Bug 20039

Summary: jquery new XSS issue fixed upstream in 3.0.0
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: Nicolas Lécureuil <mageia>
Status: RESOLVED OLD QA Contact: Sec team <security>
Severity: major    
Priority: Normal    
Version: 5   
Target Milestone: ---   
Hardware: All   
OS: Linux   
URL: https://lwn.net/Vulnerabilities/710281/
Whiteboard:
Source RPM: jquery-1.7.2-6.mga6.src.rpm CVE:
Status comment:

Description David Walser 2016-12-28 18:57:18 CET
Fedora has issued an advisory on December 27:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/SIQYMJIF3ER4DWEJRRZ6EGSLOQJU6TTG/

They backported the upstream patch to 2.2.4:
http://pkgs.fedoraproject.org/cgit/rpms/js-jquery.git/commit/?h=f24&id=cf7b28bdf591000a9bd7d7363cc388c6dc8591b9

Upstream patch referenced in the RedHat bug:
https://bugzilla.redhat.com/show_bug.cgi?id=1399546

It sounds like older versions are affected too.
David Walser 2016-12-28 18:57:28 CET

Whiteboard: (none) => MGA5TOO

Comment 2 Nicolas Lécureuil 2017-04-25 15:58:43 CEST
Fixed on svn ( cauldron )

Whiteboard: MGA5TOO => (none)
Version: Cauldron => 5

Comment 3 David Walser 2017-12-27 04:34:41 CET
We can't fix this for Mageia 5.

Status: NEW => RESOLVED
Resolution: (none) => OLD