Hottest Free Downloads - DownloadPipe.com Over 197,000 downloads! Bookmark Now!
DownloadPipe.com - New Downloads Every Minute
 SEARCH:
FAQFAQ    SearchSearch      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

Bug#555234: op-panel: CVE-2007-2383 and CVE-2008-7720 prot..

 
   Linux (Home) -> Bugs RC RSS
Next:  Bug#555217: auth2db: CVE-2007-2383 and CVE-2008-7..  
Author Message
Michael Gilbert

External


Since: Sep 03, 2007
Posts: 73



(Msg. 1) Posted: Sun Nov 08, 2009 9:25 pm
Post subject: Bug#555234: op-panel: CVE-2007-2383 and CVE-2008-7720 prototypejs vulnerabilities
Archived from groups: linux>debian>bugs>rc (more info?)

package: op-panel
version: 0.27.dfsg-2
severity: serious
tags: security

Hi,

Your package contains an embedded version of prototype.js that is
vulnerable to either CVE-2007-2383 (affecting prototype.js before 1.5.1)
[0], CVE-2008-7220 (affecting prototype.js before 1.6.0.2) [1], or both.

Your package embeds the following prototype.js versions:

sid: 1.5.0_rc0
lenny: N/A
etch: N/A

This is a mass-filing, and the only checking done so far is a version
comparison, so please determine whether or not your package is itself
affected or not. If it is not affected please close the bug with a
message indicating this along with what you did to check.

The version of your package specified above is the earliest version
with the affected embedded code. If this version is in one or both of
the stable releases and you are affected, please coordinate with the
release team to prepare a proposed-update for your package to
stable/oldstable.

There are patches available for CVE-2007-2383 [2] and a backport for
prototypejs 1.5 for CVE-2008-7720 [3].

If you correct the problem in unstable, please make sure to include the
CVE number in your changelog.

Thank you for your attention to this problem.

Mike

[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2383
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-7220
[2] http://dev.rubyonrails.org/ticket/7910
[3] http://prototypejs.org/2008/1/25/prototype-1-6-0-2-bug-fixes-performan...improve



--
To UNSUBSCRIBE, email to debian-bugs-rc-REQUEST.DeleteThis@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster.DeleteThis@lists.debian.org
Back to top
Login to vote
Display posts from previous:   
Related Topics:
Bug#555217: auth2db: CVE-2007-2383 and CVE-2008-7720 proto.. - package: auth2db version: 0.2.5-2+dfsg-1 severity: serious tags: security Hi, Your package contains an embedded version of prototype.js that is vulnerable to either CVE-2007-2383 (affecting prototype.js 1.5.1 and earlier) [0], CVE-2008-7220 (affecting....

Bug#555274: plone3: CVE-2007-2383 and CVE-2008-7720 protot.. - package: plone3 version: 3.1.3-1 severity: serious tags: security Hi, Your package contains an embedded version of prototype.js that is vulnerable to either CVE-2007-2383 (affecting prototype.js before 1.5.1) [0], CVE-2008-7220 (affecting prototype.js....

Bug#499771: webkit: several vulnerabilities (CVE-2008-3950.. - Package: webkit Severity: grave Tags: security, patch Justification: user security hole Hi, the following CVE (Common Vulnerabilities & Exposures) ids were published for webkit. CVE-2008-3950[0]: | Off-by-one error in the |..

Bug#419981: xfce4-panel: Cannot be installed on Sid - Package: xfce4-panel Version: 4.3.99.2-2 Severity: grave Justification: renders package unusable When I attempt to install it, there is a message about unmet dependencies: The following packages have unmet dependencies. xfce4-panel: Depends:..

Bug#410999: kicker fails to push up the panel after update - Package: kicker Version: 4:3.5.5a.dfsg.1-6 Severity: grave Hi, I updated kicker from 4:3.5.5a.dfsg.1-5 to 4:3.5.5a.dfsg.1-6 and after that the panel failed to push up when the mouse pointer touched the bottom edge. Workaround: I configured the panel....
       Linux (Home) -> Bugs RC All times are: Pacific Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Categories:
 Windows Forums
 Game Forums
  Linux Forums
 Mac Forums
 PDA Forums
 Mobile Forums
  Top  |  Store  |  RSS Feeds RSS  |  Data Feeds  |  Advertise  |  Submit  |  Bookmark  |  Newsletter  |  Contact