Bug 210260 - www-client/opera < 9.26 multiple vulnerabilities (CVE-2008-{1080,1081,1082})
Bug#: 210260 (CVE-2008-1080) Product:  Gentoo Security Version: unspecified Platform: All
OS/Version: Linux Status: RESOLVED Severity: minor Priority: P2
Resolution: FIXED Assigned To: security@gentoo.org Reported By: jer@gentoo.org
Component: Vulnerabilities
URL:  http://secunia.com/advisories/29029/
Summary: www-client/opera < 9.26 multiple vulnerabilities (CVE-2008-{1080,1081,1082})
Keywords:  
Status Whiteboard: B3 [glsa]
Opened: 2008-02-15 17:14 0000
Description:   Opened: 2008-02-15 17:14 0000
No 9.26 build is available yet, no published vulnerability either, it seems.

------- Comment #1 From Jeroen Roovers 2008-02-15 17:15:00 0000 -------
Quote from the URL:
  "We are also addressing a few security issues; details will be
   published in due time."

------- Comment #2 From Christian Faulhammer 2008-02-19 19:52:03 0000 -------
File is already available (though not announced) on:
ftp://get.opera.com/pub/opera/linux/926/final/

Haven't found a ChangeLog yet, but one could prepare an ebuild

------- Comment #3 From Jeroen Roovers 2008-02-20 05:56:07 0000 -------
(In reply to comment #2)
> File is already available (though not announced) on:
> ftp://get.opera.com/pub/opera/linux/926/final/

Thanks for noticing.

> Haven't found a ChangeLog yet, but one could prepare an ebuild

Sure I could, put I won't put it in the tree until it's mirrored.

------- Comment #4 From Jeroen Roovers 2008-02-20 13:54:50 0000 -------
www-client/opera-9.26 is in the tree.

------- Comment #5 From Sune Kloppenborg Jeppesen 2008-02-20 13:59:34 0000 -------
Arches please test and mark stable. Target keywords are:

opera-9.26.ebuild:KEYWORDS="amd64 ppc sparc x86 ~x86-fbsd"

------- Comment #6 From Christian Faulhammer 2008-02-20 19:07:54 0000 -------
x86 stable

------- Comment #7 From Raúl Porcel 2008-02-21 12:25:24 0000 -------
sparc stable

------- Comment #8 From Pierre-Yves Rofes 2008-02-21 21:44:42 0000 -------
details are out, no major issues.

------- Comment #9 From Tobias Scherbaum 2008-02-22 14:00:45 0000 -------
ppc stable

------- Comment #10 From Steve Dibb 2008-02-25 19:39:27 0000 -------
amd64 stable

------- Comment #11 From Sune Kloppenborg Jeppesen 2008-02-25 20:18:32 0000 -------
This one is ready for GLSA vote.

------- Comment #12 From Peter Volkov 2008-02-25 20:41:01 0000 -------
Fixed in release snapshot.

------- Comment #13 From Robert Buchholz 2008-02-25 22:24:07 0000 -------
http://www.opera.com/support/search/view/877/
http://www.opera.com/support/search/view/879/
http://www.opera.com/support/search/view/880/

I'd rather go for a YES here.

------- Comment #14 From Sune Kloppenborg Jeppesen 2008-02-26 10:02:56 0000 -------
Thx for the info rbu.

GLSA request filed.

------- Comment #15 From Robert Buchholz 2008-03-03 00:01:48 0000 -------
Name: CVE-2008-1080
Opera before 9.26 allows user-assisted remote attackers to read
arbitrary files by tricking a user into typing the characters of the
target filename into a file input.


======================================================
Name: CVE-2008-1081
Opera before 9.26 allows user-assisted remote attackers to execute
arbitrary script via images that contain custom comments, which are
treated as script when the user displays the image properties.


======================================================
Name: CVE-2008-1082
Opera before 9.26 allows remote attackers to "bypass sanitization
filters" and conduct cross-site scripting (XSS) attacks via crafted
attribute values in an XML document, which are not properly handled
during DOM presentation.

------- Comment #16 From Pierre-Yves Rofes 2008-03-04 22:40:00 0000 -------
GLSA 200803-09