Bug 598159
| Summary: | CVE-2010-1459 Mono: View State Cross-Site Scripting [Fedora all] | ||
|---|---|---|---|
| Product: | [Fedora] Fedora | Reporter: | Jan Lieskovsky <jlieskov> |
| Component: | mono | Assignee: | Xavier Lamien <lxtnow> |
| Status: | CLOSED ERRATA | QA Contact: | Christian Krause <chkr> |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | rawhide | CC: | chkr, itamar, lxtnow, paul |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| URL: | http://fedoraproject.org/wiki/Security/TrackingBugs | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | Bug Fix | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2010-07-13 18:49:06 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | |||
| Bug Blocks: | 598155 | ||
|
Description
Jan Lieskovsky
2010-05-31 15:40:49 UTC
As this is prior to 2.6.4, it doesn't hit the current rawhide version, but will for others. I'll check to see if this CVE can be safely addressed by changing FALSE to TRUE gnome-sharp-2.24.1-1.fc13,gtksourceview-sharp-2.0.12-11.fc13,mono-tools-2.6.2-1.fc13,mod_mono-2.6.3-1.fc13,xsp-2.6.4-1.fc13,mono-2.6.4-1.fc13,mono-basic-2.6.2-1.fc13,libgdiplus-2.6.4-1.fc13 has been submitted as an update for Fedora 13. http://admin.fedoraproject.org/updates/gnome-sharp-2.24.1-1.fc13,gtksourceview-sharp-2.0.12-11.fc13,mono-tools-2.6.2-1.fc13,mod_mono-2.6.3-1.fc13,xsp-2.6.4-1.fc13,mono-2.6.4-1.fc13,mono-basic-2.6.2-1.fc13,libgdiplus-2.6.4-1.fc13 gnome-sharp-2.24.1-1.fc13, gtksourceview-sharp-2.0.12-11.fc13, mono-tools-2.6.2-1.fc13, mod_mono-2.6.3-1.fc13, xsp-2.6.4-1.fc13, mono-2.6.4-1.fc13, mono-basic-2.6.2-1.fc13, libgdiplus-2.6.4-1.fc13 has been pushed to the Fedora 13 stable repository. If problems still persist, please make note of it in this bug report. mono-2.4.3.1-2.fc12 has been pushed to the Fedora 12 stable repository. If problems still persist, please make note of it in this bug report. The issue is now fixed in F12 and F13 and it was never present in RAWHIDE. |