Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 193123 - <www-client/mozilla-firefox[-bin]-2.0.0.7: "-chrome" Parameter Security Issue
Summary: <www-client/mozilla-firefox[-bin]-2.0.0.7: "-chrome" Parameter Security Issue
Status: RESOLVED INVALID
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://secunia.com/advisories/26881/
Whiteboard: B2 []
Keywords:
Depends on:
Blocks:
 
Reported: 2007-09-19 22:16 UTC by Tobias Heinlein (RETIRED)
Modified: 2007-09-24 22:08 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Tobias Heinlein (RETIRED) gentoo-dev 2007-09-19 22:16:20 UTC
Mozilla has acknowledged a security issue in Firefox, which
potentially can be exploited by malicious people to compromise a
user's system.

The security issue is caused due to the "-chrome" parameter allowing
execution of arbitrary Javascript script code in chrome context. This
can be exploited to execute arbitrary commands on a user's system e.g.
via applications invoking Firefox with unfiltered command line
arguments.

The security issue affects Firefox prior to version 2.0.0.7.
Comment 1 Tobias Heinlein (RETIRED) gentoo-dev 2007-09-19 22:19:50 UTC
Version 2.0.0.7 is already in the tree. Mozilla team, is this version ready to be stabilised?
Comment 2 Robert Buchholz (RETIRED) gentoo-dev 2007-09-19 22:42:26 UTC
According to the Mozilla advisory [1], this only affects links opened by QuickTime and therefore not Linux.
Is this an issue for us, too?

[1] http://www.mozilla.org/security/announce/2007/mfsa2007-28.html
Comment 3 Raúl Porcel (RETIRED) gentoo-dev 2007-09-20 09:42:59 UTC
It can go stable, but according to the Mozilla advisory, it only affects some Quicktime stuff.
Comment 4 Robert Buchholz (RETIRED) gentoo-dev 2007-09-24 22:08:57 UTC
I don't see any need to do a security stabling if Linux is not affected.