Bug#479644: libqt4-webkit:CVE-2008-1025 Cross-site scripting (XSS) vulnerability in Apple WebKit

2008-05-20 Thread Nico Golde
Hi, please fix the code anyway. Kind regards Nico -- Nico Golde - http://www.ngolde.de - [EMAIL PROTECTED] - GPG: 0x73647CFF For security reasons, all text in this mail is double-rot13 encrypted. pgpGVSs0v72Aq.pgp Description: PGP signature

Bug#479644: libqt4-webkit:CVE-2008-1025 Cross-site scripting (XSS) vulnerability in Apple WebKit

2008-05-14 Thread Nico Golde
Hi Fathi, any news on the upstream opinion? Cheers Nico -- Nico Golde - http://www.ngolde.de - [EMAIL PROTECTED] - GPG: 0x73647CFF For security reasons, all text in this mail is double-rot13 encrypted. pgpRGNNMwLgMF.pgp Description: PGP signature

Bug#479644: libqt4-webkit:CVE-2008-1025 Cross-site scripting (XSS) vulnerability in Apple WebKit

2008-05-06 Thread Michael Gilbert
i believe that this is actually an issue with webkit itself, not the libqt4-webkit package (which uses webkit as a library). CVE-2008-1025 seems to indicate that the issue is wholely within webkit (there is no mention of qt). submitter, do you have further details that would confirm that the

Bug#479644: libqt4-webkit:CVE-2008-1025 Cross-site scripting (XSS) vulnerability in Apple WebKit

2008-05-06 Thread Michael Gilbert
On 5/6/08, Michael Gilbert wrote: i believe that this is actually an issue with webkit itself, not the libqt4-webkit package (which uses webkit as a library). CVE-2008-1025 seems to indicate that the issue is wholely within webkit (there is no mention of qt). i am mistaken, it looks like

Bug#479644: libqt4-webkit:CVE-2008-1025 Cross-site scripting (XSS) vulnerability in Apple WebKit

2008-05-06 Thread Sune Vuorela
On Wednesday 07 May 2008, Michael Gilbert wrote: i believe that this is actually an issue with webkit itself, not the libqt4-webkit package (which uses webkit as a library). CVE-2008-1025 seems to indicate that the issue is wholely within webkit (there is no mention of qt). submitter, do

Bug#479644: libqt4-webkit:CVE-2008-1025 Cross-site scripting (XSS) vulnerability in Apple WebKit

2008-05-06 Thread Sune Vuorela
On Wednesday 07 May 2008, Michael Gilbert wrote: On 5/6/08, Michael Gilbert wrote: i believe that this is actually an issue with webkit itself, not the libqt4-webkit package (which uses webkit as a library). CVE-2008-1025 seems to indicate that the issue is wholely within webkit (there is

Bug#479644: libqt4-webkit:CVE-2008-1025 Cross-site scripting (XSS) vulnerability in Apple WebKit

2008-05-05 Thread Eder L. Marques
Package: libqt4-webkit Version: 4.4.0~rc1-5 Severity: medium Tags: security Hi, the following CVE (Common Vulnerabilities Exposures) id was published for libqt4-webkit. CVE-2008-1025[0]: | Cross-site scripting (XSS) vulnerability in Apple WebKit, as used in | Safari before 3.1.1, allows remote