Bug 146420

Summary: CAN-2004-1380 multiple epiphany issues
Product: Red Hat Enterprise Linux 4 Reporter: Josh Bressers <bressers>
Component: epiphanyAssignee: Marco Pesenti Gritti <mpg>
Status: CLOSED NOTABUG QA Contact:
Severity: high Docs Contact:
Priority: medium    
Version: 4.0CC: caillon, hp
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard: impact=important,public=20050120
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2005-01-28 11:03:44 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 142822    

Description Josh Bressers 2005-01-28 00:02:15 UTC
These items have been recently fixed by epiphany.

Secunia background tab security issues [WWW]SA12712:
http://secunia.com/advisories/12712/

Part 1) "Inactive tabs can launch dialog boxes so they appear to be displayed by
a web site in another tab" is fixed in version 1.4.5 and version 1.2.10.

Part 2) "Inactive tabs can gain focus from form fields on web sites in another
tab." is a Mozilla bug and remains unfixed.



Wrong certificate shown
http://bugzilla.gnome.org/show_bug.cgi?id=158453

On some web pages, Epiphany would show the wrong certificate. This is fixed in
version 1.4.6.


We are currently waiting on CVE information for the certificate issue.

Comment 1 Marco Pesenti Gritti 2005-01-28 10:10:37 UTC
Does this really affect RHEL4? I think the decision was not to include epiphany
in RHEL4.

Comment 2 Marco Pesenti Gritti 2005-01-28 10:15:40 UTC
I will do FC3 updates but first I need to clarification by caillon about the
numbering scheme he used for the RHEL4 package.

Comment 3 Mark J. Cox 2005-01-28 11:03:44 UTC
No epiphany in RHEL4.