Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 50857
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Boris <1723542c42148b2fe4af9f7ad1e382b30d4b7fd7@nurfuerspam.de>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
opera-7.50.ebuild.patch opera-7.50.ebuild.patch patch Boris 2004-05-12 09:04 0000 2.46 KB Details | Diff
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 50857 depends on: Show dependency tree
Bug 50857 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2004-05-12 09:03 0000
The final release of Opera 7.50 is out since today. I patched the old
opera-7.50_beta1.ebuild to install the new version.

Currently the main ftp-server is hard to reach, but mirrors are available on
the website.

Reproducible: Always
Steps to Reproduce:
1.
2.
3.

------- Comment #1 From Boris 2004-05-12 09:04:00 0000 -------
Created an attachment (id=31273) [details]
opera-7.50.ebuild.patch

------- Comment #2 From Carsten Lohrke 2004-05-13 06:15:58 0000 -------
*** Bug 50920 has been marked as a duplicate of this bug. ***

------- Comment #3 From Carsten Lohrke 2004-05-13 06:18:29 0000 -------
Opera Telnet URI Handler File Creation/Truncation Vulnerability
http://www.idefense.com/application/poi/display?id=104&type=vulnerabilities&flashstatus=true

------- Comment #4 From Boris 2004-05-13 10:28:13 0000 -------
An addition to the vulnerability:

The bug is fixed since opera-7.50_beta1.
See the change Changelog for this http://www.opera.com/windows/changelogs/750b1/

------- Comment #5 From Johnny Franz 2004-05-14 08:34:32 0000 -------
Please please bump.

------- Comment #6 From Heinrich Wendel (RETIRED) 2004-05-14 13:49:26 0000 -------
already bumped it, forgot to make a change to the bug ;)

------- Comment #7 From Thierry Carrez (RETIRED) 2004-05-15 00:31:01 0000 -------
Reopened as a security bug to treat the Opera Telnet URI Handler File
Creation/Truncation Vulnerability in v <= 7.50 GLSA.

amd64 : please add ~amd64
sparc : please mark stable

------- Comment #8 From Jason Wever (RETIRED) 2004-05-15 08:46:56 0000 -------
Opera-7.50 complains on both x86 and sparc that it cannot find a spellcheck.so
to load when it starts (this library is provided by opera).  It doesn't appear
to effect the browser itself much as you can still run it, but I haven't tested
the mail components.  Do we want to try and fix this now or after the GLSA?

------- Comment #9 From Jason Wever (RETIRED) 2004-05-22 16:32:35 0000 -------
So do we care that opera cannot load the spellcheck library or not?

------- Comment #10 From Thierry Carrez (RETIRED) 2004-05-23 03:41:03 0000 -------
Heinrich: could you look into the spellcheck.so problem ?

If it's an easy fix, it would probably be better to have it in. If it's not, we'll probably mark stable this version so taht the GLSA can get out...

------- Comment #11 From Heinrich Wendel (RETIRED) 2004-05-24 05:30:11 0000 -------
since it is an configuration issue and another bug is open for it, we can close
this one if the other arches mark 7.50 stable

------- Comment #12 From Thierry Carrez (RETIRED) 2004-05-24 12:43:35 0000 -------
sparc : please retest with 7.50-r1 and mark stable, the spellcheck issue should
be solved (see bug #51183).

Removing ppc and amd64 from Cc: since no stable flags are needed from them.

------- Comment #13 From Jason Wever (RETIRED) 2004-05-24 19:17:26 0000 -------
Marked stable on sparc.

------- Comment #14 From Thierry Carrez (RETIRED) 2004-05-25 01:06:13 0000 -------
Thanks Jason !
This one is ready for a GLSA.

------- Comment #15 From Kurt Lieber 2004-05-25 08:58:36 0000 -------
glsa 200405-19

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug