Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Fedora 10: RHSA-2009:3893 Critical: Xulrunner DoS Issues

fedora
Calendar Grey April 24, 2009
Dist Fedora Esm H88
The upgrade for xulrunner on Fedora 10 improves reliability and addresses existing bugs. Upgrade now to protect your device.
https://www.mozilla.org/en-US/security/known-vulnerabilities/firefox-3.0/

Summary

XULRunner provides the XUL Runtime environment for Gecko applications.

Update Information:

https://www.mozilla.org/en-US/security/known-vulnerabilities/firefox-3.0/

Change Log

* Tue Apr 21 2009 Christopher Aillon - 1.9.0.9-1 - Update to 1.9.0.9 * Fri Mar 27 2009 Christopher Aillon - 1.9.0.8-1 - Update to 1.9.0.8 * Tue Mar 3 2009 Jan Horak - 1.9.0.7-1 - Update to 1.9.0.7 * Thu Feb 26 2009 Jan Horak - 1.9.0.6-2 - Fixed wrong version of Firefox when loading 'about:' as location (#453980). * Wed Feb 4 2009 Christopher Aillon 1.9.0.6-1 - Update to 1.9.0.6 * Thu Jan 8 2009 Martin Stransky 1.9.0.5-2 - Copied mozilla-config.h to stable include dir (#478445) * Tue Dec 16 2008 Christopher Aillon 1.9.0.5-1 - Update to 1.9.0.5

References


[ 1 ] Bug #496252 - CVE-2009-1302 Firefox 3 Layout engine crashes https://bugzilla.redhat.com/show_bug.cgi?id=496252 [ 2 ] Bug #496253 - CVE-2009-1303 Firefox 2 and 3 Layout engine crash https://bugzilla.redhat.com/show_bug.cgi?id=496253 [ 3 ] Bug #496255 - CVE-2009-1304 Firefox 3 JavaScript engine crashes https://bugzilla.redhat.com/show_bug.cgi?id=496255 [ 4 ] Bug #496256 - CVE-2009-1305 Firefox 2 and 3 JavaScript engine crash https://bugzilla.redhat.com/show_bug.cgi?id=496256 [ 5 ] Bug #486704 - CVE-2009-0652 firefox: does not properly prevent the literal rendering of homoglyph characters in IDN domain names (spoof URLs and conduct phishing attacks) https://bugzilla.redhat.com/show_bug.cgi?id=486704 [ 6 ] Bug #496262 - CVE-2009-1306 Firefox jar: scheme ignores the content-disposition: header on the inner URI https://bugzilla.redhat.com/show_bug.cgi?id=496262 [ 7 ] Bug #496263 - CVE-2009-1307 Firefox Same-origin violati...

Read the Full Advisory

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update xulrunner' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: xulrunner
Product: Fedora 10
Version: 1.9.0.9
Release: 1.fc10
URL: Summary : XUL Runtime for Gecko Applications

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here