Package: firefox-sage
Severity: grave
Tags: security
Justification: user security hole


A vulnerability has been found in sage:

Multiple cross-site scripting (XSS) vulnerabilities in Sage 1.3.6
allow remote attackers to inject arbitrary web script or HTML via
JavaScript in a content:encoded element within an item element in an
RSS feed, as demonstrated by four example content:encoded elements
that use XMLHttpRequest to read arbitrary local files, aka "Cross
Context Scripting."

See e.g. http://www.gnucitizen.org/blog/cross-context-scripting-with-sage for
details.

Please mention the CVE id in the changelog.

There is also an open bug against sage about arbitrary Javascript execution, but
I don't know whether this is the same issue:
http://mozdev.org/bugs/show_bug.cgi?id=13744


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to