Your message dated Thu, 10 Dec 2009 15:50:28 +0000
with message-id <e1nilhg-0002b5...@ries.debian.org>
and subject line Bug#559267: fixed in firefox-sage 1.4.3-3
has caused the Debian Bug report #559267,
regarding CVE-2009-4102: RSS Feeds Cross Domain Scripting Vulnerability
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)
--
559267: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=559267
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Package: firefox-sage
Severity: grave
Tags: security
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Hi,
the following CVE (Common Vulnerabilities & Exposures) id was
published for firefox-sage.
CVE-2009-4102[0]:
| Sage 1.4.3 and earlier extension for Firefox performs certain
| operations with chrome privileges, which allows remote attackers to
| execute arbitrary commands and perform cross-domain scripting attacks
| via the description tag of an RSS feed.
If you fix the vulnerability please also make sure to include the
CVE id in your changelog entry.
For further information see:
[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4102
http://security-tracker.debian.org/tracker/CVE-2009-4102
Cheers,
Giuseppe
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)
iEYEARECAAYFAksXdqQACgkQNxpp46476aqbDQCeNuf5jhtHYPRDov2Sl4jNMQo6
hy4Ani1N8/crIsZ69wOGMPKgEA3evIWI
=LgV6
-----END PGP SIGNATURE-----
--- End Message ---
--- Begin Message ---
Source: firefox-sage
Source-Version: 1.4.3-3
We believe that the bug you reported is fixed in the latest version of
firefox-sage, which is due to be installed in the Debian FTP archive:
firefox-sage_1.4.3-3.diff.gz
to main/f/firefox-sage/firefox-sage_1.4.3-3.diff.gz
firefox-sage_1.4.3-3.dsc
to main/f/firefox-sage/firefox-sage_1.4.3-3.dsc
firefox-sage_1.4.3-3_all.deb
to main/f/firefox-sage/firefox-sage_1.4.3-3_all.deb
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 559...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Alan Woodland <awoodl...@debian.org> (supplier of updated firefox-sage package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@debian.org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.8
Date: Sun, 06 Dec 2009 18:03:44 +0000
Source: firefox-sage
Binary: firefox-sage
Architecture: source all
Version: 1.4.3-3
Distribution: unstable
Urgency: high
Maintainer: Mozilla Extension Packaging Team
<pkg-mozext-maintain...@lists.alioth.debian.org>
Changed-By: Alan Woodland <awoodl...@debian.org>
Description:
firefox-sage - lightweight RSS and Atom feed reader for Firefox
Closes: 559267
Changes:
firefox-sage (1.4.3-3) unstable; urgency=high
.
* Fix two security bugs:
- Setting urgency=high, this vulnerability allowed remote
exploitation, without any user interaction.
- CVE-2009-4102 Cross Domain Scripting vulnerability.
Don't trust HTML in titles, descriptions. Don't allow
'strange' (i.e. javascript:, data:) URLs in Links.
- CVE-2006-4712 (Regression), some of the old test cases
no longer passed due to problem with htmlToText.
- Closes: #559267
Checksums-Sha1:
d681c1c5ab651f8d7cdc1b5b0ddf221fc9a7b119 1188 firefox-sage_1.4.3-3.dsc
e6f72048c87d6166c763f590d374ba86b39216d8 14511 firefox-sage_1.4.3-3.diff.gz
72fc2e141afc3c3be121b7ff05980523bf93c297 167260 firefox-sage_1.4.3-3_all.deb
Checksums-Sha256:
072b3d97fd15ca92a5fec3c66dc69e21f85d62fd7a960b4b636c399822f03498 1188
firefox-sage_1.4.3-3.dsc
94e9137bd51f6fae85097a1d5e168ae6fbcb7b2a754df3d1b0dc75d6c24fdcf3 14511
firefox-sage_1.4.3-3.diff.gz
5feb6832a06c4823aa50f1c693655f4d3e297bf70c2c66a155144911d6c503a4 167260
firefox-sage_1.4.3-3_all.deb
Files:
c26758676a077050d0a23a69c16c5d0c 1188 web optional firefox-sage_1.4.3-3.dsc
267e9192039f75899a340c7f4383f874 14511 web optional
firefox-sage_1.4.3-3.diff.gz
b632ec621495bafdee29d82085c319c9 167260 web optional
firefox-sage_1.4.3-3_all.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)
iEYEARECAAYFAkshEmAACgkQ1FNW1LDdr0LoHgCfTFRNdWlniJOFEi5wn+vhPmnn
Sf0AnAkIt4Df0HT4Z+6yeJM/GxXzZNYV
=bnL7
-----END PGP SIGNATURE-----
--- End Message ---