Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

SciLinux: CVE-2010-2755 Critical: Firefox Invalid Free Flaw

Scientific Large Esm H500
Critical: firefox security update
Date: Mon, 26 Jul 2010 13:30:28 -0500
Reply-To: Troy Dawson 
Sender: Security Errata for Scientific Linux
 
From: Troy Dawson 
Subject: Security ERRATA Critical: firefox on SL4.x, SL5.x i386/x86_64
Comments: To: "This email address is being protected from spambots. You need JavaScript enabled to view it."
 

Synopsis:	Critical: firefox security update
Issue date:	2010-07-23
CVE Names:	CVE-2010-2755

An invalid free flaw was found in Firefox's plugin handler. Malicious
web content could result in an invalid memory pointer being freed,
causing Firefox to crash or, potentially, execute arbitrary code with
the privileges of the user running the Firefox application. (CVE-2010-2755)

After installing the update, Firefox must be restarted for the changes
to take effect.

SL 4.x

 SRPMS:
firefox-3.6.7-3.el4.src.rpm
 i386:
firefox-3.6.7-3.el4.i386.rpm
 x86_64:
firefox-3.6.7-3.el4.i386.rpm
firefox-3.6.7-3.el4.x86_64.rpm

SL 5.x

 SRPMS:
firefox-3.6.7-3.el5.src.rpm
xulrunner-1.9.2.7-3.el5.src.rpm
 i386:
firefox-3.6.7-3.el5.i386.rpm
xulrunner-1.9.2.7-3.el5.i386.rpm
xulrunner-devel-1.9.2.7-3.el5.i386.rpm
 x86_64:
firefox-3.6.7-3.el5.i386.rpm
firefox-3.6.7-3.el5.x86_64.rpm
xulrunner-1.9.2.7-3.el5.i386.rpm
xulrunner-1.9.2.7-3.el5.x86_64.rpm
xulrunner-devel-1.9.2.7-3.el5.i386.rpm
xulrunner-devel-1.9.2.7-3.el5.x86_64.rpm

-Connie Sieh
-Troy Dawson
Your message here