Bug 525788
Summary: | CVE-2009-3384 WebKit, qt: Multiple security issues while handling FTP directory listings | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Jan Lieskovsky <jlieskov> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED CURRENTRELEASE | QA Contact: | |
Severity: | urgent | Docs Contact: | |
Priority: | urgent | ||
Version: | unspecified | CC: | jreznik, rcvalle, security-response-team, than, tpelka, vdanen |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2012-03-07 06:35:15 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 538235, 549881, 572756, 572757, 572758 | ||
Bug Blocks: |
Description
Jan Lieskovsky
2009-09-25 18:15:59 UTC
This issue affects latest versions of WebKit package, as shipped with Fedora release of 10 and 11 (WebKit-1.1.0-0.16.svn40351.fc10 and WebKit-1.1.1-1.fc11). This issue affects latest versions of qt package, as shipped with Fedora release of 10 and 11 (qt-4.5.2-3.fc10 and qt-4.5.2-3.fc11). Public now via: http://threatpost.com/en_us/blogs/apple-patches-critical-safari-vulnerabilities-111109 qt-4.5.3-9.fc12 has been submitted as an update for Fedora 12. http://admin.fedoraproject.org/updates/qt-4.5.3-9.fc12 qt-4.5.3-9.fc12 has been pushed to the Fedora 12 stable repository. If problems still persist, please make note of it in this bug report. qt-4.5.3-9.fc10 has been pushed to the Fedora 10 stable repository. If problems still persist, please make note of it in this bug report. qt-4.5.3-9.fc11 has been pushed to the Fedora 11 stable repository. If problems still persist, please make note of it in this bug report. This issue does not affect kdelibs or qt3 as provided with Red Hat Enterprise Linux 3, 4, or 5. QtWebKit was introduced in Qt version 4, and kdelibs would not use this code for Konqueror as it uses the FTP KIO slave. This flaw was resolved in the version of webkitgtk shipped with Red Hat Enterprise Linux 6.0 |