Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Date: Tue, 27 Nov 2007 15:47:35 -0600 Reply-To: Troy DawsonSender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA for firefox on SL5.x, SL4.x i386/x86_64 Comments: To: " This email address is being protected from spambots. You need JavaScript enabled to view it. "Synopsis: Critical: firefox security update Issue date: 2007-11-26 CVE Names: CVE-2007-5947 CVE-2007-5959 CVE-2007-5960 A cross-site scripting flaw was found in the way Firefox handled the jar: URI scheme. It was possible for a malicious website to leverage this flaw and conduct a cross-site scripting attack against a user running Firefox. (CVE-2007-5947) Several flaws were found in the way Firefox processed certain malformed web content. A webpage containing malicious content could cause Firefox to crash, or potentially execute arbitrary code as the user running Firefox. (CVE-2007-5959) A race condition existed when Firefox set the "window.location" property for a webpage. This flaw could allow a webpage to set an arbitrary Referer header, which may lead to a Cross-site Request Forgery (CSRF) attack against websites that rely only on the Referer header for protection. (CVE-2007-5960) SL 4.x SRPMS: firefox-1.5.0.12-0.8.el4.src.rpm i386: firefox-1.5.0.12-0.8.el4.i386.rpm x86_64: firefox-1.5.0.12-0.8.el4.i386.rpm firefox-1.5.0.12-0.8.el4.x86_64.rpm SL 5.x SRPMS: firefox-1.5.0.12-7.el5.src.rpm i386: firefox-1.5.0.12-7.el5.i386.rpm firefox-devel-1.5.0.12-7.el5.i386.rpm x86_64: firefox-1.5.0.12-7.el5.i386.rpm firefox-1.5.0.12-7.el5.x86_64.rpm firefox-devel-1.5.0.12-7.el5.i386.rpm firefox-devel-1.5.0.12-7.el5.x86_64.rpm -Connie Sieh -Troy Dawson