Several flaws were discovered in the browser engine of Firefox. If a user were tricked into viewing a malicious site, a remote attacker could use this to crash the browser or possibly run arbitrary code as the user invoking the program. (CVE-2010-1208, CVE-2010-1209, CVE-2010-1211, CVE-2010-1212) [More...]. ==========================================================Ubuntu Security Notice USN-957-1 July 23, 2010 firefox, firefox-3.0, xulrunner-1.9.2 vulnerabilities CVE-2010-0654, CVE-2010-1205, CVE-2010-1206, CVE-2010-1207, CVE-2010-1208, CVE-2010-1209, CVE-2010-1210, CVE-2010-1211, CVE-2010-1212, CVE-2010-1213, CVE-2010-1214, CVE-2010-1215, CVE-2010-2751, CVE-2010-2752, CVE-2010-2753, CVE-2010-2754 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 8.04 LTS Ubuntu 10.04 LTS This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 8.04 LTS: firefox-3.0 3.6.7+build2+nobinonly-0ubuntu0.8.04.1 xulrunner-1.9.2 1.9.2.7+build2+nobinonly-0ubuntu0.8.04.2 Ubuntu 10.04 LTS: abrowser 3.6.7+build2+nobinonly-0ubuntu0.10.04.1 firefox 3.6.7+build2+nobinonly-0ubuntu0.10.04.1 xulrunner-1.9.2 1.9.2.7+build2+nobinonly-0ubuntu0.10.04.1 After a standard system update you need to restart Firefox to make all the necessary changes. Details follow: Several flaws were discovered in the browser engine of Firefox. If a user were tricked into viewing a malicious site, a remote attacker could use this to crash the browser or possibly run arbitrary code as the user invoking the program. (CVE-2010-1208, CVE-2010-1209, CVE-2010-1211, CVE-2010-1212) An integer overflow was discovered in how Firefox processed plugin parameters. An attacker could exploit this to crash the browser orpossibly run arbitrary code as the user invoking the program. (CVE-2010-1214) A flaw was discovered in the Firefox JavaScript engine. If a user were tricked into viewing a malicious site, a remote attacker code execute arbitrary JavaScript with chrome privileges. (CVE-2010-1215) An integer overflow was discovered in how Firefox processed CSS values. An attacker could exploit this to crash the browser or possibly run arbitrary code as the user invoking the program. (CVE-2010-2752) An integer overflow was discovered in how Firefox interpreted the XUL element. If a user were tricked into viewing a malicious site, a remote attacker could use this to crash the browser or possibly run arbitrary code as the user invoking the program. (CVE-2010-2753) Aki Helin discovered that libpng did not properly handle certain malformed PNG images. If a user were tricked into opening a crafted PNG file, an attacker could cause a denial of service or possibly execute arbitrary code with the privileges of the user invoking the program. (CVE-2010-1205) Yosuke Hasegawa and Vladimir Vukicevic discovered that the same-origin check in Firefox could be bypassed by utilizing the importScripts Web Worker method. If a user were tricked into viewing a malicious website, an attacker could exploit this to read data from other domains. (CVE-2010-1213, CVE-2010-1207) O. Andersen that Firefox did not properly map undefined positions within certain 8 bit encodings. An attacker could utilize this to perform cross-site scripting attacks. (CVE-2010-1210) Michal Zalewski discovered flaws in how Firefox processed the HTTP 204 (no content) code. An attacker could exploit this to spoof the location bar, such as in a phishing attack. (CVE-2010-1206) Jordi Chancel discovered that Firefox did not properly handle when a server responds to an HTTPS request with plaintext and then processes JavaScript history events. An attacker could exploit this to spoof the location bar, such as in a phishing attack.