Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 286469 (CVE-2009-3265) - <=www-client/opera-10 RSS/Atom feed XSS (CVE-2009-{3265,3266})
Summary: <=www-client/opera-10 RSS/Atom feed XSS (CVE-2009-{3265,3266})
Status: RESOLVED FIXED
Alias: CVE-2009-3265
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL: http://securethoughts.com/2009/09/exp...
Whiteboard: B4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2009-09-26 03:04 UTC by Stefan Behte (RETIRED)
Modified: 2009-12-18 08:20 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Stefan Behte (RETIRED) gentoo-dev Security 2009-09-26 03:04:28 UTC
CVE-2009-3265 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-3265):
  Cross-site scripting (XSS) vulnerability in Opera 9 and 10 allows
  remote attackers to inject arbitrary web script or HTML via a (1) RSS
  or (2) Atom feed, related to the rendering of the application/rss+xml
  content type as "scripted content." NOTE: the vendor reportedly
  considers this behavior a "design feature," not a vulnerability.
Comment 1 Stefan Behte (RETIRED) gentoo-dev Security 2009-09-26 03:25:29 UTC
CVE-2009-3266 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-3266):
  Unspecified vulnerability in Opera 9 and 10 allows remote attackers
  to conduct cross-site scripting (XSS) attacks and obtain "complete
  control over feeds" via a (1) RSS or (2) Atom feed, related to the
  rendering of the application/rss+xml content type as "scripted
  content."

Comment 2 Stefan Behte (RETIRED) gentoo-dev Security 2009-11-06 14:54:42 UTC
jer, was this fixed in 10.01?
Comment 3 Jeroen Roovers (RETIRED) gentoo-dev 2009-11-06 16:39:40 UTC
Looks like [1] to me:
 "Opera may allow scripts to run on the feed subscription page,
  thereby gaining access to the feeds object. This can be used
  for automatic subscription of feeds, or reading other feeds."

[1] http://www.opera.com/support/kb/view/939/ as mentioned in CVE-2009-3266 as well as the change logs for 10.01. So yes, I guess this is fixed. :)
Comment 4 Stefan Behte (RETIRED) gentoo-dev Security 2009-11-07 03:04:26 UTC
Thanks!
Ready to vote, I vote NO.
Comment 5 Pierre-Yves Rofes (RETIRED) gentoo-dev 2009-12-18 08:20:18 UTC
No too, closing.