Bug 20039 - jquery new XSS issue fixed upstream in 3.0.0
Summary: jquery new XSS issue fixed upstream in 3.0.0
Status: RESOLVED OLD
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 5
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: Nicolas Lécureuil
QA Contact: Sec team
URL: https://lwn.net/Vulnerabilities/710281/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2016-12-28 18:57 CET by David Walser
Modified: 2017-12-27 04:34 CET (History)
0 users

See Also:
Source RPM: jquery-1.7.2-6.mga6.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2016-12-28 18:57:18 CET
Fedora has issued an advisory on December 27:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/SIQYMJIF3ER4DWEJRRZ6EGSLOQJU6TTG/

They backported the upstream patch to 2.2.4:
http://pkgs.fedoraproject.org/cgit/rpms/js-jquery.git/commit/?h=f24&id=cf7b28bdf591000a9bd7d7363cc388c6dc8591b9

Upstream patch referenced in the RedHat bug:
https://bugzilla.redhat.com/show_bug.cgi?id=1399546

It sounds like older versions are affected too.
David Walser 2016-12-28 18:57:28 CET

Whiteboard: (none) => MGA5TOO

Comment 2 Nicolas Lécureuil 2017-04-25 15:58:43 CEST
Fixed on svn ( cauldron )

Whiteboard: MGA5TOO => (none)
Version: Cauldron => 5

Comment 3 David Walser 2017-12-27 04:34:41 CET
We can't fix this for Mageia 5.

Status: NEW => RESOLVED
Resolution: (none) => OLD


Note You need to log in before you can comment on or make changes to this bug.