(CVE-2010-2751) Chris Evans discovered that Firefox did not properly process improper CSS selectors. If a user were tricked into viewing a malicious website, an attacker could exploit this to read data from other domains. (CVE-2010-0654) Soroush Dalili discovered that Firefox did not properly handle script error output. An attacker could use this to access URL parameters from other domains. (CVE-2010-2754) Updated packages for Ubuntu 8.04 LTS: Source archives: Size/MD5: 133798 271a64453687ebc18ca01d699037ba45 Size/MD5: 2506 5c9fb294eb76f6f4df27a7d2a6d427b2 Size/MD5: 49883446 e3bdceebdf5bcc94f0f901ce8744a6df Size/MD5: 67144 60a98052c5ff5ebed368edab309f6278 Size/MD5: 2577 15e7061d7023ae309200503d411fe4c7 Size/MD5: 49049246 24374c9313827c30bca434dc15cd7e34 Architecture independent packages: Size/MD5: 69844 85c4e3834feeb1cb861e7d17f0575ee3 Size/MD5: 69664 4a83b2aeb00e2a37445186b7433dd216 Size/MD5: 69684 2617bcda5d2f060181fac4856719f806 Size/MD5: 70070 e48d523346de8d1e8308dda462e8c55a Size/MD5: 69690 fa027b455560cc9624764ed947dd7c8b Size/MD5: 69676 fdfd4efd51efaf4948ac97518bf5df03 Size/MD5: 69708 492a22d9e2bf0f6c3608e44f7d5c5a51 Size/MD5: 69676 65584c1eee074b4a4d8de1b36f3ce72b Size/MD5: 69662 258b1f12d7d52197f810a7d7a870c022 Size/MD5: 69690 35bbb345037c9543954573e9b485bdb3 Size/MD5: 69660 14978d5ad3690c38d48d217ea04b1ae1 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 193518 bb745007d8a4e9d2c439ed8f290120d1 Size/MD5: 197078 fe5d85d4e3604fdd069da27e54638415 Size/MD5: 61884478 ea30e6bf107da86db371d2958cf84fe0 Size/MD5: 69790 0ed39e1bfe2d1ee466df2d3886bae686 Size/MD5: 117538 859fefa229034ba29ea5448f62e187f1 Size/MD5: 70152 317a93572d034577da8f1fadefe9e9be Size/MD5: 12582384 c5e11f9c2125438be7198349f25b8ac2 Size/MD5: 65572054 2b5bfb2c2f72e036910997316bbe90b5 Size/MD5: 4850798 27013710b91e1c0d1a5ffa0160195a28 Size/MD5: 53474 f6c384027fc0cd8081f961b85aabb979 Size/MD5: 75574 66cda9511c09782c1a1ffdb64ef431c6 Size/MD5: 11000546 8ef7230a6e2b4bdd28ede9a0eb624bbe Size/MD5: 29402 1265e1e0ff93e51119e568583d9b8f22 Size/MD5: 7828476 9d0127ac6a486e89c4f1b7428f3e1e04 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 193506 5abc8098f2297ba4b2f53c40205ce046 Size/MD5: 197084 4bbb3f6d4caa58e7bde7405b5f97db8a Size/MD5: 61449850 c81e3823346390ace4376074275eb559 Size/MD5: 69788 2e994d5022894d61a40a15f42e1a7374 Size/MD5: 112764 791c7d6638ca643615c8864273a43ea7 Size/MD5: 70144 74f7f56dee4df37d4552f5ff1b7a89ac Size/MD5: 11091722 9babed8bee9c540cdadba7c0c00c250e Size/MD5: 65735590 c3b0c790d5b3d7669f6aa920e625514b Size/MD5: 4874828 6cead2e3fcf6822f959cec9aeb358424 Size/MD5: 43868 c821bcb229a45c3982adae01c8a61637 Size/MD5: 75572 e6987169d943c59d13754840af856fdd Size/MD5: 9730964 2ba76c99a9d0508b928d8c824d3d0be6 Size/MD5: 29394 2d28252d772eedfc4cd9e244074285ee Size/MD5: 7593148 f85b13abb03715d9519a0136355f3ffa lpia architecture (Low Power Intel Architecture): Size/MD5: 193510 70d2c0431adc92af9cec7b1abaa98d0d Size/MD5: 197068 fd6bc7cf5701e72bb91f5f9674470f94 Size/MD5: 55746708 95ca1c2a9a22fada9fd4a6a583c64448 Size/MD5: 69786 1444a787a8bb4b45d6bc77590bfa896d Size/MD5: 112596 04534f3c7a6247db74229bf72dc7111b Size/MD5: 70148 02b4917b416c9cfd6334be539df3e58e Size/MD5: 10539164 861702956583ec236e96b6c2ce9ae997 Size/MD5: 60039818 7bd06b0f917b91121fa6f4e6c202383b Size/MD5: 48340385ab205c99a0f534128c3e96046d53f35 Size/MD5: 42792 9aa1cba81d55aec0b25fcba965097fb1 Size/MD5: 75570 d2285407e9026fc0dbdd78eec5bcb645 Size/MD5: 9206882 31345981e2585d2562cec2bd29e54882 Size/MD5: 29396 561795934911eaaf1738449c29176691 Size/MD5: 7574132 ef071a3a0c3c6790d3f26ee4bdad3097 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 193514 b21e26ea3e9ec018cb2db75334b2158d Size/MD5: 197086 88facd8fbeff3c362d2157ed3fbe3dd7 Size/MD5: 57310986 b1c659403a8b1a1e0bddc620b66498e0 Size/MD5: 69788 