Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 210260 (CVE-2008-1080) - www-client/opera < 9.26 multiple vulnerabilities (CVE-2008-{1080,1081,1082})
Summary: www-client/opera < 9.26 multiple vulnerabilities (CVE-2008-{1080,1081,1082})
Alias: CVE-2008-1080
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
Whiteboard: B3 [glsa]
Depends on:
Reported: 2008-02-15 17:14 UTC by Jeroen Roovers
Modified: 2008-03-04 22:40 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Note You need to log in before you can comment on or make changes to this bug.
Description Jeroen Roovers gentoo-dev 2008-02-15 17:14:03 UTC
No 9.26 build is available yet, no published vulnerability either, it seems.
Comment 1 Jeroen Roovers gentoo-dev 2008-02-15 17:15:00 UTC
Quote from the URL:
  "We are also addressing a few security issues; details will be
   published in due time."
Comment 2 Christian Faulhammer (RETIRED) gentoo-dev 2008-02-19 19:52:03 UTC
File is already available (though not announced) on:

Haven't found a ChangeLog yet, but one could prepare an ebuild
Comment 3 Jeroen Roovers gentoo-dev 2008-02-20 05:56:07 UTC
(In reply to comment #2)
> File is already available (though not announced) on:

Thanks for noticing.

> Haven't found a ChangeLog yet, but one could prepare an ebuild

Sure I could, put I won't put it in the tree until it's mirrored.
Comment 4 Jeroen Roovers gentoo-dev 2008-02-20 13:54:50 UTC
www-client/opera-9.26 is in the tree.
Comment 5 Sune Kloppenborg Jeppesen gentoo-dev 2008-02-20 13:59:34 UTC
Arches please test and mark stable. Target keywords are:

opera-9.26.ebuild:KEYWORDS="amd64 ppc sparc x86 ~x86-fbsd"
Comment 6 Christian Faulhammer (RETIRED) gentoo-dev 2008-02-20 19:07:54 UTC
x86 stable
Comment 7 Raúl Porcel (RETIRED) gentoo-dev 2008-02-21 12:25:24 UTC
sparc stable
Comment 8 Pierre-Yves Rofes (RETIRED) gentoo-dev 2008-02-21 21:44:42 UTC
details are out, no major issues.
Comment 9 Tobias Scherbaum (RETIRED) gentoo-dev 2008-02-22 14:00:45 UTC
ppc stable
Comment 10 Steve Dibb (RETIRED) gentoo-dev 2008-02-25 19:39:27 UTC
amd64 stable
Comment 11 Sune Kloppenborg Jeppesen gentoo-dev 2008-02-25 20:18:32 UTC
This one is ready for GLSA vote.
Comment 12 Peter Volkov (RETIRED) gentoo-dev 2008-02-25 20:41:01 UTC
Fixed in release snapshot.
Comment 14 Sune Kloppenborg Jeppesen gentoo-dev 2008-02-26 10:02:56 UTC
Thx for the info rbu.

GLSA request filed.
Comment 15 Robert Buchholz (RETIRED) gentoo-dev 2008-03-03 00:01:48 UTC
Name: CVE-2008-1080
Opera before 9.26 allows user-assisted remote attackers to read
arbitrary files by tricking a user into typing the characters of the
target filename into a file input.

Name: CVE-2008-1081
Opera before 9.26 allows user-assisted remote attackers to execute
arbitrary script via images that contain custom comments, which are
treated as script when the user displays the image properties.

Name: CVE-2008-1082
Opera before 9.26 allows remote attackers to "bypass sanitization
filters" and conduct cross-site scripting (XSS) attacks via crafted
attribute values in an XML document, which are not properly handled
during DOM presentation.
Comment 16 Pierre-Yves Rofes (RETIRED) gentoo-dev 2008-03-04 22:40:00 UTC
GLSA 200803-09