[Bug 55332] Sanitizer::checkCss blacklist can be bypassed using vertical tab (ASCII 11)

2014-01-14 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=55332

Andre Klapper aklap...@wikimedia.org changed:

   What|Removed |Added

 Status|PATCH_TO_REVIEW |RESOLVED
 Resolution|--- |FIXED

--- Comment #35 from Andre Klapper aklap...@wikimedia.org ---
[Patch merged into REL1_22 branch; closing again]

-- 
You are receiving this mail because:
You are on the CC list for the bug.
___
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l


[Bug 55332] Sanitizer::checkCss blacklist can be bypassed using vertical tab (ASCII 11)

2014-01-13 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=55332

Gerrit Notification Bot gerritad...@wikimedia.org changed:

   What|Removed |Added

 Status|RESOLVED|PATCH_TO_REVIEW
 Resolution|FIXED   |---

-- 
You are receiving this mail because:
You are on the CC list for the bug.
___
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l


[Bug 55332] Sanitizer::checkCss blacklist can be bypassed using vertical tab (ASCII 11)

2014-01-13 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=55332

--- Comment #33 from Gerrit Notification Bot gerritad...@wikimedia.org ---
Change 107301 had a related patch set uploaded by CSteipp:
SECURITY: Improve css javascript detection

https://gerrit.wikimedia.org/r/107301

-- 
You are receiving this mail because:
You are on the CC list for the bug.
___
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l


[Bug 55332] Sanitizer::checkCss blacklist can be bypassed using vertical tab (ASCII 11)

2014-01-13 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=55332

--- Comment #34 from Gerrit Notification Bot gerritad...@wikimedia.org ---
Change 107301 merged by MarkAHershberger:
SECURITY: Improve css javascript detection

https://gerrit.wikimedia.org/r/107301

-- 
You are receiving this mail because:
You are on the CC list for the bug.
___
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l


[Bug 55332] Sanitizer::checkCss blacklist can be bypassed using vertical tab (ASCII 11)

2013-12-13 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=55332

--- Comment #31 from Gerrit Notification Bot gerritad...@wikimedia.org ---
Change 101290 had a related patch set uploaded by GWicke:
Fix css decoding in the sanitizer

https://gerrit.wikimedia.org/r/101290

-- 
You are receiving this mail because:
You are on the CC list for the bug.
___
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l


[Bug 55332] Sanitizer::checkCss blacklist can be bypassed using vertical tab (ASCII 11)

2013-12-13 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=55332

Gerrit Notification Bot gerritad...@wikimedia.org changed:

   What|Removed |Added

 Status|RESOLVED|PATCH_TO_REVIEW
 Resolution|FIXED   |---

-- 
You are receiving this mail because:
You are on the CC list for the bug.
___
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l


[Bug 55332] Sanitizer::checkCss blacklist can be bypassed using vertical tab (ASCII 11)

2013-12-13 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=55332

--- Comment #32 from Gerrit Notification Bot gerritad...@wikimedia.org ---
Change 101290 merged by GWicke:
Fix css decoding in the sanitizer

https://gerrit.wikimedia.org/r/101290

-- 
You are receiving this mail because:
You are on the CC list for the bug.
___
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l


[Bug 55332] Sanitizer::checkCss blacklist can be bypassed using vertical tab (ASCII 11)

2013-12-13 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=55332

Gabriel Wicke gwi...@wikimedia.org changed:

   What|Removed |Added

 Status|PATCH_TO_REVIEW |RESOLVED
 Resolution|--- |FIXED

-- 
You are receiving this mail because:
You are on the CC list for the bug.
___
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l


[Bug 55332] Sanitizer::checkCss blacklist can be bypassed using vertical tab (ASCII 11)

2013-11-15 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=55332

Andre Klapper aklap...@wikimedia.org changed:

   What|Removed |Added

 Status|PATCH_TO_REVIEW |RESOLVED
 Resolution|--- |FIXED

--- Comment #30 from Andre Klapper aklap...@wikimedia.org ---
No open patches to review here, hence restting status to RESOLVED FIXED.

-- 
You are receiving this mail because:
You are on the CC list for the bug.
___
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l


[Bug 55332] Sanitizer::checkCss blacklist can be bypassed using vertical tab (ASCII 11)

2013-11-14 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=55332

Chris Steipp cste...@wikimedia.org changed:

   What|Removed |Added

   Keywords|patch-need-review   |
 Status|NEW |RESOLVED
  Group|security|
  Component|Core|Parser
 Resolution|--- |FIXED
Product|Security|MediaWiki

-- 
You are receiving this mail because:
You are on the CC list for the bug.
___
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l


[Bug 55332] Sanitizer::checkCss blacklist can be bypassed using vertical tab (ASCII 11)

2013-11-14 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=55332

--- Comment #25 from Gerrit Notification Bot gerritad...@wikimedia.org ---
Change 95545 merged by jenkins-bot:
SECURITY: Improve css javascript detection

https://gerrit.wikimedia.org/r/95545

-- 
You are receiving this mail because:
You are on the CC list for the bug.
___
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l


[Bug 55332] Sanitizer::checkCss blacklist can be bypassed using vertical tab (ASCII 11)

2013-11-14 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=55332

--- Comment #26 from Gerrit Notification Bot gerritad...@wikimedia.org ---
Change 95542 merged by jenkins-bot:
SECURITY: Improve css javascript detection

https://gerrit.wikimedia.org/r/95542

-- 
You are receiving this mail because:
You are on the CC list for the bug.
___
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l


[Bug 55332] Sanitizer::checkCss blacklist can be bypassed using vertical tab (ASCII 11)

2013-11-14 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=55332

--- Comment #27 from Gerrit Notification Bot gerritad...@wikimedia.org ---
Change 95557 had a related patch set uploaded by CSteipp:
SECURITY: Improve css javascript detection

https://gerrit.wikimedia.org/r/95557

-- 
You are receiving this mail because:
You are on the CC list for the bug.
___
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l


[Bug 55332] Sanitizer::checkCss blacklist can be bypassed using vertical tab (ASCII 11)

2013-11-14 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=55332

Gerrit Notification Bot gerritad...@wikimedia.org changed:

   What|Removed |Added

 Status|RESOLVED|PATCH_TO_REVIEW
 Resolution|FIXED   |---

-- 
You are receiving this mail because:
You are on the CC list for the bug.
___
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l


[Bug 55332] Sanitizer::checkCss blacklist can be bypassed using vertical tab (ASCII 11)

2013-11-14 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=55332

--- Comment #28 from Gerrit Notification Bot gerritad...@wikimedia.org ---
Change 95538 merged by jenkins-bot:
SECURITY: Improve css javascript detection

https://gerrit.wikimedia.org/r/95538

-- 
You are receiving this mail because:
You are on the CC list for the bug.
___
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l


[Bug 55332] Sanitizer::checkCss blacklist can be bypassed using vertical tab (ASCII 11)

2013-11-14 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=55332

--- Comment #29 from Gerrit Notification Bot gerritad...@wikimedia.org ---
Change 95557 merged by jenkins-bot:
SECURITY: Improve css javascript detection

https://gerrit.wikimedia.org/r/95557

-- 
You are receiving this mail because:
You are on the CC list for the bug.
___
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l