Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 464
Alerts This Week
Warning Icon 1 464

Scientific Linux SL5.x Critical: xulrunner Security Update CVE-2010-3765

Scientific Large Esm H446
Critical: xulrunner security update
Date: Thu, 28 Oct 2010 11:08:40 -0500
Reply-To: Troy Dawson 
Sender: Security Errata for Scientific Linux
 
From: Troy Dawson 
Subject: Security ERRATA Critical: xulrunner on SL5.x i386/x86_64
Comments: To: "This email address is being protected from spambots. You need JavaScript enabled to view it."
 

Synopsis:	Critical: xulrunner security update
Issue date:	2010-10-27
CVE Names:	CVE-2010-3765

A race condition flaw was found in the way XULRunner handled Document
Object Model (DOM) element properties. Malicious HTML content could
cause an application linked against XULRunner (such as Firefox) to crash
or, potentially, execute arbitrary code with the privileges of the user
running the application. (CVE-2010-3765)

After installing the update, applications using XULRunner must be
restarted for the changes to take effect.

SL 5.x

 SRPMS:
xulrunner-1.9.2.11-4.el5_5.src.rpm
 i386:
xulrunner-1.9.2.11-4.el5_5.i386.rpm
xulrunner-devel-1.9.2.11-4.el5_5.i386.rpm
 x86_64:
xulrunner-1.9.2.11-4.el5_5.i386.rpm
xulrunner-1.9.2.11-4.el5_5.x86_64.rpm
xulrunner-devel-1.9.2.11-4.el5_5.i386.rpm
xulrunner-devel-1.9.2.11-4.el5_5.x86_64.rpm

-Connie Sieh
-Troy Dawson