|
Bugzilla – Full Text Bug Listing |
| Summary: | VUL-0: Mozilla Firefox 3.6.8 a. o.: version 3.6.9 and 3.5.12 fixes security bug Cross-Site Scripting Attacks, Obtain Potentially Sensitive Information, and Execute Arbitrary Code (related: Thunderbird 3.1.2 Thunderbird 3.0.6 SeaMonkey 2.0.6 ) | ||
|---|---|---|---|
| Product: | [openSUSE] openSUSE 11.2 | Reporter: | Martin Seidler <Martin.Seidler> |
| Component: | Firefox | Assignee: | E-mail List <bnc-team-mozilla> |
| Status: | RESOLVED FIXED | QA Contact: | E-mail List <qa-bugs> |
| Severity: | Major | ||
| Priority: | P5 - None | CC: | Martin.Seidler |
| Version: | Final | ||
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | openSUSE 11.2 | ||
| Whiteboard: | |||
| Found By: | --- | Services Priority: | |
| Business Priority: | Blocker: | --- | |
| Marketing QA Status: | --- | IT Deployment: | --- |
|
Description
Martin Seidler
2010-09-15 14:51:19 UTC
thx for the report, we know. :/ *** This bug has been marked as a duplicate of bug 637303 *** Thanks for the answer! But how could I know that you know? "Access Denied You are not authorized to access bug #637303." By the way: "Expected Results: 1. Release a security warning (documentation bug).[...]" Shall I open a second bug report for that? ;-) (In reply to comment #1) > thx for the report, we know. :/ > > *** This bug has been marked as a duplicate of bug 637303 *** >>"Access Denied >>You are not authorized to access bug #637303." As the bug 637303 is hidden/privat it does not serve the warning and informing function of a bug report. As the bug is at least for 10 days otherwise public and even confirmed by the vendor (Mozilla) that makes not sense at all. Openness may also be about making the user able to decide if she or he will use a program with a confirmed security bug (but maybe without any effect in the wild live at all?), use an other maybe not so stable version of that program or just use an other program for that purpose (Chromium, Opera, Kmail, Evolution, etc.). And also it is not possible to see for a user which programs are affected (Mozilla Firefox 3.6.8 ; Firefox 3.5.11 ; Thunderbird 3.1.2 ; Thunderbird 3.0.6 ; SeaMonkey 2.0.6 ). from the so called "bug 637303" . So I will reopen this not hidden bug report. And I still rate a real openSUSE security warning being appropriate to be published at a time when it is not only of historical interest. the firefox update was just released, the rest will follow. (In reply to comment #4) (1) > the firefox update was just released, *Thanks a lot* for this version of Firefox! So I could now change form MozillaFirefox 3.6.10-30.1 (i586) from the openSUSE Mozilla repository back to the MozillaFirefox 3.6.10-0.3.1 (i586) from the openSUSE Update (main) repository to be in line with the Main repositories again, or? (2) >the rest will follow. On the issue of Thunderbird: Shall/Could I update Mozilla Thunderbird 3.0.6-0.1.1 (i586) from the openSUSE Update (main) repository on my openSUSE 11.2 system to Mozilla Thunderbird 3.1.4-23.1 (i586) from the openSUSE Mozilla repository? I cannot see anything with a higher version number than 3.0.6 in the openSUSE Test (test for Update main) repository. Or will be there a openSUSE MozillaThunderbird 3.0.7 or 3.0.8 for openSUSE 11.2 in the future? |