|
Bugzilla – Full Text Bug Listing |
| Summary: | VUL-0: CVE-2004-1491: opera - trick user into running arbitrary commands | ||
|---|---|---|---|
| Product: | [Novell Products] SUSE Security Incidents | Reporter: | Ludwig Nussel <lnussel> |
| Component: | Incidents | Assignee: | Security Team bot <security-team> |
| Status: | RESOLVED FIXED | QA Contact: | Security Team bot <security-team> |
| Severity: | Major | ||
| Priority: | P3 - Medium | CC: | christian.westgaard, security-team |
| Version: | unspecified | ||
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | CVE-2004-1491: CVSS v2 Base Score: 5.0 (AV:N/AC:L/Au:N/C:N/I:P/A:N) | ||
| Found By: | Other | Services Priority: | |
| Business Priority: | Blocker: | --- | |
| Marketing QA Status: | --- | IT Deployment: | --- |
|
Description
Ludwig Nussel
2004-12-14 21:10:20 UTC
I'll talk to our Opea contact Waiting for answer from "Espen Sand" <espen@opera.com> any news? Did you check whether the report is valid at all? It is confirmed and I still got no reply from Opera; I'll go and find a solution myself. NEEDINFO is wrong as it refers to the reporter and I cannot provide the information you need. You may set default filehandler in /usr/share/opera/ini/filehandler.ini Or per user in (created on firstrun) ~/.opera/filehandler.ini (aka $OPERA_DIR/filehandler.ini) Fixed package submitted to stable Lukas, please submit packages for older distributions too. The "VUL-0" tag means that all supported versions need an update. Thanks. OK, down to what version? 8.2 CAN-2004-1491 SM-Tracker-578 8.2 version is still missing .... patchinfo is missing please reassign to security-team when done. we'll submit patchinfo files then. Reassigning, 8.2 submitted fixed packages released. CVE-2004-1491: CVSS v2 Base Score: 5.0 (AV:N/AC:L/Au:N/C:N/I:P/A:N) |