An update for firefox is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Telecommunications Update Service, and Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: firefox security update Advisory ID: RHSA-2023:3597-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:3597 Issue date: 2023-06-14 CVE Names: CVE-2023-34414 CVE-2023-34416 ==================================================================== 1. Summary: An update for firefox is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Telecommunications Update Service, and Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream AUS (v.8.4) - x86_64 Red Hat Enterprise Linux AppStream E4S (v.8.4) - aarch64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux AppStream TUS (v.8.4) - aarch64, ppc64le, s390x, x86_64 3. Description: Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability. This update upgrades Firefox to version 102.12.0 ESR. Security Fix(es): * Mozilla: Click-jacking certificate exceptions through rendering lag (CVE-2023-34414) * Mozilla: Memory safety bugs fixed in Firefox 114 and Firefox ESR 102.12 (CVE-2023-34416) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and otherrelated information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the update, Firefox must be restarted for the changes to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 2212841 - CVE-2023-34414 Mozilla: Click-jacking certificate exceptions through rendering lag 2212842 - CVE-2023-34416 Mozilla: Memory safety bugs fixed in Firefox 114 and Firefox ESR 102.12 6. Package List: Red Hat Enterprise Linux AppStream AUS (v.8.4): Source: firefox-102.12.0-1.el8_4.src.rpm x86_64: firefox-102.12.0-1.el8_4.x86_64.rpm firefox-debuginfo-102.12.0-1.el8_4.x86_64.rpm firefox-debugsource-102.12.0-1.el8_4.x86_64.rpm Red Hat Enterprise Linux AppStream E4S (v.8.4): Source: firefox-102.12.0-1.el8_4.src.rpm aarch64: firefox-102.12.0-1.el8_4.aarch64.rpm firefox-debuginfo-102.12.0-1.el8_4.aarch64.rpm firefox-debugsource-102.12.0-1.el8_4.aarch64.rpm ppc64le: firefox-102.12.0-1.el8_4.ppc64le.rpm firefox-debuginfo-102.12.0-1.el8_4.ppc64le.rpm firefox-debugsource-102.12.0-1.el8_4.ppc64le.rpm s390x: firefox-102.12.0-1.el8_4.s390x.rpm firefox-debuginfo-102.12.0-1.el8_4.s390x.rpm firefox-debugsource-102.12.0-1.el8_4.s390x.rpm x86_64: firefox-102.12.0-1.el8_4.x86_64.rpm firefox-debuginfo-102.12.0-1.el8_4.x86_64.rpm firefox-debugsource-102.12.0-1.el8_4.x86_64.rpm Red Hat Enterprise Linux AppStream TUS(v.8.4): Source: firefox-102.12.0-1.el8_4.src.rpm aarch64: firefox-102.12.0-1.el8_4.aarch64.rpm firefox-debuginfo-102.12.0-1.el8_4.aarch64.rpm firefox-debugsource-102.12.0-1.el8_4.aarch64.rpm ppc64le: firefox-102.12.0-1.el8_4.ppc64le.rpm firefox-debuginfo-102.12.0-1.el8_4.ppc64le.rpm firefox-debugsource-102.12.0-1.el8_4.ppc64le.rpm s390x: firefox-102.12.0-1.el8_4.s390x.rpm firefox-debuginfo-102.12.0-1.el8_4.s390x.rpm firefox-debugsource-102.12.0-1.el8_4.s390x.rpm x86_64: firefox-102.12.0-1.el8_4.x86_64.rpm firefox-debuginfo-102.12.0-1.el8_4.x86_64.rpm firefox-debugsource-102.12.0-1.el8_4.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2023-34414 https://access.redhat.com/security/cve/CVE-2023-34416 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBZIm2/tzjgjWX9erEAQhp+g/9FXjVXchFC944VqlrMtRxln9zZ8LcGKuP 03VGBkhqk49RWcC2aLHELIESu0LsWfvgS4HBfyNIZUVA3VsVEtMhfNTA6NbchA9k j194GJaw0X02YGAiXzUGfLzytndAiHRdBV2ZxMDN4LkFOVryJCpaRlmu6muNrTIX csvTyTbNOzrhExfJxMZJvYEg0VMd6R+lXvWnGA6AdlSdFrzsRxDJfIReM36g8Afj oOei4GFPYspdTWQ6s80fTzH/gpN5jbVFiM6QXpNSB548ordSf1J8ntO/oKYP7Nlq 0RiNIjU5ygLjpkjA+9WuGoXQaAiv8HezI26Bs5wQfCO8Sro8Jc/uxAQI7p13ZS3e eOwb2juTsxhkEOthySmvQP8zMZo6/XdZWAuQjzlY2vyCOqs3DrMIQu/SLUZA2Z/V aasdnSPYQmpsTkCtlOmz0DnLM5resYlkNvK5bcmBsf7OZxjPTAcmRq2W8FlhALL7 /tuN61rV4sGy/Pm8tQNvjrYbe1yz1LrN1SHAqfpPxDRRKsfU9z54Iw27c8wDxS1f zjuk8MrwDlUlh9JdXiWRi+tj7ZIVOYWRZi2BfYS0Ya04I2yY2Ij/p8fPijA9XFPn