Bug 168738 - CAN-2005-2968 Mozilla improper command line URL sanitization
Summary: CAN-2005-2968 Mozilla improper command line URL sanitization
Keywords:
Status: CLOSED NOTABUG
Alias: None
Product: Fedora
Classification: Fedora
Component: mozilla
Version: 4
Hardware: All
OS: Linux
medium
high
Target Milestone: ---
Assignee: Christopher Aillon
QA Contact: Ben Levenson
URL:
Whiteboard: impact=important,public=20050906,repo...
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2005-09-19 21:50 UTC by Josh Bressers
Modified: 2007-11-30 22:11 UTC (History)
0 users

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2005-09-22 12:37:30 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Josh Bressers 2005-09-19 21:50:30 UTC
+++ This bug was initially created as a clone of Bug #168737 +++

Upstream bug:
https://bugzilla.mozilla.org/show_bug.cgi?id=307185

The URL passed to mozilla on the command line does not properly escape dangerous
characters before handing the URL to the shell.

Comment 1 Josh Bressers 2005-09-19 21:53:23 UTC
This issue also affects FC3

Comment 2 Josh Bressers 2005-09-22 12:37:30 UTC
After investigating this issue, we have determined that it does not affect the
Mozilla packages Red Hat ships.


Note You need to log in before you can comment on or make changes to this bug.