It was discovered that there was a potential credential stealing attack in epiphany-browser, the default GNOME web browser. When using a sandboxed Content Security Policy (CSP) or the HTML . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3423-1
Update to the new upstream Firefox 3.0.7 / XULRunner 1.9.0.7 fixing multiple security issues: https://www.mozilla.org/en-US/security/known-vulnerabilities/firefox-3.0/ This update also contains new builds of all applications depending on Gecko libraries, built against the new version. Note: after the updated packages are installed, Firefox must be restarted for the update to take effect.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2009-2422 2009-03-08 06:09:09 --------------------------------------------------------------------------------Name : epiphany Product : Fedora 10 Version : 2.24.3 Release : 3.fc10 URL : https://wiki.gnome.org/Apps Summary : GNOME web browser based on the Mozilla rendering engine Description : Epiphany is a simple GNOME web browser based on the Mozilla rendering engine. --------------------------------------------------------------------------------Update Information: Update to the new upstream Firefox 3.0.7 / XULRunner 1.9.0.7 fixing multiple security issues: https://www.mozilla.org/en-US/security/known-vulnerabilities/firefox-3.0/ This update also contains new builds of all applications depending on Gecko libraries, built against the new version. Note: after the updated packages are installed, Firefox must be restarted for the update to take effect. --------------------------------------------------------------------------------ChangeLog: * Fri Mar 6 2009 Jan Horak - 2.24.3-3 - Rebuild against newer gecko * Wed Feb 4 2009 Christopher Aillon - 2.24.3-2 - Rebuild against newer gecko * Fri Jan 16 2009 Matthias Clasen 2.24.3-1 - Update to 2.24.3 * Wed Jan 14 2009 Matěj Cepl 2.24.2.1-2 - Make epiphany own directories for plugins and extensions (#479921). * Mon Jan 5 2009 Christopher Aillon - 2.24.2.1-1 - Update to 2.24.2.1 * Thu Dec 18 2008 Martin Stransky - 2.24.2-5 - build fix to configure * Wed Dec 17 2008Christopher Aillon - 2.24.2-4 - Rebuild against newer gecko * Tue Nov 25 2008 Matthias Clasen - 2.24.2-3 - Update to 2.24.2 --------------------------------------------------------------------------------References: [ 1 ] Bug #488272 - CVE-2009-0771 Firefox 3 Layout Engine Crashes https://bugzilla.redhat.com/show_bug.cgi?id=488272 [ 2 ] Bug #488273 - CVE-2009-0772 Firefox 2 and 3 - Layout engine crashes https://bugzilla.redhat.com/show_bug.cgi?id=488273 [ 3 ] Bug #488276 - CVE-2009-0773 Firefox 3 crashes in the JavaScript engine https://bugzilla.redhat.com/show_bug.cgi?id=488276 [ 4 ] Bug #488283 - CVE-2009-0774 Firefox 2 and 3 crashes in the JavaScript engine https://bugzilla.redhat.com/show_bug.cgi?id=488283 [ 5 ] Bug #488287 - CVE-2009-0775 Firefox XUL Linked Clones Double Free Vulnerability https://bugzilla.redhat.com/show_bug.cgi?id=488287 [ 6 ] Bug #488290 - CVE-2009-0776 Firefox XML data theft via RDFXMLDataSource and cross-domain redirect https://bugzilla.redhat.com/show_bug.cgi?id=488290 [ 7 ] Bug #488292 - CVE-2009-0777 Firefox URL spoofing with invisible control characters https://bugzilla.redhat.com/show_bug.cgi?id=488292 --------------------------------------------------------------------------------This update can be installed with the "yum" update program. Use su -c 'yum update epiphany' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ Fedora-package-announce mailing list
Updated package.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-768 2005-08-17 ---------------------------------------------------------------------Product : Fedora Core 4 Name : epiphany Version : 1.6.5 Release : 1 Summary : GNOME web browser based on the Mozilla rendering engine Description : epiphany is a simple GNOME web browser based on the Mozilla rendering engine ---------------------------------------------------------------------* Wed Aug 17 2005 Marco Pesenti Gritti - 1.6.5-1 - Update to 1.6.5 - Remove patch integrated upstream ---------------------------------------------------------------------This update can be downloaded from: 99fec86f8515989856285e83a549284c SRPMS/epiphany-1.6.5-1.src.rpm f06f4e3da318e50516a10cb6d3956373 ppc/epiphany-1.6.5-1.ppc.rpm e1692fdd30b1a882e5fcaddcc64ed923 ppc/epiphany-devel-1.6.5-1.ppc.rpm da3dc22b947c8e222443ce94b5db3e8a ppc/debug/epiphany-debuginfo-1.6.5-1.ppc.rpm 2b059d8b0e564fc1d984d1f4e0f489f7 x86_64/epiphany-1.6.5-1.x86_64.rpm effb4eb02562be004685a2b685f8f051 x86_64/epiphany-devel-1.6.5-1.x86_64.rpm 16b229aaecd73ad69589aaf5d41404c7 x86_64/debug/epiphany-debuginfo-1.6.5-1.x86_64.rpm cc2e9466c0570142b1f4a29d6f432889 i386/epiphany-1.6.5-1.i386.rpm 6872a06d2cea3cfc83f29581308e925b i386/epiphany-devel-1.6.5-1.i386.rpm 43dc35463f64e1a696c034349c09b498 i386/debug/epiphany-debuginfo-1.6.5-1.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. -----------------------------------------------------------------------fedora-announce-list mailing list
Get the latest Linux and open source security news straight to your inbox.