Bug 3643

Summary: Security update for opera to version 11.60
Product: Mageia Reporter: Dave Hodgins <davidwhodgins>
Component: SecurityAssignee: QA Team <qa-bugs>
Status: RESOLVED FIXED QA Contact:
Severity: normal    
Priority: Normal CC: anssi.hannula, sysadmin-bugs, tmb
Version: 1Keywords: Triaged, validated_update
Target Milestone: ---   
Hardware: i586   
OS: Linux   
URL: ftp://ftp.opera.com/pub/opera/linux/1160/
Whiteboard:
Source RPM: opera CVE:
Status comment:

Description Dave Hodgins 2011-12-06 20:23:42 CET
Version 11.60 of Opera has been released and closes three security holes in the web browser. Code-named "Tunny", the update addresses a vulnerability affecting some two- and three-letter top-level domains (TLD) that could allow cookies to be set for the TLD itself; these cookies could then be read by other sites using that TLD. A problem related to a weakness in the SSL v3.0 and TLS 1.0 specifications which could be used for eavesdropping attacks against some applications, and a cross-domain information leakage problem in the JavaScript "in" operator, have also been fixed.
Comment 1 Manuel Hiebel 2011-12-06 21:26:23 CET
Assigned to the package maintainer.

Keywords: (none) => Triaged
Assignee: bugsquad => anssi.hannula

Comment 2 Anssi Hannula 2011-12-06 22:56:22 CET
opera-11.60-1.mga1 pushed to nonfree/updates_testing

Suggested advisory
===================
Opera 11.60 fixes several security issues found in Opera 11.52 and earlier and provides other fixes and new features.

Fixed an issue that could allow pages to set cookies or communicate cross-site for some top level domains.
http://www.opera.com/support/kb/view/1003/

Improved handling of certificate revocation corner cases.

Added a fix for a weakness in the SSL v3.0 and TLS 1.0 specifications, as reported by Thai Duong and Juliano Rizzo.
http://www.opera.com/support/kb/view/1004/

Fixed an issue where the JavaScript "in" operator allowed leakage of cross-domain information, as reported by David Bloom.
http://www.opera.com/support/kb/view/1005/

Additionally, a moderately severe undisclosed issue was fixed.

References:
http://www.opera.com/docs/changelogs/unix/1160/
====================

Please test.

Status: NEW => ASSIGNED
CC: (none) => anssi.hannula
Assignee: anssi.hannula => qa-bugs

Comment 3 Dave Hodgins 2011-12-07 00:11:47 CET
The program is working, but the menu entry doesn't show up.
Comment 4 claire robinson 2011-12-08 13:05:55 CET
Testing x86_64

Flash OK
Java OK
Email OK - They've added date groupings.

The menu icon shows for me Dave in KDE, I haven't checked in Gnome yet.

Uninstalled too in case it was left over from the previous version and verified it added the menu entry.

Which desktop are you using?
Comment 5 Dave Hodgins 2011-12-08 20:09:12 CET
I've checked both kde and gnome, and the menu entry for opera itself
does not show up in either, on my i586 system.

The entry for the opera widget manager shows up under tools/system tools,
but not the entry for the browser.
Comment 6 claire robinson 2011-12-08 21:09:03 CET
It's present for me x86_64 in both KDE and gnome. I'll try i586 tomorrow and see if it's missing here too.
Comment 7 Anssi Hannula 2011-12-08 21:26:40 CET
Dave, did it work with the previous version?

The menu entry file and the icon files of 11.60 are identical to those of 11.52.
Comment 8 Dave Hodgins 2011-12-08 23:23:54 CET
Found the problem and fixed it with
rm .local/share/applications/opera-browser.desktop

The file had at date stamp of July 18th.  May have been from a beta
test.

Validating the update.

Could someone from the sysadmin push the srpm
opera-11.60-1.mga1.nonfree.src.rpm
from Nonfree Updates Testing to Nonfree Updates

Advisory:
Opera 11.60 fixes several security issues found in Opera 11.52 and earlier and
provides other fixes and new features.

Fixed an issue that could allow pages to set cookies or communicate cross-site
for some top level domains.
http://www.opera.com/support/kb/view/1003/

Improved handling of certificate revocation corner cases.

Added a fix for a weakness in the SSL v3.0 and TLS 1.0 specifications, as
reported by Thai Duong and Juliano Rizzo.
http://www.opera.com/support/kb/view/1004/

Fixed an issue where the JavaScript "in" operator allowed leakage of
cross-domain information, as reported by David Bloom.
http://www.opera.com/support/kb/view/1005/

Additionally, a moderately severe undisclosed issue was fixed.

References:
http://www.opera.com/docs/changelogs/unix/1160/

https://bugs.mageia.org/show_bug.cgi?id=3643

Keywords: (none) => validated_update
CC: (none) => sysadmin-bugs

Comment 9 Thomas Backlund 2011-12-11 01:05:17 CET
Update pushed.

Status: ASSIGNED => RESOLVED
CC: (none) => tmb
Resolution: (none) => FIXED