First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 59503
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Sune Kloppenborg Jeppesen <jaervosz@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 59503 depends on: Show dependency tree
Bug 59503 blocks:
Votes: 0    Show votes for this bug    Vote for this bug

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2004-08-05 04:27 0000
From ChangeLog:

Security:

-Denied write-access to properties on objects from scripts that fail a standard origin check, in order to block potential access by attackers to user's computer. Fixes critical vulnerability reported in GreyMagic Security Advisory GM#008-OP.

-Fixed security issue regarding spoofing of the addressfield by loading other page contents while keeping the URL, reported in Secunia Advisory SA12162.

-Blocked access to file:/ URLs from documents that are not themselves loaded from file:/ URLs.

------- Comment #1 From Sune Kloppenborg Jeppesen 2004-08-05 04:37:44 0000 -------
*** Bug 58511 has been marked as a duplicate of this bug. ***

------- Comment #2 From Sune Kloppenborg Jeppesen 2004-08-05 04:38:09 0000 -------
Heinrich please bump

------- Comment #3 From Heinrich Wendel (RETIRED) 2004-08-05 06:40:26 0000 -------
bumped and marked stable on x86

------- Comment #4 From Sune Kloppenborg Jeppesen 2004-08-05 07:09:07 0000 -------
Thx Heinrich for the quick bump.

amd64, sparc please mark stable

ppc please mark ~ 

------- Comment #5 From Tom Martin (RETIRED) 2004-08-05 09:31:19 0000 -------
Marked stable on amd64.

------- Comment #6 From Gustavo Zacarias (RETIRED) 2004-08-05 10:38:52 0000 -------
Stable on sparc.

------- Comment #7 From Thierry Carrez (RETIRED) 2004-08-05 11:11:18 0000 -------
Keywords all set, ready for a GLSA

------- Comment #8 From Thierry Carrez (RETIRED) 2004-08-05 13:45:34 0000 -------
GLSA 200408-05

First Last Prev Next    No search results available      Search page      Enter new bug