Bug 2327069 - CVE-2023-44270 seamonkey: Improper input validation in PostCSS [fedora-41]
Summary: CVE-2023-44270 seamonkey: Improper input validation in PostCSS [fedora-41]
Keywords:
Status: CLOSED NOTABUG
Alias: None
Product: Fedora
Classification: Fedora
Component: seamonkey
Version: 41
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: ---
Assignee: Gecko Maintainer
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: {"flaws": ["50e4275e-9f35-4fcd-a6bf-0...
Depends On:
Blocks: CVE-2023-44270
TreeView+ depends on / blocked
 
Reported: 2024-11-18 17:48 UTC by Marco Benatto
Modified: 2025-03-19 04:25 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2024-11-18 19:46:01 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Marco Benatto 2024-11-18 17:48:49 UTC
More information about this security flaw is available in the following bug:

https://bugzilla.redhat.com/show_bug.cgi?id=2326998

Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

Comment 1 Dmitry Butskoy 2024-11-18 19:43:32 UTC
It seems to me that SeaMonkey does not use PostCSS in any way (at least, for now). Probably it was included into the issue just because is was labeled as "gecko-related" (as many similar erroneous SeaMonkey bugreports have been in the past).

Unfortunately, I don't have access to bug 2326998, so I can't obtain its additional info (and pass it upstream if needed).

Anyway, there are only a few indirect references to PostCSS in the code, related to the context of additional external software for (actually unused and incomplete) devtools. So probably all these SM bugs should be closed "notabug".

Comment 2 Dmitry Butskoy 2024-11-18 19:46:01 UTC
OK, now bug 2326998 is accessible.

SeaMonkey does not use PostCSS in any way for now.

Comment 3 Red Hat Bugzilla 2025-03-19 04:25:05 UTC
The needinfo request[s] on this closed bug have been removed as they have been unresolved for 120 days


Note You need to log in before you can comment on or make changes to this bug.