eb428c8c01f6be3aa464777c674190b5 Size/MD5: 117864 9aa59444c252802f3b5924220d55eb08 Size/MD5: 70154 16f689e8a4ca5e39faf84d1a05b284b1 Size/MD5: 11630256 e87ebcc8a4e1662f77973b1459e7e3f8 Size/MD5: 61643232 c1d16ece8283c428c05e4536da749c43 Size/MD5: 4812322 702c04a61b7127d6cc94b2da10c789e9 Size/MD5: 51244 932f5c7499be44f3271211208192b5f5 Size/MD5: 75590 b253bda40f77b58075291b89c4039ba7 Size/MD5: 11048454 24a9d3e6451cbc4576ddd234a5065a3b Size/MD5: 29398 f6750de249a3a06862932c7653140afb Size/MD5: 7977978 b8d79bdb7b195b4b93671b1d3b2d3aed Updated packages for Ubuntu 10.04: Source archives: Size/MD5: 176178 b3bdd80ebdd2d8ee9d699cb687f14d1b Size/MD5: 2579 3ff3f293d113251fd07f955e767fd38f Size/MD5: 49883446 e3bdceebdf5bcc94f0f901ce8744a6df Size/MD5: 59348 ee3d606728404b5dad1e85e265045d4b Size/MD5: 2625 2c49cbc28bea388691e4551196ff463f Size/MD5: 49049246 24374c9313827c30bca434dc15cd7e34 Architecture independent packages: Size/MD5: 80062 8bac3087f159c0257b4bb94730fb9a23 Size/MD5: 79822 b56b1e09e4898613bd90f694546fc1a9 Size/MD5: 79818 d1888fa706d9c49eaac2e867a2fee5af Size/MD5: 79822 35012ede420cce4dafd26d868efcc4f4 Size/MD5: 79826 7f013ba9ec10d5456a7ffedfb28972fa Size/MD5: 79826 11451690afbff5bfe9b479da32429bfd Size/MD5: 79840 cdfdcc87bcc532a8d1f7d62fb49d4e9d Size/MD5: 8936 42ed58848f4ab3663cc59119e0124ddf Size/MD5: 79844 432e5b36c9bc4b70a44f70db6e349ca7 Size/MD5: 79842 d9e6119a134c15addc9eb1702a0afa49 Size/MD5: 79826 8b84744da7e05d09fd61c16750072498 Size/MD5: 79808 c77da23dfc7c77989ba17b4bcd3b5a1c Size/MD5: 79840 42fe71aebabdb6503aac45894eded920 Size/MD5: 79808 389f1620ce70f43288b64e0b1e790de1 Size/MD5: 79832 332988a82ee05d9f955bfcbafb7cd036 Size/MD5: 79846 3048f9eea8d682b0dbc320ebca661f22 Size/MD5: 79812 db5c1c2d6138178f10b57eb1274abf46 Size/MD5: 29688 f14c6acf9496c9cade65f1de2c2d4134 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 207154 35023f4877343fd702e4d28b82347d80 Size/MD5: 62302236 d6673f8182fab86776adaa74ffaf6726 Size/MD5: 79922 6e061ffb64a10641c346f8d021d4f430 Size/MD5: 113964 16644c9344d3e7dc37b88aa2649fb8c0 Size/MD5: 80404 861415506042ce00a13440331b217aec Size/MD5: 12527134 303a5598159fad4242c5e3791701d682 Size/MD5: 64611760 4f316a9717dbecf7929ce326ea5fca9f Size/MD5: 4733724 73d80d8dc55330653564ad1bf6da0728 Size/MD5: 75264 9b3c21aef15ec24abb836af0c7401445 Size/MD5: 10384748 1f7f07e21cf1b948b65140d05298bf46 Size/MD5: 29162 592b61379cbcef106f5c7a58c671cc8a Size/MD5: 203588 4d7bb2460b51f9ecffa4bfda52f09212 Size/MD5: 51050 b1d3abb53790493a98c0a252f7fc8c61 Size/MD5: 7753176 49f87ca1521d5a39654007319d95850b i386 architecture (x86 compatible Intel/AMD): Size/MD5: 207154 6e8ab4cc4a22334a4a846f514b46be30 Size/MD5: 62778246 d56da39268b4a559d285a18538c5d6b7 Size/MD5: 79916 23d444d3f4bec46e6a186da05b3bb2a6 Size/MD5: 113442 b69930c590f6c539a8b85281f7947627 Size/MD5: 80400 caa787e506ce73c86bbd8e01e7a69e8c Size/MD5: 11244268 f7c24d464ea79138f1b960920ba9d22a Size/MD5: 65829462 1b8afbe5079a5b08f24954173c00514b Size/MD5: 4762346 546fcec400c652713bf445f23d28148a Size/MD5: 75260 512f26dbadb3d8e252c4204ede22e83a Size/MD5: 9375274 124047f73321ac42f98e76395077eed8 Size/MD5: 29158 ad60a9a1cccfe4f8702531da45060006 Size/MD5: 203582 d0ea62c91360baf517ef56153d13c35f Size/MD5: 43258 e6fcfdd954455ba31855e0ab7fe17fc1 Size/MD5: 7577650 e98aa4185fdf79f5bbf9c38bfeecc49a powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 207166 925d624cfe3d653ae9b3f2d07e211699 Size/MD5: 59334046 917ff3a144910a891e0fba444b5aae9d Size/MD5: 79920 6777c05f75b0a45daa1a7e944d24089c Size/MD5: 118336 65ace801699a7769a847cdf5de1ac18c Size/MD5: 80404 42f80624b2aadfb3c16966c8949fd9b8 Size/MD5: 12050360 bba84c34b6e475fa55af88acf5b67078 Size/MD5: 64148266 d8486f048a5d181e99f5151b33bed166 Size/MD5: 4703220 