Debian: DSA-2106-2: New xulrunner packages fix regression

Date 19 Sep 2010
Posted By LinuxSecurity Advisories
DSA-2106-1 introduced a regression that could lead to an application crash. This update fixes this problem. For reference, the text of the original advisory is provided below.

- ------------------------------------------------------------------------
Debian Security Advisory DSA-2106-2                  This email address is being protected from spambots. You need JavaScript enabled to view it.                           Stefan Fritsch
September 19, 2010          
- ------------------------------------------------------------------------

Package        : xulrunner
Vulnerability  : several
Problem type   : remote
Debian-specific: no
CVE Id(s)      : CVE-2010-2760 CVE-2010-2763 CVE-2010-2765 CVE-2010-2766 CVE-2010-2767 CVE-2010-2768 CVE-2010-2769 CVE-2010-3167 CVE-2010-3168 CVE-2010-3169

DSA-2106-1 introduced a regression that could lead to an application
crash.  This update fixes this problem.  For reference, the text of
the original advisory is provided below.

Several remote vulnerabilities have been discovered in Xulrunner, a
runtime environment for XUL applications. The Common Vulnerabilities
and Exposures project identifies the following problems:

- - Implementation errors in XUL processing allow the execution of
  arbitrary code (CVE-2010-2760, CVE-2010-3167, CVE-2010-3168)

- - An implementation error in the XPCSafeJSObjectWrapper wrapper allows
  the bypass of the same origin policy (CVE-2010-2763)

- - An integer overflow in frame handling allows the execution of
  arbitrary code (CVE-2010-2765)

- - An implementation error in DOM handling allows the execution of
  arbitrary code (CVE-2010-2766)

- - Incorrect pointer handling in the plugin code allow the execution of
  arbitrary code (CVE-2010-2767)

- - Incorrect handling of an object tag may lead to the bypass of cross
  site scripting filters (CVE-2010-2768)

- - Incorrect copy and paste handling could lead to cross site scripting

- - Crashes in the layout engine may lead to the execution of arbitrary
  code (CVE-2010-3169)

For the stable distribution (lenny), the problem has been fixed in 
version The packages for the mips architecture are not
included in this update. They will be released as soon as they become

We recommend that you upgrade your xulrunner packages.

Upgrade instructions
- --------------------

wget url
        will fetch the file for you
dpkg -i file.deb
        will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
        will update the internal database
apt-get upgrade
        will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.

Debian GNU/Linux 5.0 alias lenny
- --------------------------------

Stable updates are available for alpha, amd64, arm, armel, hppa, i386, ia64, mipsel, powerpc, s390 and sparc.

Source archives:
  These files will probably be moved into the stable distribution on
  its next update.

- ---------------------------------------------------------------------------------
For apt-get: deb stable/updates main
For dpkg-ftp: dists/stable/updates/main
Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it.
Package info: `apt-cache show ' and

