogs/linux/950/#security</bug_file_loc>
          <status_whiteboard>B3 [noglsa]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>minor</bug_severity>
          <target_milestone>---</target_milestone>
          <dependson>226139</dependson>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>jer@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          

      

      
          <long_desc isprivate="0">
            <who>jer@gentoo.org</who>
            <bug_when>2008-06-12 14:29:01 0000</bug_when>
            <thetext>Advisories:
http://www.opera.com/support/search/view/878/
http://www.opera.com/support/search/view/883/
http://www.opera.com/support/search/view/885/

From the [URL]:
* Fixed an issue where certain characters could obscure the page address, as reported by Tony Thomas. See our advisory.
* Solved an issue where Images could be read cross-domain with canvas, as reported by Philip Taylor. See our advisory.
* Pages held in frames are no longer able to change the location of pages in unrelated frames on the parent page. See our advisory.
* Improved Fraud Protection now includes advanced malware prevention and upgraded phishing detection technologies. See article: Opera Fraud Protection.
* Added support for Extended Validation (EV) certificates.
* Added automatic downloading of trusted root certificates when required.
* Disabled SSL v2 and weak ciphers.
* Improvements made to certificate handling, the new certificate repository and the certificates UI.
* Introduced a new security notification scheme in the address field: 
  + black padlock with a check mark on green field for secure sites with Extended Validation
  + black padlock without a check mark on yellow field for regular secure sites
question mark on gray field for HTTPS sites with issues
  + no notification for normal sites
  + fraud warning on red field for blacklisted sites
* Opera now distinguishes between local servers on localhost, intranet servers, and remote servers on the Internet. 
* Local servers can use remote resources, but not vice versa.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jer@gentoo.org</who>
            <bug_when>2008-06-12 14:31:08 0000</bug_when>
            <thetext>Oh, and it&apos;s in the tree. This should be as easy as a call for stabilisation from amd64, ppc, x86 and x86-fbsd. :)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-06-12 15:00:08 0000</bug_when>
            <thetext>Arches, please test and mark stable:
=www-client/opera-9.50
Target keywords : &quot;amd64 ppc release sparc x86&quot;</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-06-12 15:01:22 0000</bug_when>
            <thetext>(In reply to comment #0)
&gt; http://www.opera.com/support/search/view/878/

According to the description, this issue has been addressed in 9.26 already, so it does not affect our stable.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>fauli@gentoo.org</who>
            <bug_when>2008-06-13 06:50:00 0000</bug_when>
            <thetext>x86 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>armin76@gentoo.org</who>
            <bug_when>2008-06-13 09:43:46 0000</bug_when>
            <thetext>Opera dropped support for sparc, so nothing we can do about it.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dertobi123@gentoo.org</who>
            <bug_when>2008-06-13 15:04:21 0000</bug_when>
            <thetext>ppc stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ken69267@gentoo.org</who>
            <bug_when>2008-06-13 15:35:09 0000</bug_when>
            <thetext>amd64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-06-14 14:26:38 0000</bug_when>
            <thetext>(In reply to comment #5)
&gt; Opera dropped support for sparc, so nothing we can do about it.

In which case we should either p.mask the old Opera releases on sparc, or drop their sparc keywords.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jer@gentoo.org</who>
            <bug_when>2008-06-15 21:30:40 0000</bug_when>
            <thetext>(In reply to comment #8)
&gt; (In reply to comment #5)
&gt; &gt; Opera dropped support for sparc, so nothing we can do about it.
&gt; 
&gt; In which case we should either p.mask the old Opera releases on sparc, or drop
&gt; their sparc keywords.

It&apos;s a closed source package, so keywords are added and dropped as versions per architecture are available. I have no opinion on whether to keep 9.27 p.masked and with all keywords except sparc dropped. SPARC team should decide about this.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>pva@gentoo.org</who>
            <bug_when>2008-06-16 16:43:40 0000</bug_when>
            <thetext>Fixed in release snapshot.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>armin76@gentoo.org</who>
            <bug_when>2008-06-17 09:54:08 0000</bug_when>
            <thetext>Okay, feel free to p.mask it and keep the sparc keyword.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jer@gentoo.org</who>
            <bug_when>2008-06-17 15:28:26 0000</bug_when>
            <thetext>(In reply to comment #11)
&gt; Okay, feel free to p.mask it and keep the sparc keyword.

It is done. Now is the time for sparc workstation users to ask Opera, Inc. loudly to support their arch again. :)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-06-18 23:19:25 0000</bug_when>
            <thetext>GLSA vote, I vote NO.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vorlon@gentoo.org</who>
            <bug_when>2008-06-23 11:54:29 0000</bug_when>
            <thetext>agreed -&gt; noglsa</thetext>
          </long_desc>
      
    </bug>

</bugzilla>