CVE-2022-3140: check IFrame "FrameURL" target
authorCaolán McNamara <caolanm@redhat.com>
Tue, 30 Aug 2022 16:01:08 +0000 (17:01 +0100)
committerBastien Roucariès <rouca@debian.org>
Fri, 29 Dec 2023 09:39:36 +0000 (09:39 +0000)
commit52290fc71c2d8428ed38e681e6dd726d5616d3cd
tree2a6e687cd6d4752b4541662e4d8f909d6e2f3203
parent2ed621e0b60a67b40d2f7e41a10491fbb501af8c
CVE-2022-3140: check IFrame "FrameURL" target

similiar to

commit b3edf85e0fe6ca03dc26e1bf531be82193bc9627
Date:   Wed Aug 7 17:37:11 2019 +0100

    warn on load when a document binds an event to a macro

Change-Id: Iea888b1c083d2dc69ec322309ac9ae8c5e5eb315
Reviewed-on: https://gerrit.libreoffice.org/c/core/+/139059
Tested-by: Jenkins
Reviewed-by: Stephan Bergmann <sbergman@redhat.com>
Conflicts:
sfx2/source/doc/iframe.cxx
sw/source/filter/html/htmlplug.cxx
sw/source/filter/xml/xmltexti.cxx
bug-debian-security: https://deb.freexian.com/extended-lts/tracker/CVE-2022-3140
bug: https://deb.freexian.com/extended-lts/tracker/CVE-2022-3140

Gbp-Pq: Name 0072-CVE-2022-3140-check-IFrame-FrameURL-target.patch
sfx2/source/appl/macroloader.cxx
sfx2/source/doc/iframe.cxx
sfx2/source/inc/macroloader.hxx
sw/source/filter/html/htmlplug.cxx
sw/source/filter/xml/xmltexti.cxx