[Bug 808243] New: Firefox 19.0.2/17.0.4
https://bugzilla.novell.com/show_bug.cgi?id=808243 https://bugzilla.novell.com/show_bug.cgi?id=808243#c0 Summary: Firefox 19.0.2/17.0.4 Classification: openSUSE Product: openSUSE 12.2 Version: Final Platform: Other OS/Version: Other Status: NEW Severity: Major Priority: P5 - None Component: Firefox AssignedTo: bnc-team-mozilla@forge.provo.novell.com ReportedBy: wolfgang@rosenauer.org QAContact: qa-bugs@suse.de CC: security-team@suse.de Found By: --- Blocker: --- Firefox 19.0.2/17.0.4 Thunderbird 17.0.4 Seamonkey 2.16.1 released because of https://www.mozilla.org/security/announce/2013/mfsa2013-29.html Description VUPEN Security, via TippingPoint's Zero Day Initiative, reported a use-after-free within the HTML editor when content script is run by the document.execCommand() function while internal editor operations are occurring. This could allow for arbitrary code execution. References use-after-free in nsHTMLEditor when using execCommand() (CVE-2013-0787) -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=808243 https://bugzilla.novell.com/show_bug.cgi?id=808243#c1 Marcus Meissner <meissner@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Priority|P5 - None |P2 - High CC| |meissner@suse.com, | |pcerny@suse.com Summary|Firefox 19.0.2/17.0.4 |VUL-0: MozillaFirefox | |19.0.2/17.0.4 Severity|Major |Critical --- Comment #1 from Marcus Meissner <meissner@suse.com> 2013-03-08 15:29:59 UTC --- are they release already? -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=808243 https://bugzilla.novell.com/show_bug.cgi?id=808243#c2 --- Comment #2 from Wolfgang Rosenauer <wolfgang@rosenauer.org> 2013-03-08 16:05:21 UTC --- Firefox 19 and 17 are released. Thunderbird 17 and SeaMonkey are not yet. TB probably on monday and no idea for Seamonkey. I could already submit Firefox (and also TB but there is no guarantee they are final). Do you suggest to have separate patches because of that timing or should I submit if everything is ready? -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=808243 https://bugzilla.novell.com/show_bug.cgi?id=808243#c3 --- Comment #3 from Marcus Meissner <meissner@suse.com> 2013-03-08 18:48:13 UTC --- submit seperately, its fine -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@novell.com