This service will be undergoing maintenance at 00:00 UTC, 2016-08-01. It is expected to last about 1 hours
Bug 168738 - CAN-2005-2968 Mozilla improper command line URL sanitization
CAN-2005-2968 Mozilla improper command line URL sanitization
Status: CLOSED NOTABUG
Product: Fedora
Classification: Fedora
Component: mozilla (Show other bugs)
4
All Linux
medium Severity high
: ---
: ---
Assigned To: Christopher Aillon
Ben Levenson
impact=important,public=20050906,repo...
: Security
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2005-09-19 17:50 EDT by Josh Bressers
Modified: 2007-11-30 17:11 EST (History)
0 users

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2005-09-22 08:37:30 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:


Attachments (Terms of Use)

  None (edit)
Description Josh Bressers 2005-09-19 17:50:30 EDT
+++ This bug was initially created as a clone of Bug #168737 +++

Upstream bug:
https://bugzilla.mozilla.org/show_bug.cgi?id=307185

The URL passed to mozilla on the command line does not properly escape dangerous
characters before handing the URL to the shell.
Comment 1 Josh Bressers 2005-09-19 17:53:23 EDT
This issue also affects FC3
Comment 2 Josh Bressers 2005-09-22 08:37:30 EDT
After investigating this issue, we have determined that it does not affect the
Mozilla packages Red Hat ships.

Note You need to log in before you can comment on or make changes to this bug.