Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Fedora: 2009-3875 Critical: Firefox 3 Layout Engine Fix

fedora
Calendar Grey April 23, 2009
Dist Fedora Esm H88
Fedora 9 sees a Mozilla Firefox upgrade that resolves various concerns. Keep updated regarding safety and performance enhancements.
https://www.mozilla.org/en-US/security/known-vulnerabilities/firefox-3.0/

Summary

Mozilla Firefox is an open-source web browser, designed for standards

compliance, performance and portability.

Update Information:

https://www.mozilla.org/en-US/security/known-vulnerabilities/firefox-3.0/

Change Log

* Tue Apr 21 2009 Christopher Aillon - 3.0.9-1 - Update to 3.0.9 * Fri Mar 27 2009 Christopher Aillon - 3.0.8-1 - Update to 3.0.8 * Wed Mar 4 2009 Jan Horak - 3.0.7-1 - Update to 3.0.7 * Thu Feb 26 2009 Jan Horak - 3.0.6-2 - Fixed spelling mistake in firefox.sh.in * Wed Feb 4 2009 Christopher Aillon - 3.0.6-1 - Update to 3.0.6 * Wed Jan 7 2009 Jan Horak - 3.0.5-2 - Fixed wrong LANG and LC_MESSAGES variables interpretation (#441973) in startup script. * Tue Dec 16 2008 Christopher Aillon 3.0.5-1 - Update to 3.0.5 * Thu Nov 13 2008 Jan Horak 3.0.4-2 - Removed firefox-2.0-getstartpage.patch patch - Start page is set by different way * Wed Nov 12 2008 Christopher Aillon 3.0.4-1 - Update to 3.0.4 * Tue Sep 23 2008 Christopher Aillon 3.0.2-1 - Update to 3.0.2 * Wed Jul 16 2008 Christopher Aillon 3.0.1-1 - Update to 3.0.1 * Tue Jun 17 2008 Christopher Aillon 3.0-1 - Firefox 3 Final * Thu May 8 2008 Colin Walters 3.0-0.61 - Rebuild to pick up new xulrunner (bug #445543)

References


[ 1 ] Bug #496252 - CVE-2009-1302 Firefox 3 Layout engine crashes https://bugzilla.redhat.com/show_bug.cgi?id=496252 [ 2 ] Bug #496253 - CVE-2009-1303 Firefox 2 and 3 Layout engine crash https://bugzilla.redhat.com/show_bug.cgi?id=496253 [ 3 ] Bug #496255 - CVE-2009-1304 Firefox 3 JavaScript engine crashes https://bugzilla.redhat.com/show_bug.cgi?id=496255 [ 4 ] Bug #496256 - CVE-2009-1305 Firefox 2 and 3 JavaScript engine crash https://bugzilla.redhat.com/show_bug.cgi?id=496256 [ 5 ] Bug #486704 - CVE-2009-0652 firefox: does not properly prevent the literal rendering of homoglyph characters in IDN domain names (spoof URLs and conduct phishing attacks) https://bugzilla.redhat.com/show_bug.cgi?id=486704 [ 6 ] Bug #496262 - CVE-2009-1306 Firefox jar: scheme ignores the content-disposition: header on the inner URI https://bugzilla.redhat.com/show_bug.cgi?id=496262 [ 7 ] Bug #496263 - CVE-2009-1307 Firefox Same-origin violati...

Read the Full Advisory

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update firefox' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: firefox
Product: Fedora 9
Version: 3.0.9
Release: 1.fc9
URL: Summary : Mozilla Firefox Web browser

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here