[Bug 1166064] CVE-2012-6662 jquery-ui: XSS vulnerability in default content in Tooltip widget

bugzilla at redhat.com bugzilla at redhat.com
Thu Nov 20 14:44:09 UTC 2014


https://bugzilla.redhat.com/show_bug.cgi?id=1166064

Vasyl Kaigorodov <vkaigoro at redhat.com> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
         Depends On|                            |1166086
         Depends On|                            |1166087
         Depends On|                            |1166088
         Depends On|                            |1166089
         Depends On|                            |1166090
         Depends On|                            |1166091
         Depends On|                            |1166092
         Depends On|                            |1166093
         Depends On|                            |1166094
         Depends On|                            |1166095
         Depends On|                            |1166096
         Depends On|                            |1166097
         Depends On|                            |1166098
         Depends On|                            |1166099
         Depends On|                            |1166100
         Depends On|                            |1166101
         Depends On|                            |1166102
         Depends On|                            |1166103
         Depends On|                            |1166104
         Depends On|                            |1166105
         Depends On|                            |1166106
         Depends On|                            |1166107
         Depends On|                            |1166109
         Depends On|                            |1166111
         Depends On|                            |1166112
         Depends On|                            |1166113
         Depends On|                            |1166114
         Depends On|                            |1166115
         Depends On|                            |1166116
         Depends On|                            |1166117

Yohan Graterol <yohangraterol92 at gmail.com> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
                 CC|yohangraterol92 at gmail.com   |

Dominic Cleal <dcleal at redhat.com> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
                 CC|                            |dcleal at redhat.com



--- Comment #1 from Dominic Cleal <dcleal at redhat.com> ---
Regarding products that ship rubygem-jquery-ui-rails (or ruby193-) such as
Satellite 6 or OpenStack, versions 4.0.0 or higher of jquery-ui-rails contain
jquery-ui 1.10.0, so should not be vulnerable if newer than 4.0.0.

jquery-ui-rails is essentially a redistribution of jquery-ui and has a version
scheme of its own:
https://github.com/joliss/jquery-ui-rails/blob/master/VERSIONS.md


Referenced Bugs:

https://bugzilla.redhat.com/show_bug.cgi?id=1166086
[Bug 1166086] CVE-2012-6662 asterisk-gui: jquery-ui: XSS vulnerability in
default content in Tooltip widget [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1166087
[Bug 1166087] CVE-2012-6662 beacon: jquery-ui: XSS vulnerability in default
content in Tooltip widget [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1166088
[Bug 1166088] CVE-2012-6662 blender: jquery-ui: XSS vulnerability in
default content in Tooltip widget [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1166089
[Bug 1166089] CVE-2012-6662 bodhi: jquery-ui: XSS vulnerability in default
content in Tooltip widget [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1166090
[Bug 1166090] CVE-2012-6662 cacti: jquery-ui: XSS vulnerability in default
content in Tooltip widget [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1166091
[Bug 1166091] CVE-2012-6662 calibre: jquery-ui: XSS vulnerability in
default content in Tooltip widget [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1166092
[Bug 1166092] CVE-2012-6662 cinnamon: jquery-ui: XSS vulnerability in
default content in Tooltip widget [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1166093
[Bug 1166093] CVE-2012-6662 ckeditor: jquery-ui: XSS vulnerability in
default content in Tooltip widget [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1166094
[Bug 1166094] CVE-2012-6662 cobbler: jquery-ui: XSS vulnerability in
default content in Tooltip widget [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1166095
[Bug 1166095] CVE-2012-6662 couchdb: jquery-ui: XSS vulnerability in
default content in Tooltip widget [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1166096
[Bug 1166096] CVE-2012-6662 cumin: jquery-ui: XSS vulnerability in default
content in Tooltip widget [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1166097
[Bug 1166097] CVE-2012-6662 django-typepad: jquery-ui: XSS vulnerability in
default content in Tooltip widget [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1166098
[Bug 1166098] CVE-2012-6662 dl: jquery-ui: XSS vulnerability in default
content in Tooltip widget [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1166099
[Bug 1166099] CVE-2012-6662 dokuwiki: jquery-ui: XSS vulnerability in
default content in Tooltip widget [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1166100
[Bug 1166100] CVE-2012-6662 drupal6: jquery-ui: XSS vulnerability in
default content in Tooltip widget [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1166101
[Bug 1166101] CVE-2012-6662 drupal7: jquery-ui: XSS vulnerability in
default content in Tooltip widget [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1166102
[Bug 1166102] CVE-2012-6662 drupal7-jquery_update: jquery-ui: XSS
vulnerability in default content in Tooltip widget [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1166103
[Bug 1166103] CVE-2012-6662 fish: jquery-ui: XSS vulnerability in default
content in Tooltip widget [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1166104
[Bug 1166104] CVE-2012-6662 fityk: jquery-ui: XSS vulnerability in default
content in Tooltip widget [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1166105
[Bug 1166105] CVE-2012-6662 freeipa: jquery-ui: XSS vulnerability in
default content in Tooltip widget [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1166106
[Bug 1166106] CVE-2012-6662 gallery3: jquery-ui: XSS vulnerability in
default content in Tooltip widget [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1166107
[Bug 1166107] CVE-2012-6662 global: jquery-ui: XSS vulnerability in default
content in Tooltip widget [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1166109
[Bug 1166109] CVE-2012-6662 graphite-web: jquery-ui: XSS vulnerability in
default content in Tooltip widget [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1166111
[Bug 1166111] CVE-2012-6662 hotot: jquery-ui: XSS vulnerability in default
content in Tooltip widget [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1166112
[Bug 1166112] CVE-2012-6662 ikiwiki: jquery-ui: XSS vulnerability in
default content in Tooltip widget [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1166113
[Bug 1166113] CVE-2012-6662 libgda: jquery-ui: XSS vulnerability in default
content in Tooltip widget [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1166114
[Bug 1166114] CVE-2012-6662 mediawiki: jquery-ui: XSS vulnerability in
default content in Tooltip widget [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1166115
[Bug 1166115] CVE-2012-6662 mojomojo: jquery-ui: XSS vulnerability in
default content in Tooltip widget [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1166116
[Bug 1166116] CVE-2012-6662 nodejs-should: jquery-ui: XSS vulnerability in
default content in Tooltip widget [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1166117
[Bug 1166117] CVE-2012-6662 OpenLP: jquery-ui: XSS vulnerability in default
content in Tooltip widget [fedora-all]
-- 
You are receiving this mail because:
You are on the CC list for the bug.
Unsubscribe from this bug https://bugzilla.redhat.com/token.cgi?t=Xq3ZwtkdSH&a=cc_unsubscribe



More information about the perl-devel mailing list