Several remote vulnerabilities have been discovered in the Iceweasel web
browser, an unbranded version of the Firefox browser. The Common
Vulnerabilities and Exposures project identifies the following problems:
CVE-2008-5500
Jesse Ruderman discovered that the layout engine is vulnerable to
DoS attacks that might trigger memory corruption and an integer
overflow. (MFSA 2008-60)
CVE-2008-5503
Boris Zbarsky discovered that an information disclosure attack could
be performed via XBL bindings. (MFSA 2008-61)
CVE-2008-5504
It was discovered that attackers could run arbitrary JavaScript with
chrome privileges via vectors related to the feed preview.
(MFSA 2008-62)
CVE-2008-5506
Marius Schilder discovered that it is possible to obtain sensible
data via a XMLHttpRequest. (MFSA 2008-64)
CVE-2008-5507
Chris Evans discovered that it is possible to obtain sensible data
via a JavaScript URL. (MFSA 2008-65)
CVE-2008-5508
Chip Salzenberg discovered possible phishing attacks via U...
Get the latest Linux and open source security news straight to your inbox.