Bug 3115 - Security update for opera
Summary: Security update for opera
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 1
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: QA Team
QA Contact:
URL: http://my.opera.com/desktopteam/blog/
Whiteboard:
Keywords: validated_update
Depends on:
Blocks:
 
Reported: 2011-10-19 21:24 CEST by Dave Hodgins
Modified: 2011-10-20 15:54 CEST (History)
3 users (show)

See Also:
Source RPM: opera-11.51-1.mga1.nonfree.src.rpm
CVE:
Status comment:


Attachments

Description Dave Hodgins 2011-10-19 21:24:17 CEST
This update fixes a vulnerability that was publicly disclosed
yesterday.
http://www.h-online.com/security/news/item/Critical-security-hole-in-current-version-of-Opera-1362504.html
Comment 1 Manuel Hiebel 2011-10-19 21:29:53 CEST
(Add the maintainer of opera)

Assignee: bugsquad => anssi.hannula

Comment 2 Dave Hodgins 2011-10-20 06:16:10 CEST
Testing on i586 complete for the srpm
opera-11.52-1.mga1.nonfree.src.rpm

Testing browsing, email, usenet, rss, flash at
http://www.adobe.com/software/flash/about/ and java at
http://java.com/en/download/testjava.jsp

Advisory:
This security update for opera closes a vulnerability in SVG font
handling, that can allow execution of arbitrary code.

CC: (none) => qa-bugs

Comment 3 claire robinson 2011-10-20 12:33:50 CEST
Is this ready for QA? It has not been assigned.
Comment 4 Manuel Hiebel 2011-10-20 12:43:38 CEST
I think yes, funda had push the package sine some hours: http://svnweb.mageia.org/packages?view=revision&revision=156744
Comment 5 claire robinson 2011-10-20 12:53:00 CEST
Assigning QA so it appears in the proper searches.

Assignee: anssi.hannula => qa-bugs

Comment 6 Anssi Hannula 2011-10-20 13:00:09 CEST
Reference for the advisory:
http://www.opera.com/support/kb/view/1002/

CC: (none) => anssi.hannula

Comment 7 claire robinson 2011-10-20 13:20:19 CEST
Tested OK x86_64

Advisory:
----------------
This security update for opera closes a vulnerability in SVG font
handling, that can allow execution of arbitrary code.

http://www.opera.com/support/kb/view/1002/
----------------

SRPM: opera-11.52-1.mga1.nonfree.src.rpm

Can sysadmin please push from nonfree/updates_testing to nonfree/updates

Thankyou!

Keywords: (none) => validated_update
CC: qa-bugs => sysadmin-bugs
Hardware: i586 => All
Severity: normal => major

Comment 8 Thomas Backlund 2011-10-20 15:54:26 CEST
Update pushed.

Status: NEW => RESOLVED
CC: (none) => tmb
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.