CVE-2011-4969: jQuery 1.6.2 XSS

Related Vulnerabilities: CVE-2011-4969  

Debian Bug report logs - #699482
CVE-2011-4969: jQuery 1.6.2 XSS

version graph

Reported by: Luciano Bello <luciano@debian.org>

Date: Thu, 31 Jan 2013 21:54:02 UTC

Severity: important

Tags: patch, security, squeeze

Found in version 1.4.2-2

Fixed in version 1.6.4-1

Done: Paul Gevers <elbrus@debian.org>

Bug is archived. No further changes may be made.

Forwarded to http://bugs.jquery.com/ticket/9521

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, Debian Javascript Maintainers <pkg-javascript-devel@lists.alioth.debian.org>:
Bug#699482; Package jquery. (Thu, 31 Jan 2013 21:54:04 GMT) (full text, mbox, link).


Acknowledgement sent to Luciano Bello <luciano@debian.org>:
New Bug report received and forwarded. Copy sent to Debian Javascript Maintainers <pkg-javascript-devel@lists.alioth.debian.org>. (Thu, 31 Jan 2013 21:54:04 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Luciano Bello <luciano@debian.org>
To: submit@bugs.debian.org
Subject: CVE-2011-4969: jQuery 1.6.2 XSS
Date: Thu, 31 Jan 2013 22:50:44 +0100
Package: jquery
Severity: important
Tags: security squeeze
Justification: user security hole

Hi there,
   It's 2011 calling :)
   The CVE-2011-4969 for this issue:    
http://blog.jquery.com/2011/09/01/jquery-1-6-3-released/
   I'm not sure if squeeze (1.4.2-2) is affected. Any way to check it?
  
Cheers,
luciano



Information forwarded to debian-bugs-dist@lists.debian.org, Debian Javascript Maintainers <pkg-javascript-devel@lists.alioth.debian.org>:
Bug#699482; Package jquery. (Sat, 09 Feb 2013 15:30:03 GMT) (full text, mbox, link).


Acknowledgement sent to Salvatore Bonaccorso <carnil@debian.org>:
Extra info received and forwarded to list. Copy sent to Debian Javascript Maintainers <pkg-javascript-devel@lists.alioth.debian.org>. (Sat, 09 Feb 2013 15:30:03 GMT) (full text, mbox, link).


Message #10 received at 699482@bugs.debian.org (full text, mbox, reply):

From: Salvatore Bonaccorso <carnil@debian.org>
To: Luciano Bello <luciano@debian.org>, 699482@bugs.debian.org
Subject: Re: Bug#699482: CVE-2011-4969: jQuery 1.6.2 XSS
Date: Sat, 9 Feb 2013 16:26:46 +0100
[Message part 1 (text/plain, inline)]
Control: forwarded 699482 http://bugs.jquery.com/ticket/9521

Hi Luciano

On Thu, Jan 31, 2013 at 10:50:44PM +0100, Luciano Bello wrote:
> Package: jquery
> Severity: important
> Tags: security squeeze
> Justification: user security hole
> 
> Hi there,
>    It's 2011 calling :)
>    The CVE-2011-4969 for this issue:    
> http://blog.jquery.com/2011/09/01/jquery-1-6-3-released/
>    I'm not sure if squeeze (1.4.2-2) is affected. Any way to check it?

It looks a bit 'complicated' situation[0], and upstream applied the
following commit[1]. Attached is also the debdiff, but I'm not
confortable to it right now as it's untested.
 
 [0]: http://bugs.jquery.com/ticket/9521
 [1]: https://github.com/jquery/jquery/commit/749dbad981f040bd65cbb50c10e9aa6e44bd26ff

Regards,
Salvatore
[jquery_1.4.2-2+squeeze1.debdiff (text/plain, attachment)]

Set Bug forwarded-to-address to 'http://bugs.jquery.com/ticket/9521'. Request was from Salvatore Bonaccorso <carnil@debian.org> to 699482-submit@bugs.debian.org. (Sat, 09 Feb 2013 15:30:03 GMT) (full text, mbox, link).


Added tag(s) patch. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Sat, 09 Feb 2013 19:03:03 GMT) (full text, mbox, link).


Reply sent to Paul Gevers <elbrus@debian.org>:
You have taken responsibility. (Fri, 27 Jan 2017 21:09:06 GMT) (full text, mbox, link).


Notification sent to Luciano Bello <luciano@debian.org>:
Bug acknowledged by developer. (Fri, 27 Jan 2017 21:09:06 GMT) (full text, mbox, link).


Message #19 received at 699482-done@bugs.debian.org (full text, mbox, reply):

From: Paul Gevers <elbrus@debian.org>
To: 699482-done@bugs.debian.org
Subject: CVE-2011-4969 was fixed in Debian in 2011
Date: Fri, 27 Jan 2017 22:05:43 +0100
[Message part 1 (text/plain, inline)]
Version: 1.6.4-1

Bug maintenance.

CVE-2011-4969 was fixed upstream in 1.6.3 which was accepted in Debian
via 1.6.4-1 on 2011-09-27. All current supported Debian versions are fixed.

Paul

[signature.asc (application/pgp-signature, attachment)]

Marked as found in versions 1.4.2-2. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Sat, 28 Jan 2017 10:03:05 GMT) (full text, mbox, link).


Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Sun, 26 Feb 2017 07:35:08 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 15:12:19 2019; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.