cXEEBjEIAC7qcZyv/gKvh2Wg177Rhzu5MhGKqVCqeeQuwYZj1mgXmlMmVGYXJu1q CK+lWQUTyUE=/vWN -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for firefox is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: firefox security update Advisory ID: RHSA-2023:1367-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:1367 Issue date: 2023-03-21 CVE Names: CVE-2023-25751 CVE-2023-25752 CVE-2023-28162 CVE-2023-28164 CVE-2023-28176 ==================================================================== 1. Summary: An update for firefox is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream EUS (v.8.6) - aarch64, ppc64le, s390x, x86_64 3. Description: Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability. This update upgrades Firefox to version 102.9.0 ESR. Security Fix(es): * Mozilla: Incorrect code generation during JIT compilation (CVE-2023-25751) * Mozilla: Memory safety bugs fixed in Firefox 111 and Firefox ESR 102.9 (CVE-2023-28176) * Mozilla: Potential out-of-bounds when accessing throttled streams (CVE-2023-25752) * Mozilla: Invalid downcast in Worklets (CVE-2023-28162) * Mozilla: URL being dragged from a removed cross-origin iframe into the same tab triggered navigation (CVE-2023-28164) For more details about the security issue(s), including the impact, a CVSS score,acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the update, Firefox must be restarted for the changes to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 2178458 - CVE-2023-25751 Mozilla: Incorrect code generation during JIT compilation 2178460 - CVE-2023-25752 Mozilla: Potential out-of-bounds when accessing throttled streams 2178466 - CVE-2023-28162 Mozilla: Invalid downcast in Worklets 2178470 - CVE-2023-28164 Mozilla: URL being dragged from a removed cross-origin iframe into the same tab triggered navigation 2178472 - CVE-2023-28176 Mozilla: Memory safety bugs fixed in Firefox 111 and Firefox ESR 102.9 6. Package List: Red Hat Enterprise Linux AppStream EUS (v.8.6): Source: firefox-102.9.0-3.el8_6.src.rpm aarch64: firefox-102.9.0-3.el8_6.aarch64.rpm firefox-debuginfo-102.9.0-3.el8_6.aarch64.rpm firefox-debugsource-102.9.0-3.el8_6.aarch64.rpm ppc64le: firefox-102.9.0-3.el8_6.ppc64le.rpm firefox-debuginfo-102.9.0-3.el8_6.ppc64le.rpm firefox-debugsource-102.9.0-3.el8_6.ppc64le.rpm s390x: firefox-102.9.0-3.el8_6.s390x.rpm firefox-debuginfo-102.9.0-3.el8_6.s390x.rpm firefox-debugsource-102.9.0-3.el8_6.s390x.rpm x86_64: firefox-102.9.0-3.el8_6.x86_64.rpm firefox-debuginfo-102.9.0-3.el8_6.x86_64.rpm firefox-debugsource-102.9.0-3.el8_6.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7.References: https://access.redhat.com/security/cve/CVE-2023-25751 https://access.redhat.com/security/cve/CVE-2023-25752 https://access.redhat.com/security/cve/CVE-2023-28162 https://access.redhat.com/security/cve/CVE-2023-28164 https://access.redhat.com/security/cve/CVE-2023-28176 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBZBxe+dzjgjWX9erEAQg6+w//e4W6RCA+d80cXa9iSRY7h/h6HkcfIypm y0xTEXOxgLD5ob1quXdik9AWJkO0dCyIxG1GYgvCRO/p2Wf4ImIfgrN/aBL3Wrim F+AS19ZxFpyzr3dEpwuJ+pzSKlsTBGAixegbBDjBRlt2pQtKj/a66flrVGjXGx8x PtXP0Q7HtFrucrcKjKWD6tF7wScIYmdKjRH0LRGTzooLp+5GeVhD6b7GDlLDN5gU xA77lN3DhAOwiezHb0rUxrP+A7pD6K7A61a5KNQHgIhsdu5u2ScCdh4ZUr1R/szf rahIXaxFx0adZuHKxZf7ADNZZ630lH5Pvrj6v9v3Y9wkB1ukcurdtGYU+mpYIikZ w5QBwVzInnMYgfiOcJKSotPBUtvdToKIRgIfYeCm81jtoWgMbQGcFSGZJ2ahE2ix xeAMb+hBZvqI/Y3j5jWfFGSj9e+3+nCS82mexBOkW2Hvm5m4siHyZlcw1T4dMNaA BrpahZ3G9KJMVePHhLbx/q3e8LOvSYqyyE0KrgfiYLQy2R6241Qm7tul9c8z04I6 1ChSO2/2C0xL+Ujq9BvcLP/h4JHUFiFUaNrLhJyBIohODL+EoKnjznkobyXAG6gv z7IaqxAy9htlq3vBdvtQKn1oOSZX2gERzUmDaYctnXZETBKGtvYGJhEyMV5QdFdX VewXOXbdMsU=LycA -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Update to new upstream Firefox version 3.0.11, fixing multiple security issues detailed in the upstream advisories: https://www.mozilla.org/en-US/security/known-vulnerabilities/firefox-3.0/ Update also includes all packages depending on gecko-libs rebuild against new version of Firefox / XULRunner.