<?xml version="1.0" encoding="UTF-8" ?>

<bugzilla version="5.2"
          urlbase="https://bugzilla.altlinux.org/"
          
          maintainer="jenya@basealt.ru"
>

    <bug>
          <bug_id>20761</bug_id>
          
          <creation_ts>2009-07-13 11:01:30 +0400</creation_ts>
          <short_desc>webkit multiple vulnerabilities: CVE-2009-1724, CVE-2009-1725, ...</short_desc>
          <delta_ts>2009-10-22 23:54:29 +0400</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>4</classification_id>
          <classification>Development</classification>
          <product>Sisyphus</product>
          <component>libwebkit</component>
          <version>unstable</version>
          <rep_platform>all</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>CLOSED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc>http://support.apple.com/kb/HT3666</bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>security</keywords>
          <priority>P3</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Vladimir Lettiev">crux</reporter>
          <assigned_to name="Alexey Shabalin">shaba</assigned_to>
          <cc>aris</cc>
    
    <cc>shaba</cc>
          
          <qa_contact>qa-sisyphus</qa_contact>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>94589</commentid>
    <comment_count>0</comment_count>
    <who name="Vladimir Lettiev">crux</who>
    <bug_when>2009-07-13 11:01:30 +0400</bug_when>
    <thetext>* CVE-2009-1724 - An issue in WebKit&apos;s handling of the parent and top objects may result in a cross-site scripting attack when visiting a maliciously crafted website. This update addresses the issue through improved handling of parent and top objects.
Fixed in rev 44906 (http://trac.webkit.org/changeset/44906/trunk)

* CVE-2009-1725 - A memory corruption issue exists in WebKit&apos;s handling of numeric character references. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution. This update addresses the issue through improved handling of numeric character references. Credit to Chris Evans for reporting this issue.
Fixed in rev 44865 (http://trac.webkit.org/changeset/44865/trunk)

Also several security fixes in svn:
* rev 45731
 https://bugs.webkit.org/show_bug.cgi?id=27136
 Fix a bug where webkit hangs when executing infinite JavaScript loop.

* rev 45696
 https://bugs.webkit.org/show_bug.cgi?id=27110
 REGRESSION: crash in edge cases of floating point parsing.

* rev 45642
https://bugs.webkit.org/show_bug.cgi?id=26918
Tests prevention of injected HTML Base tag.

* rev 45639
https://bugs.webkit.org/show_bug.cgi?id=27071
Resolves issue when HTTP parameters contain null- and  non-null-control- characters.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>94646</commentid>
    <comment_count>1</comment_count>
    <who name="Alexey Shabalin">shaba</who>
    <bug_when>2009-07-14 12:44:54 +0400</bug_when>
    <thetext>Новые версии webkit, закрывающие эти ошибки, требуют нового libsoup-2.27.
Надо смотреть, возможно ли сейчас обновить libsoup.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>95369</commentid>
    <comment_count>2</comment_count>
    <who name="Yuri N. Sedunov">aris</who>
    <bug_when>2009-07-28 07:49:10 +0400</bug_when>
    <thetext>(In reply to comment #1)
&gt; Новые версии webkit, закрывающие эти ошибки, требуют нового libsoup-2.27.
&gt; Надо смотреть, возможно ли сейчас обновить libsoup.

Могу libsoup-2.27.4 положить в people/gnome для особо нуждающизся :).</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>102009</commentid>
    <comment_count>3</comment_count>
    <who name="Alexey Shabalin">shaba</who>
    <bug_when>2009-10-22 23:54:29 +0400</bug_when>
    <thetext>fixed libwebkit-1.1.15.2-alt1</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>