Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 96273 - www-client/opera: version 8.02 includes security fixes
Summary: www-client/opera: version 8.02 includes security fixes
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: x86 All
: High minor (vote)
Assignee: Gentoo Security
URL: http://www.opera.com/linux/changelogs...
Whiteboard: B4 [noglsa] jaervosz
Keywords:
: 96683 100591 101986 (view as bug list)
Depends on: 96365
Blocks:
  Show dependency tree
 
Reported: 2005-06-16 05:56 UTC by Max Lorenz
Modified: 2005-08-15 10:22 UTC (History)
4 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Max Lorenz 2005-06-16 05:56:54 UTC
Namely:
http://secunia.com/advisories/15008/
http://secunia.com/advisories/15411/
http://secunia.com/advisories/15423/
http://secunia.com/advisories/13253/

See changelog for more complete information:
http://www.opera.com/linux/changelogs/801/

Thanks, Max

Reproducible: Always
Steps to Reproduce:
1.
2.
3.
Comment 1 Heinrich Wendel (RETIRED) gentoo-dev 2005-06-16 07:36:10 UTC
bumped and stable on x86 and amd64, ppc please test 
Comment 2 Heinrich Wendel (RETIRED) gentoo-dev 2005-06-17 08:29:19 UTC
there is a problem on x86, see bug #96365, masking again for x86 
Comment 3 Thierry Carrez (RETIRED) gentoo-dev 2005-06-21 13:30:09 UTC
Note: this also fixes :
http://secunia.com/advisories/15488/
Comment 4 Thierry Carrez (RETIRED) gentoo-dev 2005-06-21 13:30:46 UTC
*** Bug 96683 has been marked as a duplicate of this bug. ***
Comment 5 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-06-23 05:19:21 UTC
Heinrich any news on this one? 
Comment 6 Heinrich Wendel (RETIRED) gentoo-dev 2005-06-23 10:30:51 UTC
8.01 only works on nptl enabled systems 
Comment 7 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-06-23 12:22:48 UTC
Thx Heinrich, back to upstream. 
Comment 8 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-07-05 01:53:50 UTC
Heinrich any news on this one? 
Comment 9 Thierry Carrez (RETIRED) gentoo-dev 2005-07-29 00:52:59 UTC
8.02 is out, fixing the following extra lame Secunia findings :

    * Solved download dialog spoofing issue described in Secunia Advisory SA15870
    * Fixed image dragging issue described in Secunia Advisory SA15756
    * Prevented link hijacking issue described in Secunia Advisory SA15781 

Not sure it fixes the NPTL problem though. If it doesn't, it means they don't
consider it a bug...

Heinrich, please advise.
Comment 10 Thierry Carrez (RETIRED) gentoo-dev 2005-07-29 00:53:37 UTC
*** Bug 100591 has been marked as a duplicate of this bug. ***
Comment 11 Thierry Carrez (RETIRED) gentoo-dev 2005-07-30 07:25:01 UTC
Looks like 8.02 is still nptl only. Not sure how we can get around this.
Comment 12 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-07-31 12:51:03 UTC
Heinrich any advise? 
Comment 13 Heinrich Wendel (RETIRED) gentoo-dev 2005-08-04 01:32:46 UTC
added 8.02, no advice though 
Comment 14 Thierry Carrez (RETIRED) gentoo-dev 2005-08-04 04:59:10 UTC
According to upstream, 8.02 should be fixed to run on non-nptl systems. Let's
keep it in ~ a little before calling arch testers to mark stable.
Comment 15 Thierry Carrez (RETIRED) gentoo-dev 2005-08-10 01:42:39 UTC
I guess it's ready for stable testing.
Arches, please test and mark stable if you can.
Comment 16 Simon Stelling (RETIRED) gentoo-dev 2005-08-10 08:03:21 UTC
*** Bug 101986 has been marked as a duplicate of this bug. ***
Comment 17 Simon Stelling (RETIRED) gentoo-dev 2005-08-10 08:08:44 UTC
stable on amd64
Comment 18 Gustavo Zacarias (RETIRED) gentoo-dev 2005-08-10 08:14:05 UTC
sparc stable.
Comment 19 Olivier Crete (RETIRED) gentoo-dev 2005-08-10 17:00:39 UTC
x86 stable
Comment 20 Thierry Carrez (RETIRED) gentoo-dev 2005-08-11 00:35:11 UTC
Is it worth a GLSA ?
The 8.02 fixes probably don't, but the 8.01 ones could...
Comment 21 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-08-15 09:54:29 UTC
I tend to vote NO. 
Comment 22 Tavis Ormandy (RETIRED) gentoo-dev 2005-08-15 09:59:02 UTC
also vote NO
Comment 23 Stefan Cornelius (RETIRED) gentoo-dev 2005-08-15 10:06:05 UTC
i'd say no, too.
Comment 24 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-08-15 10:22:15 UTC
Closing without GLSA. Feel free to reopen if you disagree.