80495ffb4b7b1c676b9ad02fa9235bfe Size/MD5: 75270 ec340871c8e9031b76937c99b544cc8f Size/MD5: 10444212 2c13f79bf2f06c6af1ff6367fc4ca47e Size/MD5: 29158 de133902ae85fbc819149a54790b3c0b Size/MD5: 203594 6505596fc236c9d6aa6816b7db752c84 Size/MD5: 50646 ac25d6be9e735bc36732decb081ec893 Size/MD5: 7851984 660e76677f099bd4875176d2256141fe sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 207158 3aefafcdf24111dcea0a2f00f3c4d7e4 Size/MD5: 56631458 204bcfdae61fef2ea48a271f3f942999 Size/MD5: 79918 8380bd71e3b55a14272a5471d8315185 Size/MD5: 109182 d4a4e69e6e0de25f87a77332ef0613d9 Size/MD5: 80402 ec0333aad274d54c09132eca79fb9e75 Size/MD5: 1142089811f6e38c8140613b9750bb737154b42a Size/MD5: 58882828 f70edccb6dcd625204e6291cb4fac28e Size/MD5: 4684742 f94d779ec3ee86bc9fbe3dfaefa6e8ec Size/MD5: 75270 5ce106f544087f6881537ed3969faca5 Size/MD5: 9355980 a564a7b20f7969d85257939dc2305663 Size/MD5: 29158 ed011f2fa20f5f2438582b3c97d6ef5a Size/MD5: 203592 2c1359cff3d94cd2fedf6c281220005b Size/MD5: 42404 4a0951ee7f1d27167a1cb391f79fe9b0 Size/MD5: 7567012 0e0d24f9901ddbcbd03ab51c5d226a49 . Several vulnerabilities in Firefox create opportunities for attackers to disrupt the browser's functionality or run malicious code, presenting serious threats to its users.. Firefox Flaws, Ubuntu Security, Remote Code Execution, Xulrunner Vulnerabilities. . Severity: Critical. LinuxSecurity.com Team
Several flaws were discovered in the Firefox browser and JavaScriptengines. If a user were tricked into viewing a malicious website, a remoteattacker could cause a denial of service or possibly execute arbitrary codewith the privileges of the user invoking the program. (CVE-2009-3070,CVE-2009-3071, CVE-2009-3072, CVE-2009-3074, CVE-2009-3075) [More...]. ==========================================================Ubuntu Security Notice USN-821-1 September 10, 2009 firefox-3.0, xulrunner-1.9 vulnerabilities CVE-2009-3070, CVE-2009-3071, CVE-2009-3072, CVE-2009-3074, CVE-2009-3075, CVE-2009-3076, CVE-2009-3077, CVE-2009-3078, CVE-2009-3079 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 8.04 LTS Ubuntu 8.10 Ubuntu 9.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 8.04 LTS: firefox-3.0 3.0.14+build2+nobinonly-0ubuntu0.8.04.1 xulrunner-1.9 1.9.0.14+build2+nobinonly-0ubuntu0.8.04.1 Ubuntu 8.10: abrowser 3.0.14+build2+nobinonly-0ubuntu0.8.10.1 firefox-3.0 3.0.14+build2+nobinonly-0ubuntu0.8.10.1 xulrunner-1.9 1.9.0.14+build2+nobinonly-0ubuntu0.8.10.1 Ubuntu 9.04: abrowser 3.0.14+build2+nobinonly-0ubuntu0.9.04.1 firefox-3.0 3.0.14+build2+nobinonly-0ubuntu0.9.04.1 xulrunner-1.9 1.9.0.14+build2+nobinonly-0ubuntu0.9.04.1 After a standard system upgrade you need to restart Firefox and any applications that use xulrunner, such as Epiphany, to effect the necessary changes. Details follow: Several flaws were discovered in the Firefox browser and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could cause a denial of service or possibly execute arbitrary code with the privilegesof the user invoking the program. (CVE-2009-3070, CVE-2009-3071, CVE-2009-3072, CVE-2009-3074, CVE-2009-3075) Jesse Ruderman and Dan Kaminsky discovered that Firefox did not adequately inform users when security modules were added or removed via PKCS11. If a user visited a malicious website, an attacker could exploit this to trick the user into installing a malicious PKCS11 module. (CVE-2009-3076) It was discovered that Firefox did not properly manage memory when using XUL tree elements. If a user were tricked into viewing a malicious website, a remote attacker could cause a denial of service or possibly execute arbitrary code with the privileges of the user invoking the program. (CVE-2009-3077) Juan Pablo Lopez Yacubian discovered that Firefox