Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 83267
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Thierry Carrez (RETIRED) <koon@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 83267 depends on: Show dependency tree
Bug 83267 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2005-02-25 00:44 0000
Creating this bug as a metabug for all vulnerabilities fixed in the latest
Mozilla releases, we will mark other Mozilla vulnerability bugs as dupes of
this one as soon as we confirm they are fixed in these.

Currently out : Firefox 1.0.1
Mozilla team : please provide ebuilds for FF 1.0.1

------- Comment #1 From Thierry Carrez (RETIRED) 2005-02-25 00:53:32 0000 -------
Bugs that /should/ be fixed are :

Bug 73870 : Window Injection Vulnerability
Bug 76616 : Download Dialog Source Spoofing
Bug 81307 : Dragging Multiple vulnerabilities
Bug 81011 : Local users can delete the files of mozilla users
Bug 81113 : IDN Spoofing Security Issue (CAN-2005-0233)

Mozilla known vulnerabilities page is still not updated.

------- Comment #2 From Thierry Carrez (RETIRED) 2005-02-25 08:30:43 0000 -------
Fixed in Firefox 1.0.1 :

MFSA 2005-29 Internationalized Domain Name (IDN) homograph spoofing (Gentoo bug 81113)
MFSA 2005-28 Unsafe /tmp/plugtmp directory exploitable to erase user's files (Gentoo bug 81011)
MFSA 2005-27 Plugins can be used to load privileged content (CAN-2005-0527) (Gentoo bug 81307)
MFSA 2005-26 Cross-site scripting by dropping javascript: link on tab (Gentoo bug 81307)
MFSA 2005-25 Image drag and drop executable spoofing (Gentoo bug 81307)
MFSA 2005-24 HTTP auth prompt tab spoofing
MFSA 2005-23 Download dialog source spoofing (Gentoo bug 76616)
MFSA 2005-22 Download dialog spoofing using Content-Disposition header
MFSA 2005-21 Overwrite arbitrary files downloading .lnk twice
MFSA 2005-20 XSLT can include stylesheets from arbitrary hosts
MFSA 2005-19 Autocomplete data leak
MFSA 2005-18 Memory overwrite in string library
MFSA 2005-17 Install source spoofing with user:pass@host
MFSA 2005-16 Spoofing download and security dialogs with overlapping windows (Gentoo bug 81307)
MFSA 2005-15 Heap overflow possible in UTF8 to Unicode conversion
MFSA 2005-14 SSL "secure site" indicator spoofing
MFSA 2005-13 Window Injection Spoofing (CAN-2004-1156) (Gentoo bug 73870)

------- Comment #3 From Thierry Carrez (RETIRED) 2005-02-25 08:31:36 0000 -------
*** Bug 73870 has been marked as a duplicate of this bug. ***

------- Comment #4 From Thierry Carrez (RETIRED) 2005-02-25 08:31:49 0000 -------
*** Bug 76616 has been marked as a duplicate of this bug. ***

------- Comment #5 From Thierry Carrez (RETIRED) 2005-02-25 08:32:06 0000 -------
*** Bug 81307 has been marked as a duplicate of this bug. ***

------- Comment #6 From Thierry Carrez (RETIRED) 2005-02-25 08:32:23 0000 -------
*** Bug 81011 has been marked as a duplicate of this bug. ***

------- Comment #7 From Thierry Carrez (RETIRED) 2005-02-25 08:32:41 0000 -------
*** Bug 81113 has been marked as a duplicate of this bug. ***

------- Comment #8 From Brad Laue (RETIRED) 2005-02-26 00:29:30 0000 -------
FF 1.0.1 now in CVS.

------- Comment #9 From Thierry Carrez (RETIRED) 2005-02-28 03:10:50 0000 -------
Arches, please test and mark FireFox 1.0.1 stable

------- Comment #10 From Gustavo Zacarias (RETIRED) 2005-02-28 10:20:29 0000 -------
firefox-1.0.1 stable on sparc.
Keeping us in the bug waiting for tb 1.0.1 & moz 1.7.6 ebuilds.

------- Comment #11 From Thierry Carrez (RETIRED) 2005-02-28 11:25:56 0000 -------
*** Bug 83567 has been marked as a duplicate of this bug. ***

------- Comment #12 From Thierry Carrez (RETIRED) 2005-02-28 11:27:36 0000 -------
MFSA 2005-18 is CAN-2005-0255, credit:Ga

------- Comment #13 From Thierry Carrez (RETIRED) 2005-02-28 11:27:36 0000 -------
MFSA 2005-18 is CAN-2005-0255, credit:Gaƫl Delalleau (Gentoo bug 83567)

------- Comment #14 From Michael Hanselmann (hansmi) (RETIRED) 2005-02-28 14:19:00 0000 -------
Stable on ppc.

------- Comment #15 From Thierry Carrez (RETIRED) 2005-03-01 09:09:03 0000 -------
*** Bug 83696 has been marked as a duplicate of this bug. ***

------- Comment #16 From Jannick Kuhr 2005-03-02 11:17:04 0000 -------
Shouldn't mozilla-firefox-bin be also marked stable?

------- Comment #17 From Thierry Carrez (RETIRED) 2005-03-02 11:49:09 0000 -------
Good point... I was still hoping Mozilla 1.7.6 would go out soon but we should
probably go ahead anyway.

amd64, x86: please test and mark mozilla-firefox-bin-1.0.1 stable.

------- Comment #18 From Simon Stelling (RETIRED) 2005-03-02 12:28:46 0000 -------
firefox-bin and firefox are stable on amd64, waiting for another amd64-dev to
test mozilla and thunderbird

------- Comment #19 From Ian Leitch (RETIRED) 2005-03-03 05:39:22 0000 -------
firefox and -bin are both stable on x86 (marked by Chris White and Brad Laue
respectivley) 

------- Comment #20 From Thierry Carrez (RETIRED) 2005-03-03 06:55:34 0000 -------
Anyone has a clue of when Moz 1.7.6 and TB 1.0.1 will be out ? I need to know
if we should release GLSA now or wait for the others...

------- Comment #21 From Thierry Carrez (RETIRED) 2005-03-04 04:38:12 0000 -------
Creating separate bugs for Mozilla Suite and Thunderbird issues, since they
apparently won't be out very soon.

------- Comment #22 From Thierry Carrez (RETIRED) 2005-03-04 04:48:39 0000 -------
Extra CANs (http://secunia.com/advisories/14407/):

MFSA 2005-28 --> CAN-2005-0578
MFSA 2005-24 --> CAN-2005-0584
MFSA 2005-20 --> CAN-2005-0588
MFSA 2005-19 --> CAN-2005-0589
MFSA 2005-17 --> CAN-2005-0590
MFSA 2005-15 --> CAN-2005-0592
MFSA 2005-14 --> CAN-2005-0593

------- Comment #23 From Thierry Carrez (RETIRED) 2005-03-04 09:13:42 0000 -------
GLSA 200503-10
arm: please mark stable to benefit from GLSA

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug