Bug 124397 - CAN-2003-0564 Mozilla flaws (CAN-2004-0191)
Summary: CAN-2003-0564 Mozilla flaws (CAN-2004-0191)
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Fedora
Classification: Fedora
Component: mozilla
Version: 1
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Christopher Blizzard
QA Contact: Ben Levenson
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2004-05-26 11:07 UTC by Mark J. Cox
Modified: 2007-11-30 22:10 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2004-11-09 10:17:27 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Mark J. Cox 2004-05-26 11:07:56 UTC
NISCC testing of implementations of the S/MIME protocol uncovered a
number of bugs in NSS versions prior to 3.9. The parsing of unexpected
ASN.1 constructs within S/MIME data could cause Mozilla to crash or
consume large amounts of memory. A remote attacker could potentially
trigger these bugs by sending a carefully-crafted S/MIME message to a
victim. 

Andreas Sandblad discovered a cross-site scripting issue that affects
various versions of Mozilla. When linking to a new page it is still
possible to interact with the old page before the new page has been
successfully loaded. Any Javascript events will be invoked in the
context of the new page, making cross-site scripting possible if the
different pages belong to different domains.

        CAN-2003-0564/2004-0191 Affects: FC1
        to match http://rhn.redhat.com/errata/RHSA-2004-110.html

Comment 1 Barry K. Nathan 2004-08-26 11:16:33 UTC
Hmmm... still not fixed in FC1?

Comment 2 Mark J. Cox 2004-11-09 10:17:27 UTC
FC1 was transferred to the Fedora Legacy project.  This issue is fixed
in FC2 and FC3.


Note You need to log in before you can comment on or make changes to this bug.