did properly display certain Unicode characters in the location bar and other text fields when using a certain non-Ubuntu font. If a user configured Firefox to use this font, an attacker could exploit this to spoof the location bar, such as in a phishing attack. (CVE-2009-3078) It was discovered that the BrowserFeedWriter in Firefox could be subverted to run JavaScript code from web content with elevated chrome privileges. If a user were tricked into viewing a malicious website, an attacker could exploit this to execute arbitrary code with the privileges of the user invoking the program. (CVE-2009-3079) Updated packages for Ubuntu 8.04 LTS: Source archives: Size/MD5: 106290 9e9affc499213399a986fa8accd06a9a Size/MD5: 2781 1169bce3f68552493e1bc47f7679a585 Size/MD5: 11623385 f575ddd6c1d07a896c87e3aabdb6a96b Size/MD5: 79438 b5a4f3597dd4e38a305a3171d1927522 Size/MD5: 2832 fe9542586e0aeed4db98bc9754010c84 Size/MD5: 40829392 ddbc45f0308e28dd3b0c402a4b5a360c Architecture independent packages: Size/MD5: 66394 72174ccf649aa8d461cd332d7dbabbdf Size/MD5: 66398 9c920413fec6a6b06c750e347c1c0c8c Size/MD5: 66370 13f3b6d7fdc28e9fc9baca59b29d82ac Size/MD5: 66350 bf069a0aa9392565372db2769e861592 Size/MD5: 66508 23e26cd83a18236dbaab01f8fe5aaeb0 Size/MD5: 66414 a88d773868a66825912e3ecbbe6458c6 Size/MD5: 66362 18890f81f405b6ab2407b8e5a8fec102 Size/MD5: 8976 bc00d90537effd641c9870f20d7adf43 Size/MD5: 8968 6fae4a63c0fae5d54f684f6b68acad48 Size/MD5: 66382 e9be69b90e8d5799743ed12c4a08a1b9 Size/MD5: 66350 34b53aab6a91d73b6e86e7e51ac41a3d Size/MD5: 66340 64d663d92ba23d2052732375b473a57e Size/MD5: 8954 fa836fcc39f4baaf79a453031fb67207 Size/MD5: 66372 7f08b2d583935dfd46aea694b04eabbe Size/MD5: 8944 50498e8ac35f06b9a01df8f2974a62b7 Size/MD5: 66340 7a070da0d512f5c3f3ad9f96b80c70bc Size/MD5: 125908 21b5c8032a12b734bd33062d10958ee9 Size/MD5: 235930 999fb4fd67afc30c4be1bf1e49672e81 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 9034 1a506b1b4a1468bbf1317e272d03ed6f Size/MD5: 29578 86cf53ac51dedd10cfe0ee62273bbdce Size/MD5: 1092420 7401a68e65594f21f306ef65b00f367d Size/MD5: 4647288 ff1312bd02e2a31128cbf4270b59c05c Size/MD5: 48654 cfa6a6284f519d05eaf9b60eea118cfd Size/MD5: 9083188 eae522d965df8a53b83d276acd65e134 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 9032 9d487a984344d3ed0f8a7b2c730f0185 Size/MD5: 25738 08d83ad0b59109fa6820780ae01150c5 Size/MD5: 1071526 331c069b2a4c966818c82a7eb510af2a Size/MD5: 4623646 8cba2daa21935980773dacab26133e9c Size/MD5: 38516 71c79ebfcebf608b5f6118024aa91027 Size/MD5: 7808832 abf04f5d5aa172485b80da016d078419 lpia architecture (Low Power Intel Architecture): Size/MD5: 9032 2f2f6f96be0c6fecd6da1ee2545c9391 Size/MD5: 25354 8fa47299dd895c5c2e6c8eaaacc4f5ad Size/MD5: 1068126 48ce6bd344196c6cd26df00d4fba9044 Size/MD5: 4619042821e4d131f91888edf3a0272104535c3 Size/MD5: 37616 125429d355add7494acf357aa04f9616 Size/MD5: 7698406 72296862c611089916229a7e7831705c powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 9032 11d3b37eb99d779dbc55d2ee1b9c9eb2 Size/MD5: 27516 04acec5fa28ef7c97a50f1535f653ec2 Size/MD5: 1085504 8285f1455d39fb25215e37fe054ec089 Size/MD5: 4615032 1fe1d65c796a70cca669fcee65439a0d Size/MD5: 43680 998298d0eaa36980e47edc0a83a58597 Size/MD5: 8660432 1fd769a1433ea8dbeb0da3593602be3e Updated packages for Ubuntu 8.10: Source archives: Size/MD5: 124134 a4f493bfa8ceb53fe415509c918ed5f9 Size/MD5: 2836 d4aa06c8b556870608830012674a1e6d Size/MD5: 11623385 f575ddd6c1d07a896c87e3aabdb6a96b Size/MD5: 251317 8cf331089ed63f0c5e7d2d58bc70595b Size/MD5: 2850 9503e412ad93b458c20413fb550fbdfa Size/MD5: 40829392 ddbc45f0308e28dd3b0c402a4b5a360c Architecture independent packages: Size/MD5: 69232 0e0e0191f99d0c036ba519e2ad60dbf9 Size/MD5: 69134 