Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Fedora 9: 2009-3099 Critical Galeon Memory Flaw Remote Code Execution

fedora
Calendar Grey March 28, 2009
Dist Fedora Esm H88
Galeon enhancement for Fedora 9 tackles memory corruption vulnerabilities, improving both browser safety and reliability.
Mozilla Firefox is an open source Web browser

Summary

Galeon is a web browser built around Gecko (Mozilla's rendering

engine) and Necko (Mozilla's networking engine). It's a GNOME web

browser, designed to take advantage of as many GNOME technologies as

makes sense. Galeon was written to do just one thing - browse the web.

Mozilla Firefox is an open source Web browser. XULRunner provides the XUL

Runtime environment for Mozilla Firefox. A memory corruption flaw was

discovered in the way Firefox handles XML files containing an XSLT transform. A

remote attacker could use this flaw to crash Firefox or, potentially, execute

arbitrary code as the user running Firefox. (CVE-2009-1169) A flaw was

discovered in the way Firefox handles certain XUL garbage collection events. A

remote attacker could use this flaw to crash Firefox or, potentially, execute

arbitrary code as the user running Firefox. (CVE-2009-1044) This update also

provides depending packages rebuilt against new Firefox version. Miro updates

to upstream 2.0.3. Provides new features and fixes various bugs in 1.2.x series

* Fri Mar 27 2009 Christopher Aillon - 2.0.7-8

- Rebuild against newer gecko

* Fri Mar 6 2009 Jan Horak - 2.0.7-7

- Rebuild against newer gecko

* Sun Feb 15 2009 Denis Leroy - 2.0.7-6

- Added upstream patch to use Gnome print support

- Added patch to fix compiler warnings

* Wed Feb 4 2009 Christopher Aillon - 2.0.7-5

- Rebuild against newer gecko

* Wed Dec 17 2008 Christopher Aillon - 2.0.7-4

- Rebuild against newer gecko

* Wed Nov 12 2008 Christopher Aillon - 2.0.7-3

- Rebuild against newer gecko

* Tue Oct 7 2008 Denis Leroy - 2.0.7-2

- Added patches to fix default font (#212616) and printing (#449806). Yay.

* Sat Sep 27 2008 Denis Leroy - 2.0.7-1

- Update to upstream 2.0.7, support for libxul-unstable

- Plugin patch cleanup

- Other patches upstreamed

* Wed Sep 24 2008 Christopher Aillon - 2.0.5-3

- Rebuild against newer gecko

* Wed Jun 18 2008 Denis Leroy - 2.0.5-2

- Rebuild with xulrunner 1.9

su -c 'yum update galeon' at the command line.

For more information, refer to "Managing Software with yum",

available at .

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

Fedora-package-announce mailing list

Fedora-package-announce@redhat.com

https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 9
Version: 2.0.7
Release: 8.fc9
Summary: GNOME2 Web browser based on Mozilla

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here