Your message dated Mon, 13 Jun 2016 15:13:39 +0200 with message-id <[email protected]> and subject line Re: xulrunner: multiple security issues has caused the Debian Bug report #565521, regarding xulrunner: multiple security issues to be marked as done.
This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility to reopen the Bug report if necessary, and/or fix the problem forthwith. (NB: If you are a system administrator and have no idea what this message is talking about, this may indicate a serious mail system misconfiguration somewhere. Please contact [email protected] immediately.) -- 565521: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=565521 Debian Bug Tracking System Contact [email protected] with problems
--- Begin Message ---Package: xulrunner Version: 1.9.1.6-1 Severity: serious Tags: security Hi, the following CVE (Common Vulnerabilities & Exposures) ids were published for xulrunner. CVE-2009-1597[0]: | Mozilla Firefox executes DOM calls in response to a javascript: URI in | the target attribute of a submit element within a form contained in an | inline PDF file, which might allow remote attackers to bypass intended | Adobe Acrobat JavaScript restrictions on accessing the document | object, as demonstrated by a web site that permits PDF uploads by | untrusted users, and therefore has a shared document.domain between | the web site and this javascript: URI. NOTE: the researcher reports | that Adobe's position is "a PDF file is active content." CVE-2009-2061[1]: | Mozilla Firefox before 3.0.10 processes a 3xx HTTP CONNECT response | before a successful SSL handshake, which allows man-in-the-middle | attackers to execute arbitrary web script, in an https site's context, | by modifying this CONNECT response to specify a 302 redirect to an | arbitrary https web site. CVE-2009-2065[2]: | Mozilla Firefox 3.0.10, and possibly other versions, detects http | content in https web pages only when the top-level frame uses https, | which allows man-in-the-middle attackers to execute arbitrary web | script, in an https site's context, by modifying an http page to | include an https iframe that references a script file on an http site, | related to "HTTP-Intended-but-HTTPS-Loadable (HPIHSL) pages." CVE-2009-4129[3]: | Race condition in Mozilla Firefox allows remote attackers to produce a | JavaScript message with a spoofed domain association by writing the | message in between the document request and document load for a web | page in a different domain. CVE-2009-4129[4]: | Race condition in Mozilla Firefox allows remote attackers to produce a | JavaScript message with a spoofed domain association by writing the | message in between the document request and document load for a web | page in a different domain. If you fix the vulnerabilities please also make sure to include the CVE ids in your changelog entry. For further information see: [0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1597 http://security-tracker.debian.org/tracker/CVE-2009-1597 [1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2061 http://security-tracker.debian.org/tracker/CVE-2009-2061 [2] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2065 http://security-tracker.debian.org/tracker/CVE-2009-2065 [3] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4129 http://security-tracker.debian.org/tracker/CVE-2009-4129 [4] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4129 http://security-tracker.debian.org/tracker/CVE-2009-4129
--- End Message ---
--- Begin Message ---On Sat, Jan 16, 2010 at 12:08:06PM -0500, Michael Gilbert wrote: > Package: xulrunner > Version: 1.9.1.6-1 > Severity: serious > Tags: security > > Hi, > the following CVE (Common Vulnerabilities & Exposures) ids were > published for xulrunner. Closing, six years have passed and these are history by now. Cheers, Moritz
--- End Message ---