7a107636a56092a3a66d36820ebcfa17 Size/MD5: 69146 12f90c75baae309a88e5a5940e351a00 Size/MD5: 69110 f6329c2ce6f7f76796aaaaff74339a16 Size/MD5: 69088 ce40e5c5739db0e263421715288807a8 Size/MD5: 69224 4366d7a1f2a5cfa4f8094d20d9b4fad5 Size/MD5: 69150 f2052987595f40591e137610024c12ce Size/MD5: 69102 e951a76c254cbd3606329dc9e0d7fc93 Size/MD5: 8974 aadda3917885d48ccd51b168bb21a15f Size/MD5: 8964 748c8e1473c3b93d2196dc057ca66d83 Size/MD5: 69126 8734b439e2329a44b62f98fc0f22b76e Size/MD5: 69092 f89b08a33e1099ce6f25c23f300333de Size/MD5: 69086 aa561060f068c91f3e3d5bc513b2d443 Size/MD5: 8952 7f0a6aaf6a0165321043c283f16fc4a8 Size/MD5: 69110 286b6a53b24354745e2aa7d70a84d328 Size/MD5: 8938 15f55d83d1fd1ec1e5fb2619d013ffca Size/MD5: 69086 e0f1dc1ccff93feb8941ce339600a249 Size/MD5: 127916 b0e9081b05b1522b2548f00fdf669cdb Size/MD5: 237688 1fc0799898571b51e24bc9271b6857f4 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 203870 b92e19ddd12be1f3804b72125c7ec142 Size/MD5: 202280 25dafb591b5cc4f4dace43dd4aefd201 Size/MD5: 69194 df93faf5875b4b9fa00e1c67d4f36224 Size/MD5: 88634 1e0000d26a93204155065aeefaf14429 Size/MD5: 905518 9eeff4a135156d331a22b4ae53496fd5 Size/MD5: 4566012 0318f73389c28c1bbffe62a11531393f Size/MD5: 47114 8184af91cdd257ac8c993f575df313a8 Size/MD5: 8730940 90ee0983a736326c8938d4ea838fc2cb Size/MD5: 22872 603f86f4153ab6f801813a22d45107dc i386 architecture (x86 compatible Intel/AMD): Size/MD5: 203870 428d8b49b3b546a036d2212a129c5496 Size/MD5: 202280 f5b77814e99d1c9ef22fe5bd80f2d1ca Size/MD5: 69194 7dd60f72213d6be89e4b817235ed30dc Size/MD5: 84670 2b27257da688da1724d03b4abe67d072 Size/MD5: 887792 7254af69a3ae921d274112c1684a9a38 Size/MD5: 4543006 dff65a3b6537d35333a8194e217c5144 Size/MD5: 39384 5e9e74c039b375e3d2951df7c703277a Size/MD5: 7560244 7522b8f84ec46f1ae4a6d0d050bc76eb Size/MD5: 22872 1d2a7de6e37494883784044e2c35521b lpia architecture (Low Power Intel Architecture): Size/MD5: 203868 65150db07b9aa32952449d22ac5d8659 Size/MD5: 202280 a5cdab866d279d1c52939b95d8ac3390 Size/MD5: 69194 79d503da53dd76d8f34e0f3a89e0f8f5 Size/MD5: 84086 2406c742ebfc1ff83d889bc383acdcf6 Size/MD5: 885002 21acaa89fd227e195d53de471640b1bc Size/MD5: 4538650 1f011a078bcebb0a962a94ca96b268e7 Size/MD5: 38416 ccb919a90e27dfc5b19bd3e07eb61632 Size/MD5: 7455510 adcffb83e149950dec130e122394eee4 Size/MD5: 22870 fbc8850bccfef5355d143a04c6be961b powerpc architecture (AppleMacintosh G3/G4/G5): Size/MD5: 203858 6df1fd1dff3856d9bc48ae010c4fd43f Size/MD5: 202292 ee1d9fc1084cc5c4a749202d30c74e10 Size/MD5: 69200 7b26c8db77ce630e9be3195f564548c8 Size/MD5: 86062 febbe97ca61a230f7383e06dd7d51a13 Size/MD5: 899256 ae48628fbce79df8997cc85641b3f199 Size/MD5: 4532660 46a649812318f5a5cfb31507508b8e5c Size/MD5: 42412 c5800c5ab30ecc571c9e212f29366fd8 Size/MD5: 8298266 142ebd56108331af8c82ed8446c78c44 Size/MD5: 22876 d9480b2dfbb214ab525c93bfbafc7f2f sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 203868 b34d2bddd76e531053adf40b650c78df Size/MD5: 202286 ddf93965d547ea461bb024741b341379 Size/MD5: 69194 9c7454f67de9d7c8a87301e216e64dfe Size/MD5: 83736 213e7dea16014156a8a9a06bf9f4cfab Size/MD5: 887504 180783c653bfa175fbeab01fd0e88bc6 Size/MD5: 4519580 399fc54e2d91a6ce6c117f93c75787a6 Size/MD5: 37876 1d1514c84490e809839f4c2a268693e2 Size/MD5: 8116684 9029915c843b14d8a0fd564c3360f052 Size/MD5: 22874 8066e3fa096a09e9932a577580c4110b Updated packages for Ubuntu 9.04: Source archives: Size/MD5: 124332 3a123c6047aba42fb6f772104f6e3997 Size/MD5: 2836 cf0c039acf7221fa478344b781f37fa7 Size/MD5: 11623385 f575ddd6c1d07a896c87e3aabdb6a96b Size/MD5: 252035 1e2c2185fca143c76f136626c3718924 Size/MD5: 2850 efc18ec64bc6104a9148e82ee2693a18 Size/MD5: 40829392 ddbc45f0308e28dd3b0c402a4b5a360c Architecture independent packages: Size/MD5: 69436 