Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 501
Alerts This Week
Warning Icon 1 501

Fedora 9: 2009-3099 Moderate: Firefox Memory Flaw Threat

fedora
Calendar Grey March 27, 2009
Scroller Fedora
Latest security patches for Mozilla Firefox address critical memory vulnerabilities in Fedora 9, included in the gnome-python2-extras update, enhancing user protection.
Mozilla Firefox is an open source Web browser

Summary

The gnome-python-extra package contains the source packages for additional

Python bindings for GNOME. It should be used together with gnome-python.

Mozilla Firefox is an open source Web browser. XULRunner provides the XUL

Runtime environment for Mozilla Firefox. A memory corruption flaw was

discovered in the way Firefox handles XML files containing an XSLT transform. A

remote attacker could use this flaw to crash Firefox or, potentially, execute

arbitrary code as the user running Firefox. (CVE-2009-1169) A flaw was

discovered in the way Firefox handles certain XUL garbage collection events. A

remote attacker could use this flaw to crash Firefox or, potentially, execute

arbitrary code as the user running Firefox. (CVE-2009-1044) This update also

provides depending packages rebuilt against new Firefox version. Miro updates

to upstream 2.0.3. Provides new features and fixes various bugs in 1.2.x series

* Fri Mar 27 2009 Christopher Aillon - 2.19.1-25

- Rebuild against newer gecko

* Fri Mar 6 2009 Jan Horak - 2.19.1-24

- Rebuild against newer gecko

* Wed Feb 4 2009 Christopher Aillon - 2.19.1-23

- Rebuild against newer gecko

* Wed Dec 17 2008 Christopher Aillon - 2.19.1-22

- Rebuild against newer gecko

* Wed Nov 12 2008 Christopher Aillon - 2.19.1-21

- Rebuild against newer gecko

* Mon Oct 27 2008 Matthew Barnes - 2.19.1-20

- Provide Python bindings for libgdl on ppc64 (RH bug #468693).

* Thu Oct 9 2008 Matthew Barnes - 2.19.1-19

- Remove gtkspell-static patch. Appears to not be needed anymore.

* Wed Sep 24 2008 Christopher Aillon - 2.19.1-18

- Rebuild against newer gecko

* Fri Jul 18 2008 Paul W. Frields - 2.19.1-17.fc9

- Rebuild against new xulrunner (1.9.0.1) and fix dependencies

* Fri Jun 20 2008 Martin Stransky - 2.19.1-16.fc9

- Rebuild against new gecko-libs 1.9 (xulrunner)

su -c 'yum update gnome-python2-extras' at the command line.

For more information, refer to "Managing Software with yum",

available at .

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

Fedora-package-announce mailing list

Fedora-package-announce@redhat.com

https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
important
Lowest
Low
Medium
High
Critical

Product: Fedora 9
Version: 2.19.1
Release: 25.fc9
Summary: The sources for additional. PyGNOME Python extension modules.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.