Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

Debian: DSA 838-1 Critical: Mozilla-Firefox Remote Code Threat

debian
Calendar Grey October 2, 2005
Debian Logo
Several security weaknesses in mozilla-firefox might enable unauthorized code execution and lead to denial of service incidents.
Updated package.

Summary


Heap overrun in XBM image processing

CAN-2005-2702

Denial of service (crash) and possible execution of arbitrary
code via Unicode sequences with "zero-width non-joiner"
characters.

CAN-2005-2703

XMLHttpRequest header spoofing

CAN-2005-2704

Object spoofing using XBL

CAN-2005-2705

JavaScript integer overflow

CAN-2005-2706

Privilege escalation using about: scheme

CAN-2005-2707

Chrome window spoofing allowing windows to be created without
UI components such as a URL bar or status bar that could be
used to carry out phishing attacks

For the stable distribution (sarge), these problems have been fixed in
version 1.0.4-2sarge5

For the unstable distribution (sid), these problems have been fixed in
version 1.0.7-1

We recommend that you upgrade your mozilla-firefox package.


Upgrade Instructions
- --------------------wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get package manager,...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here