on https sites, subresource certificates are not validated
Bug #1541109 reported by
Ryan Castellucci
This bug affects 3 people
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Liferea |
New
|
Undecided
|
Unassigned | ||
Midori Web Browser |
Fix Released
|
Undecided
|
Unassigned | ||
Debian |
Invalid
|
Undecided
|
Unassigned | ||
epiphany-webkit (Ubuntu) |
Confirmed
|
Undecided
|
Unassigned | ||
midori (Ubuntu) |
Confirmed
|
Undecided
|
Unassigned | ||
surf (Ubuntu) |
Fix Released
|
Undecided
|
Reiner Herrmann | ||
webkitgtk (Ubuntu) |
Confirmed
|
Undecided
|
Unassigned | ||
xxxterm (Ubuntu) |
Confirmed
|
Undecided
|
Unassigned |
Bug Description
Midori will silently load content, including scripts, from servers with invalid certificates. This allows a MitM attacker to inject code into most web pages.
Further explanation and test case: https:/
Related branches
lp://staging/~midori/midori/webKitTwoOnly
On hold
for merging
into
lp://staging/midori
- Midori Devs: Pending requested
-
Diff: 6316 lines (+248/-3830) (has conflicts)43 files modifiedCMakeLists.txt (+19/-54)
data/gtk3.css (+1/-6)
extensions/CMakeLists.txt (+9/-11)
extensions/about.vala (+0/-4)
extensions/adblock/extension.vala (+26/-60)
extensions/adblock/subscriptions.vala (+0/-34)
extensions/addons.c (+3/-3)
extensions/colorful-tabs.c (+0/-5)
extensions/cookie-manager/cookie-manager.c (+2/-8)
extensions/external-download-manager.vala (+0/-12)
extensions/feed-panel/feed-panel.c (+0/-33)
extensions/feed-panel/katze-net.c (+0/-117)
extensions/notes.vala (+0/-5)
extensions/open-with.vala (+0/-28)
extensions/transfers.vala (+0/-22)
katze/katze-item.c (+0/-27)
katze/katze.h (+1/-6)
katze/midori-paths.vala (+6/-27)
katze/midori-uri.vala (+0/-6)
midori/main.c (+3/-15)
midori/midori-browser.c (+0/-402)
midori/midori-browser.h (+0/-4)
midori/midori-contextaction.vala (+0/-2)
midori/midori-download.vala (+0/-191)
midori/midori-frontend.c (+0/-3)
midori/midori-locationaction.c (+26/-40)
midori/midori-preferences.c (+0/-29)
midori/midori-privatedata.c (+0/-39)
midori/midori-searchaction.c (+1/-118)
midori/midori-session.c (+5/-271)
midori/midori-settings.vala (+36/-33)
midori/midori-speeddial.vala (+0/-83)
midori/midori-tab.vala (+5/-46)
midori/midori-view.c (+74/-1650)
midori/midori-websettings.c (+31/-301)
midori/midori-websettings.h (+0/-9)
midori/sokoke.c (+0/-39)
tests/actions.vala (+0/-28)
tests/browser.c (+0/-7)
tests/download.vala (+0/-24)
tests/extensions.c (+0/-4)
tests/properties.c (+0/-5)
tests/tab.vala (+0/-19)
Changed in webkitgtk (Ubuntu): | |
status: | New → Confirmed |
Changed in midori: | |
milestone: | none → 0.6.0 |
Changed in surf (Ubuntu): | |
assignee: | nobody → Reiner Herrmann (deki) |
status: | Confirmed → Fix Committed |
Changed in midori: | |
status: | New → Fix Released |
To post a comment you must log in.
tested with midori 0.5.11 on Ubuntu 16.04, the test case shows that the vulnerability is present