Bug 598155 (CVE-2010-1459)
Summary: | CVE-2010-1459 Mono: View State Cross-Site Scripting | ||||||
---|---|---|---|---|---|---|---|
Product: | [Other] Security Response | Reporter: | Jan Lieskovsky <jlieskov> | ||||
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> | ||||
Status: | CLOSED ERRATA | QA Contact: | |||||
Severity: | medium | Docs Contact: | |||||
Priority: | medium | ||||||
Version: | unspecified | CC: | chkr, paul | ||||
Target Milestone: | --- | Keywords: | Security | ||||
Target Release: | --- | ||||||
Hardware: | All | ||||||
OS: | Linux | ||||||
URL: | http://www.mono-project.com/Vulnerabilities#ASP.NET_View_State_Cross-Site_Scripting | ||||||
Whiteboard: | |||||||
Fixed In Version: | Doc Type: | Bug Fix | |||||
Doc Text: | Story Points: | --- | |||||
Clone Of: | Environment: | ||||||
Last Closed: | 2010-07-13 18:50:58 UTC | Type: | --- | ||||
Regression: | --- | Mount Type: | --- | ||||
Documentation: | --- | CRM: | |||||
Verified Versions: | Category: | --- | |||||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||
Cloudforms Team: | --- | Target Upstream Version: | |||||
Embargoed: | |||||||
Bug Depends On: | 598159 | ||||||
Bug Blocks: | |||||||
Attachments: |
|
Description
Jan Lieskovsky
2010-05-31 15:26:08 UTC
Created attachment 418328 [details]
Upstream patch against v1.9.1
This issue affects the versions of the mono package, as shipped with Fedora release of 11, 12 and 13. This issue affects the version of the mono package, as present in EPEL-5 repository. Please fix. gnome-sharp-2.24.1-1.fc13,gtksourceview-sharp-2.0.12-11.fc13,mono-tools-2.6.2-1.fc13,mod_mono-2.6.3-1.fc13,xsp-2.6.4-1.fc13,mono-2.6.4-1.fc13,mono-basic-2.6.2-1.fc13,libgdiplus-2.6.4-1.fc13 has been submitted as an update for Fedora 13. http://admin.fedoraproject.org/updates/gnome-sharp-2.24.1-1.fc13,gtksourceview-sharp-2.0.12-11.fc13,mono-tools-2.6.2-1.fc13,mod_mono-2.6.3-1.fc13,xsp-2.6.4-1.fc13,mono-2.6.4-1.fc13,mono-basic-2.6.2-1.fc13,libgdiplus-2.6.4-1.fc13 mono-2.4.3.1-2.fc12 has been submitted as an update for Fedora 12. http://admin.fedoraproject.org/updates/mono-2.4.3.1-2.fc12 gnome-sharp-2.24.1-1.fc13, gtksourceview-sharp-2.0.12-11.fc13, mono-tools-2.6.2-1.fc13, mod_mono-2.6.3-1.fc13, xsp-2.6.4-1.fc13, mono-2.6.4-1.fc13, mono-basic-2.6.2-1.fc13, libgdiplus-2.6.4-1.fc13 has been pushed to the Fedora 13 stable repository. If problems still persist, please make note of it in this bug report. mono-2.4.3.1-2.fc12 has been pushed to the Fedora 12 stable repository. If problems still persist, please make note of it in this bug report. The issue is now fixed in F12 and F13 and it was never present in RAWHIDE. |