Bug 431748 (CVE-2008-0418)

Summary: CVE-2008-0418 Mozilla chrome: directory traversal
Product: [Other] Security Response Reporter: Josh Bressers <bressers>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED CURRENTRELEASE QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: security-response-team
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: 2.0.0.12-1.fc7 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2008-02-28 21:45:33 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 432042, 432043, 432045, 432046, 432047, 432048    
Bug Blocks: 431060, 431062, 431108, 431112, 431114, 431118, 431129    

Comment 2 Josh Bressers 2008-02-08 01:48:11 UTC
CVE-2008-0418 describes a chrome: directory traversal flaw.  It is possible that
this flaw could be used by malicious web content to steal certain session data.
 It should be noted that this flaw only affects browsers that have certain
extensions installed.  The list of vulnerable extensions can be found here:
https://bugzilla.mozilla.org/attachment.cgi?id=300181

Comment 6 Fedora Update System 2008-02-08 21:15:39 UTC
seamonkey-1.1.8-1.fc7 has been submitted as an update for Fedora 7

Comment 7 Fedora Update System 2008-02-08 21:16:56 UTC
seamonkey-1.1.8-1.fc8 has been submitted as an update for Fedora 8

Comment 8 Fedora Update System 2008-02-08 22:17:06 UTC
blam-1.8.3-13.fc8,chmsee-1.0.0-1.28.fc8,devhelp-0.16.1-5.fc8,epiphany-2.20.2-3.fc8,epiphany-extensions-2.20.1-5.fc8,firefox-2.0.0.12-1.fc8,galeon-2.0.4-1.fc8.2,gnome-python2-extras-2.19.1-12.fc8,gnome-web-photo-0.3-8.fc8,gtkmozembedmm-1.4.2.cvs20060817-18.fc8,kazehakase-0.5.2-1.fc8.2,liferea-1.4.11-2.fc8,Miro-1.1-3.fc8,openvrml-0.17.5-2.fc8,ruby-gnome2-0.16.0-20.fc8,yelp-2.20.0-7.fc8 has been submitted as an update for Fedora 8

Comment 9 Fedora Update System 2008-02-11 15:34:51 UTC
chmsee-1.0.0-1.28.fc7,devhelp-0.13-13.fc7,epiphany-2.18.3-6.fc7,epiphany-extensions-2.18.3-7,firefox-2.0.0.12-1.fc7,galeon-2.0.3-15.fc7,gnome-python2-extras-2.14.3-8.fc7,gtkmozembedmm-1.4.2.cvs20060817-15.fc7,kazehakase-0.5.2-1.fc7.2,liferea-1.4.9-2.fc7,Miro-1.1-3.fc7,openvrml-0.16.7-3.fc7,ruby-gnome2-0.16.0-21.fc7,yelp-2.18.1-9.fc7 has been submitted as an update for Fedora 7

Comment 10 Fedora Update System 2008-02-13 04:49:11 UTC
chmsee-1.0.0-1.28.fc7, devhelp-0.13-13.fc7, epiphany-extensions-2.18.3-7, firefox-2.0.0.12-1.fc7, gtkmozembedmm-1.4.2.cvs20060817-15.fc7, gnome-python2-extras-2.14.3-8.fc7, galeon-2.0.3-15.fc7, ruby-gnome2-0.16.0-21.fc7, epiphany-2.18.3-6.fc7, kazehakase-0.5.2-1.fc7.2, liferea-1.4.9-2.fc7, yelp-2.18.1-9.fc7, Miro-1.1-3.fc7, openvrml-0.16.7-3.fc7 has been pushed to the Fedora 7 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 11 Fedora Update System 2008-02-13 04:53:36 UTC
seamonkey-1.1.8-1.fc8 has been pushed to the Fedora 8 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 12 Fedora Update System 2008-02-13 05:02:47 UTC
blam-1.8.3-13.fc8, chmsee-1.0.0-1.28.fc8, devhelp-0.16.1-5.fc8, epiphany-2.20.2-3.fc8, epiphany-extensions-2.20.1-5.fc8, firefox-2.0.0.12-1.fc8, galeon-2.0.4-1.fc8.2, gnome-python2-extras-2.19.1-12.fc8, gnome-web-photo-0.3-8.fc8, gtkmozembedmm-1.4.2.cvs20060817-18.fc8, kazehakase-0.5.2-1.fc8.2, liferea-1.4.11-2.fc8, Miro-1.1-3.fc8, openvrml-0.17.5-2.fc8, ruby-gnome2-0.16.0-20.fc8, yelp-2.20.0-7.fc8 has been pushed to the Fedora 8 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 13 Fedora Update System 2008-02-13 15:10:38 UTC
seamonkey-1.1.8-1.fc7 has been pushed to the Fedora 7 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 14 Fedora Update System 2008-02-27 01:51:41 UTC
thunderbird-2.0.0.12-1.fc7 has been submitted as an update for Fedora 7

Comment 15 Fedora Update System 2008-02-27 01:52:34 UTC
thunderbird-2.0.0.12-1.fc8 has been submitted as an update for Fedora 8

Comment 16 Fedora Update System 2008-02-28 21:37:57 UTC
thunderbird-2.0.0.12-1.fc8 has been pushed to the Fedora 8 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 17 Fedora Update System 2008-02-28 21:44:49 UTC
thunderbird-2.0.0.12-1.fc7 has been pushed to the Fedora 7 stable repository.  If problems still persist, please make note of it in this bug report.