Date:         Thu, 19 Jul 2007 16:05:27 -0500
Reply-To:     Troy Dawson 
Sender:       Security Errata for Scientific Linux
              
From:         Troy Dawson 
Subject:      Security ERRATA for firefox on SL5.x, SL4.x, SL3,x i386/x86_64
Comments: To: scientific-linux-errata@fnal.gov

Synopsis:	Critical: firefox security update
Issue date:	2007-07-18
CVE Names:	CVE-2007-3089 CVE-2007-3656 CVE-2007-3734
                 CVE-2007-3735 CVE-2007-3736 CVE-2007-3737
                 CVE-2007-3738

Several flaws were found in the way Firefox processed certain malformed
JavaScript code. A web page containing malicious JavaScript code could
cause Firefox to crash or potentially execute arbitrary code as the user
running Firefox. (CVE-2007-3734, CVE-2007-3735, CVE-2007-3737,
CVE-2007-3738)

Several content injection flaws were found in the way Firefox handled
certain JavaScript code. A web page containing malicious JavaScript code
could inject arbitrary content into other web pages. (CVE-2007-3736,
CVE-2007-3089)

A flaw was found in the way Firefox cached web pages on the local disk.
A malicious web page may be able to inject arbitrary HTML into a
browsing session if the user reloads a targeted site. (CVE-2007-3656)

SL 3.0.x

   SRPMS:
	firefox-1.5.0.12-0.3.SL3.src.rpm
   i386:
	firefox-1.5.0.12-0.3.SL3.i386.rpm
   x86_64:
	firefox-1.5.0.12-0.3.SL3.i386.rpm
	firefox-1.5.0.12-0.3.SL3.x86_64.rpm

SL 4.x

   SRPMS:
	firefox-1.5.0.12-0.3.el4.src.rpm
   i386:
	firefox-1.5.0.12-0.3.el4.i386.rpm
   x86_64:
	firefox-1.5.0.12-0.3.el4.i386.rpm
	firefox-1.5.0.12-0.3.el4.x86_64.rpm

SL 5.x

   SRPMS:
	firefox-1.5.0.12-3.el5.src.rpm
   i386:
	firefox-1.5.0.12-3.el5.i386.rpm
	firefox-devel-1.5.0.12-3.el5.i386.rpm
   x86_64:
	firefox-1.5.0.12-3.el5.i386.rpm
	firefox-1.5.0.12-3.el5.x86_64.rpm
	firefox-devel-1.5.0.12-3.el5.i386.rpm
	firefox-devel-1.5.0.12-3.el5.x86_64.rpm

-Connie Sieh
-Troy Dawson

SciLinux: CVE-2007-3089 firefox SL5.x, SL4.x, SL3,x i386/x86_64

Critical: firefox security update

Summary

Date:         Thu, 19 Jul 2007 16:05:27 -0500Reply-To:     Troy Dawson Sender:       Security Errata for Scientific Linux              From:         Troy Dawson Subject:      Security ERRATA for firefox on SL5.x, SL4.x, SL3,x i386/x86_64Comments: To: scientific-linux-errata@fnal.govSynopsis:	Critical: firefox security updateIssue date:	2007-07-18CVE Names:	CVE-2007-3089 CVE-2007-3656 CVE-2007-3734                 CVE-2007-3735 CVE-2007-3736 CVE-2007-3737                 CVE-2007-3738Several flaws were found in the way Firefox processed certain malformedJavaScript code. A web page containing malicious JavaScript code couldcause Firefox to crash or potentially execute arbitrary code as the userrunning Firefox. (CVE-2007-3734, CVE-2007-3735, CVE-2007-3737,CVE-2007-3738)Several content injection flaws were found in the way Firefox handledcertain JavaScript code. A web page containing malicious JavaScript codecould inject arbitrary content into other web pages. (CVE-2007-3736,CVE-2007-3089)A flaw was found in the way Firefox cached web pages on the local disk.A malicious web page may be able to inject arbitrary HTML into abrowsing session if the user reloads a targeted site. (CVE-2007-3656)SL 3.0.x   SRPMS:	firefox-1.5.0.12-0.3.SL3.src.rpm   i386:	firefox-1.5.0.12-0.3.SL3.i386.rpm   x86_64:	firefox-1.5.0.12-0.3.SL3.i386.rpm	firefox-1.5.0.12-0.3.SL3.x86_64.rpmSL 4.x   SRPMS:	firefox-1.5.0.12-0.3.el4.src.rpm   i386:	firefox-1.5.0.12-0.3.el4.i386.rpm   x86_64:	firefox-1.5.0.12-0.3.el4.i386.rpm	firefox-1.5.0.12-0.3.el4.x86_64.rpmSL 5.x   SRPMS:	firefox-1.5.0.12-3.el5.src.rpm   i386:	firefox-1.5.0.12-3.el5.i386.rpm	firefox-devel-1.5.0.12-3.el5.i386.rpm   x86_64:	firefox-1.5.0.12-3.el5.i386.rpm	firefox-1.5.0.12-3.el5.x86_64.rpm	firefox-devel-1.5.0.12-3.el5.i386.rpm	firefox-devel-1.5.0.12-3.el5.x86_64.rpm-Connie Sieh-Troy Dawson



Security Fixes

Severity

Related News