aca8cfcfb048be736e72cfa19cfd4069 Size/MD5: 69340 c2e1c85d4ebab9ed52ff1b870217d5d1 Size/MD5: 69350 240dfa802eea86f78e5c00dba75b6963 Size/MD5: 69312 b617ad72a7f5ea612796478c612f69ba Size/MD5: 69302 eee51430ad5ac030a560b0c72f9b1714 Size/MD5: 69430 637f8936c312a800bc501310a42da62f Size/MD5: 69368 f1bac873daa95739c9269de97f6b8c16 Size/MD5: 69310 cbefac16099544c4c8ff163bd55df9b8 Size/MD5: 8976 c8d08c0acb3bf67ce39afa7237f69d0d Size/MD5: 8972 f25aa5d34332243cb183e2f8577e0047 Size/MD5: 69332 1656a97d09cf86c79aa5966a236d7cb3 Size/MD5: 69300 5fe758ae445beb1fc30de541b5339b69 Size/MD5: 69290 839156123fc5dd65b2727c75079198ff Size/MD5: 8952 586702e3b342bd94dcf31208f049e95f Size/MD5: 69318 1d33fa21d4e4ae6ec21fe7ae9659b38a Size/MD5: 8940 1a2942d88f675cd0c6a20e27f6426a13 Size/MD5: 69290 482522f41747ed3bc720f52c0fbe4c04 Size/MD5: 128256 3067d603ad4508d9648d222a90b7c71f Size/MD5: 238082 bc159ae63391c465fa3cd1b3eec49b31 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 204024 2c5f471bae436e068958488d4916d16a Size/MD5: 202478 2fc77e65a6daae7cf44c7400afd323a8 Size/MD5: 69406 fa7d6773c8844216a7490a87cce35fde Size/MD5: 88828 03938a00eb19fedb479c6b9d8ca58656 Size/MD5: 905478 43ab9a6fdf56d42009dec0b1448a5543 Size/MD5: 4565804 5b1fafb67c3d34fe23709c112a5853f1 Size/MD5: 47114 8b20be7e83c2d45a2639492478848cc7 Size/MD5: 8731478 43c820fc227f96b9eeba8160f3b81913 Size/MD5: 23128 e1dc1b6fb5b03a404462bd6ae9388baa i386 architecture (x86 compatible Intel/AMD): Size/MD5: 204034 f9e83b55d27053eb1ea4c52b66f98c5c Size/MD5: 202476 d3b7ccb2d0fb7ee477b5e708f2c9f96c Size/MD5: 69396 9d25f91602196467f78a13c06a94a9f0 Size/MD5: 84894 f8c8178bda2ac487ce1acc9ec4411a98 Size/MD5: 887812 aef7db63c4d7f92a7a28f754904da297 Size/MD5: 4542740 758a9ae7bb055018427d48c8104374e4 Size/MD5: 39374 9d0bbc3e61e43ee08c69e4b6627372c9 Size/MD5: 7560834 11395926ffd2a77db4be8cb03c3a4c35 Size/MD5: 23132 77fe8afe3b67886e649b86d5b7516aed lpia architecture (Low Power IntelArchitecture): Size/MD5: 204028 6f094d99889f85f54b32c5f486d7f420 Size/MD5: 202470 9b9d5f8e4921819cecb2a074de47f9df Size/MD5: 69402 cc4bbef3171ebe53a8ab5a8ca7802179 Size/MD5: 84302 acb670d2713e5fff17e6471b96380a5a Size/MD5: 884950 bd3312134a3a981de2f67492e8e9f054 Size/MD5: 4538550 9ca134d2716b26197b6c8dce0adef6a5 Size/MD5: 38390 144323809d31f05ed24fa81311029bde Size/MD5: 7456482 9ae6a8fbe6f048738468e16d208c3ea9 Size/MD5: 23126 427552373250b82f102795324fddafd1 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 204040 15375281b2bcffce78d034a672827701 Size/MD5: 202482 fdd5fed039e36fcc831ef3c18d8644ee Size/MD5: 69406 cfb13c2ea5274e62eb8e8a8f7dfc7268 Size/MD5: 86280 ef0d3448ed56be77f15ca67a5e219274 Size/MD5: 899248 5858b968b2742030bd5b69bdcc5f7848 Size/MD5: 4532440 6decfb84b596405e544f75bb6951d79e Size/MD5: 42420 51fbaec8ee0a7a0c8e21af955b74823e Size/MD5: 8299006 ea1af9de9ef3d30900be5baa6d9da395 Size/MD5: 23130 3dd32aa5f5e1b0a3fb15f096b3161eb1 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 204036 263092465b2212db3b9ea8c6240c80ec Size/MD5: 202478 9d1051dc103acd0f3498ce005217f60f Size/MD5: 69406 cd7561d9dfce624c585cde1d7ade2b52 Size/MD5: 83916 9d436dc9b84189110ad0fec69a5a92e5 Size/MD5: 887398 a9e0554d70581cb13fccf5781feeec71 Size/MD5: 4519214 c01319699d7b8484333661bb0484482e Size/MD5: 37808 e87f332cb2b11cc4c83480a86d06a35f Size/MD5: 8117282 595a01a18d26da26adacd1f9a8167042 Size/MD5: 23130 bc91e7b155762556f3d66b6b8ab88d27 . Critical notice: Ubuntu addresses various vulnerabilities in Firefox and Xulrunner impacting older versions, presenting significant risks.. Firefox Vulnerabilities, Ubuntu Security Updates, Xulrunner Issues, Denial of Service Threats. . Severity:Important. LinuxSecurity.com Team
