Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 76112
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Dan Margolis (RETIRED) <krispykringle@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 76112 depends on: Show dependency tree
Bug 76112 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2004-12-29 21:43 0000
Sounds like remote code execution if able to trick victim into viewing
page/clicking link. I assume we'll wait for Mozilla to release an update/fix.

------- Comment #1 From Sven Wegener 2004-12-29 22:18:31 0000 -------
Quote:

> Solution
> =========
> 
> This bug is fixed in Mozilla 1.7.5. (Bug 264388)

------- Comment #2 From Thierry Carrez (RETIRED) 2004-12-30 07:37:52 0000 -------
Mozilla 1.7.5 stable process is handled on bug 68976
Any idea if this is present in Thunderbird ?

It's quite difficult to get any confirmation from the Mozilla folks. The security page (http://www.mozilla.org/projects/security/known-vulnerabilities.html) has not been updated since Firefox 1.0PR... And closed-access bugs are everywhere.

If someone from our Mozilla team knows anyone that would help confirming what stuff affects what versions and what is already fixed (basically, an update of the known vuln page), that would help us a lot.

------- Comment #3 From Thierry Carrez (RETIRED) 2005-01-01 11:04:37 0000 -------
https://bugzilla.mozilla.org/show_bug.cgi?id=264388 is not public so I can't
confirm this one.

This should get a GLSA but without confirmation I don't really feel like it.

------- Comment #4 From Sune Kloppenborg Jeppesen 2005-01-04 01:35:48 0000 -------
Mozilla bug opened. I vote for a GLSA on this one.

------- Comment #5 From Thierry Carrez (RETIRED) 2005-01-04 01:40:30 0000 -------
Yes, this should get a GLSA, especially if we add the information on bugs 68976
and 70749.

------- Comment #6 From Thierry Carrez (RETIRED) 2005-01-05 01:11:59 0000 -------
GLSA 200501-03

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug