Bug 33494 - Cross-site scripting (XSS) in Calibre
Summary: Cross-site scripting (XSS) in Calibre
Status: RESOLVED DUPLICATE of bug 33535
Alias: None
Product: Mageia
Classification: Unclassified
Component: RPM Packages (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal critical
Target Milestone: ---
Assignee: Stig-Ørjan Smelror
QA Contact:
URL: https://github.com/janeczku/calibre-w...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2024-08-29 00:55 CEST by Daniel Tartavel
Modified: 2025-02-11 07:42 CET (History)
1 user (show)

See Also:
Source RPM: calibre-6.17.0-1.mga9.src.rpm
CVE:
Status comment:


Attachments

Description Daniel Tartavel 2024-08-29 00:55:33 CEST
Description of problem:
Calibre enable cross-site scripting.

the bug is corrected in the last version
Comment 1 Daniel Tartavel 2024-08-29 11:34:22 CEST
need to backport python3-xxhash
Comment 2 Lewis Smith 2024-08-29 20:30:14 CEST
Thank you for the report. Do we understand that Calibre should NOT allow XSS ?

(In reply to Daniel Tartavel from comment #0)
> the bug is corrected in the last version
This current M9 version 6.17.0 is 16m old, and there have been many version updates in Cauldron since: first to 6.29.0, then from 7.1.0 to 7.17.0.
What do you mean by "last version"? Can you say the first version which fixed the problem?

As for python[3]-xxhash, we do not have this in M9, but as you imply, do for M10; hence the need to backport it to M9. Presuming it became a new 'requires' for calibre.

I am away for several days, so assigning this directly to Stig who handles this package. And imported python-xxhash.

Assignee: bugsquad => smelror

Comment 3 Daniel Tartavel 2024-09-02 13:01:04 CEST
hi,

the last version in mageia 7.17.0 correct the problem.
Comment 4 Nicolas Salguero 2024-09-11 17:07:07 CEST
Hi,

Maybe this bug report talks about CVE-2024-7008.

Bug 33535 also includes CVE-2024-6781, CVE-2024-6782 and CVE-2024-7009.

Best regards,

Nico.

CC: (none) => nicolas.salguero

Comment 5 Nicolas Salguero 2025-02-11 07:42:50 CET
Duplicate of bug 33535.

*** This bug has been marked as a duplicate of bug 33535 ***

Status: NEW => RESOLVED
Resolution: (none) => DUPLICATE


Note You need to log in before you can comment on or make changes to this bug.