Bug 210260 - www-client/opera < 9.26 multiple vulnerabilities (CVE-2008-{1080,1081,1082})
|
Bug#:
210260
(CVE-2008-1080)
|
Product: Gentoo Security
|
Version: unspecified
|
Platform: All
|
|
OS/Version: Linux
|
Status: RESOLVED
|
Severity: minor
|
Priority: P2
|
|
Resolution: FIXED
|
Assigned To: security@gentoo.org
|
Reported By: jer@gentoo.org
|
|
Component: Vulnerabilities
|
|
|
URL:
http://secunia.com/advisories/29029/
|
|
Summary: www-client/opera < 9.26 multiple vulnerabilities (CVE-2008-{1080,1081,1082})
|
|
Keywords:
|
|
Status Whiteboard: B3 [glsa]
|
|
Opened: 2008-02-15 17:14 0000
|
No 9.26 build is available yet, no published vulnerability either, it seems.
Quote from the URL:
"We are also addressing a few security issues; details will be
published in due time."
(In reply to comment #2)
> File is already available (though not announced) on:
> ftp://get.opera.com/pub/opera/linux/926/final/
Thanks for noticing.
> Haven't found a ChangeLog yet, but one could prepare an ebuild
Sure I could, put I won't put it in the tree until it's mirrored.
www-client/opera-9.26 is in the tree.
Arches please test and mark stable. Target keywords are:
opera-9.26.ebuild:KEYWORDS="amd64 ppc sparc x86 ~x86-fbsd"
details are out, no major issues.
This one is ready for GLSA vote.
Fixed in release snapshot.
Thx for the info rbu.
GLSA request filed.
Name: CVE-2008-1080
Opera before 9.26 allows user-assisted remote attackers to read
arbitrary files by tricking a user into typing the characters of the
target filename into a file input.
======================================================
Name: CVE-2008-1081
Opera before 9.26 allows user-assisted remote attackers to execute
arbitrary script via images that contain custom comments, which are
treated as script when the user displays the image properties.
======================================================
Name: CVE-2008-1082
Opera before 9.26 allows remote attackers to "bypass sanitization
filters" and conduct cross-site scripting (XSS) attacks via crafted
attribute values in an XML document, which are not properly handled
during DOM presentation.