Updated firefox packages that fix several security bugs are now available Fedora Core 6. This update has been rated as having critical security impact by the Fedora Security Response Team. Mozilla Firefox is an open source Web browser. Several flaws were found in the way Firefox processed certain malformed JavaScript code. A web page containing malicious JavaScript code could cause Firefox to crash or potentially execute arbitrary code as the user running Firefox. . ---------------------------------------------------------------------Fedora Update Notification FEDORA-2007-549 2007-05-31 ---------------------------------------------------------------------Product : Fedora Core 6 Name : yelp Version : 2.16.0 Release : 13.fc6 Summary : A system documentation reader from the Gnome project Description : Yelp is the Gnome 2 help/documentation browser. It is designed to help you browse all the documentation on your system in one central tool. ---------------------------------------------------------------------Update Information: Updated firefox packages that fix several security bugs are now available Fedora Core 6. This update has been rated as having critical security impact by the Fedora Security Response Team. Mozilla Firefox is an open source Web browser. Several flaws were found in the way Firefox processed certain malformed JavaScript code. A web page containing malicious JavaScript code could cause Firefox to crash or potentially execute arbitrary code as the user running Firefox. (CVE-2007-2867, CVE-2007-2868) A flaw was found in the way Firefox handled certain FTP PASV commands. A malicious FTP server could use this flaw to perform a rudimentary port-scan of machines behind a user's firewall. (CVE-2007-1562) Several denial of service flaws were found in the way Firefox handled certain form and cookie data. A malicious web site that is able to set arbitrary form and cookie data could prevent Firefox from functioningproperly. (CVE-2007-1362, CVE-2007-2869) A flaw was found in the way Firefox handled the addEventListener JavaScript method. A malicious web site could use this method to access or modify sensitive data from another web site. (CVE-2007-2870) A flaw was found in the way Firefox displayed certain web content. A malicious web page could generate content that would overlay user interface elements such as the hostname and security indicators, tricking users into thinking they are visiting a different site. (CVE-2007-2871) Users of Firefox are advised to upgrade to these erratum packages, which contain Firefox version 1.5.0.12 that corrects these issues. ---------------------------------------------------------------------* Wed May 30 2007 Christopher Aillon - 2.16.0-13 - Rebuild against newer gecko ---------------------------------------------------------------------This update can be downloaded from: f180b68f4c5970753df93402214121a63f429aeb SRPMS/yelp-2.16.0-13.fc6.src.rpm f180b68f4c5970753df93402214121a63f429aeb noarch/yelp-2.16.0-13.fc6.src.rpm 51a2f81c7e8e0ec06934f37bfc87d11640b77ead ppc/debug/yelp-debuginfo-2.16.0-13.fc6.ppc.rpm 1779f3eb0565252531055330a3954b22016b202d ppc/yelp-2.16.0-13.fc6.ppc.rpm 59d1165fe5704217a8965c7b863b9a3933d03c53 x86_64/debug/yelp-debuginfo-2.16.0-13.fc6.x86_64.rpm 8c54a35cdabaae9ba415c5a588daf94cc54f1050 x86_64/yelp-2.16.0-13.fc6.x86_64.rpm adfc02cecf94414ff1219855e878a753bcdef44f i386/debug/yelp-debuginfo-2.16.0-13.fc6.i386.rpm 690097b89973a5e2221c1911a66c9583c7e25b78 i386/yelp-2.16.0-13.fc6.i386.rpm This update can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at . ---------------------------------------------------------------------_______________________________________________ Fedora-package-announce mailinglist
Get the latest Linux and open source security news straight to your inbox.