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-6411 2009-06-15 22:07:28 -------------------------------------------------------------------------------- Name : mozvoikko Product : Fedora 9 Version : 0.9.5 Release : 11.fc9 URL : https://voikko.puimula.org/ Summary : Finnish Voikko spell-checker extension for Mozilla programs Description : This is mozvoikko, an extension for Mozilla programs for using the Finnish spell-checker Voikko. -------------------------------------------------------------------------------- Update Information: Update to new upstream Firefox version 3.0.11, fixing multiple security issues detailed in the upstream advisories: https://www.mozilla.org/en-US/security/known-vulnerabilities/firefox-3.0/ Update also includes all packages depending on gecko-libs rebuild against new version of Firefox / XULRunner. -------------------------------------------------------------------------------- References: [ 1 ] Bug #503568 - CVE-2009-1392 Firefox browser engine crashes https://bugzilla.redhat.com/show_bug.cgi?id=503568 [ 2 ] Bug #503569 - CVE-2009-1832 Firefox double frame construction flaw https://bugzilla.redhat.com/show_bug.cgi?id=503569 [ 3 ] Bug #503570 - CVE-2009-1833 Firefox JavaScript engine crashes https://bugzilla.redhat.com/show_bug.cgi?id=503570 [ 4 ] Bug #503573 - CVE-2009-1834 Firefox URL spoofing with invalid unicode characters https://bugzilla.redhat.com/show_bug.cgi?id=503573 [ 5 ] Bug #503576 - CVE-2009-1835 Firefox Arbitrary domain cookie access by local file: resources https://bugzilla.redhat.com/show_bug.cgi?id=503576 [ 6 ] Bug #503578 - CVE-2009-1836 Firefox SSL tampering via non-200 responses to proxy CONNECT requests https://bugzilla.redhat.com/show_bug.cgi?id=503578 [ 7 ] Bug #503579 - CVE-2009-1837 Firefox Race condition while accessing the private data of a NPObject JS wrapper class object https://bugzilla.redhat.com/show_bug.cgi?id=503579 [ 8 ] Bug #503580 - CVE-2009-1838 Firefox arbitrary code execution flaw https://bugzilla.redhat.com/show_bug.cgi?id=503580 [ 9 ] Bug #503581 - CVE-2009-1839 Firefox information disclosure flaw https://bugzilla.redhat.com/show_bug.cgi?id=503581 [ 10 ] Bug #503582 - CVE-2009-1840 Firefox XUL scripts skip some security checks https://bugzilla.redhat.com/show_bug.cgi?id=503582 [ 11 ] Bug #503583 - CVE-2009-1841 Firefox JavaScript arbitrary code execution https://bugzilla.redhat.com/show_bug.cgi?id=503583 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update mozvoikko' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list
An updated firefox package that fixes various security issues is now available for Red Hat Enterprise Linux 4 and 5. This update has been rated as having critical security impact by the Red Hat Security Response Team.. ==================================================================== Red Hat Security Advisory Synopsis: Critical: firefox security update Advisory ID: RHSA-2008:0978-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2008:0978.html Issue date: 2008-11-12 CVE Names: CVE-2008-0017 CVE-2008-5014 CVE-2008-5015 CVE-2008-5016 CVE-2008-5017 CVE-2008-5018 CVE-2008-5019 CVE-2008-5021 CVE-2008-5022 CVE-2008-5023 CVE-2008-5024 ==================================================================== 1. Summary: An updated firefox package that fixes various security issues is now available for Red Hat Enterprise Linux 4 and 5. This update has been rated as having critical security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Enterprise Linux Desktop version 4 - i386, x86_64 Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64 Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64 RHEL Desktop Workstation (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64 3. Description: Mozilla Firefox is an open source Web browser. Several flaws were found in the processing of malformed web content. A web page containing malicious content could cause Firefox to crash or, potentially, execute arbitrary code as the user running Firefox. (CVE-2008-0017, CVE-2008-5014, CVE-2008-5016, CVE-2008-5017, CVE-2008-5018, CVE-2008-5019, CVE-2008-5021) Several flaws were found in the waymalformed content was processed. A web site containing specially-crafted content could potentially trick a Firefox user into surrendering sensitive information. (CVE-2008-5022, CVE-2008-5023, CVE-2008-5024) A flaw was found in the way Firefox opened "file:" URIs. If a file: URI was loaded in the same tab as a chrome or privileged "about:" page, the file: URI could execute arbitrary code with the permissions of the user running Firefox. (CVE-2008-5015) For technical details regarding these flaws, please see the Mozilla security advisories for Firefox 3.0.4. You can find a link to the Mozilla advisories in the References section. All firefox users should upgrade to these updated packages, which contain backported patches that correct these issues. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. This update is available via Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at 5. Bugs fixed (https://bugzilla.redhat.com/): 454283 - firefox-2.0-getstartpage.patch breaks extensions which set homepage 470873 - CVE-2008-5014 Mozilla crash and remote code execution via __proto__ tampering 470876 - CVE-2008-5015 Mozilla file: URIs inherit chrome privileges 470881 - CVE-2008-5016 Mozilla crash with evidence of memory corruption 470883 - CVE-2008-5017 Mozilla crash with evidence of memory corruption 470884 - CVE-2008-5018 Mozilla crash with evidence of memory corruption 470889 - CVE-2008-5019 Mozilla XSS via session restore 470892 - CVE-2008-0017 Mozilla buffer overflow in http-index-format parser 470894 - CVE-2008-5021 Mozilla crash and remote code execution in nsFrameManager 470895 - CVE-2008-5022 Mozilla nsXMLHttpRequest::NotifyEventListeners() same-origin violation 470898 - CVE-2008-5023 Mozilla -moz-binding property bypasses security checks on codebase principals 470902 - CVE-2008-5024 Mozilla parsing error in E4X default namespace 6. PackageList: Red Hat Enterprise Linux AS version 4: Source: i386: firefox-3.0.4-1.el4.i386.rpm firefox-debuginfo-3.0.4-1.el4.i386.rpm nss-3.12.1.1-3.el4.i386.rpm nss-debuginfo-3.12.1.1-3.el4.i386.rpm nss-devel-3.12.1.1-3.el4.i386.rpm ia64: firefox-3.0.4-1.el4.ia64.rpm firefox-debuginfo-3.0.4-1.el4.ia64.rpm nss-3.12.1.1-3.el4.i386.rpm nss-3.12.1.1-3.el4.ia64.rpm nss-debuginfo-3.12.1.1-3.el4.ia64.rpm nss-devel-3.12.1.1-3.el4.ia64.rpm ppc: firefox-3.0.4-1.el4.ppc.rpm firefox-debuginfo-3.0.4-1.el4.ppc.rpm nss-3.12.1.1-3.el4.ppc.rpm nss-3.12.1.1-3.el4.ppc64.rpm nss-debuginfo-3.12.1.1-3.el4.ppc.rpm nss-debuginfo-3.12.1.1-3.el4.ppc64.rpm nss-devel-3.12.1.1-3.el4.ppc.rpm s390: firefox-3.0.4-1.el4.s390.rpm firefox-debuginfo-3.0.4-1.el4.s390.rpm nss-3.12.1.1-3.el4.s390.rpm nss-debuginfo-3.12.1.1-3.el4.s390.rpm nss-devel-3.12.1.1-3.el4.s390.rpm s390x: firefox-3.0.4-1.el4.s390x.rpm firefox-debuginfo-3.0.4-1.el4.s390x.rpm nss-3.12.1.1-3.el4.s390.rpm nss-3.12.1.1-3.el4.s390x.rpm nss-debuginfo-3.12.1.1-3.el4.s390x.rpm nss-devel-3.12.1.1-3.el4.s390x.rpm x86_64: firefox-3.0.4-1.el4.x86_64.rpm firefox-debuginfo-3.0.4-1.el4.x86_64.rpm nss-3.12.1.1-3.el4.i386.rpm nss-3.12.1.1-3.el4.x86_64.rpm nss-debuginfo-3.12.1.1-3.el4.x86_64.rpm nss-devel-3.12.1.1-3.el4.x86_64.rpm Red Hat Enterprise Linux Desktop version 4: Source: i386: firefox-3.0.4-1.el4.i386.rpm firefox-debuginfo-3.0.4-1.el4.i386.rpm nss-3.12.1.1-3.el4.i386.rpm nss-debuginfo-3.12.1.1-3.el4.i386.rpm nss-devel-3.12.1.1-3.el4.i386.rpm x86_64: firefox-3.0.4-1.el4.x86_64.rpm firefox-debuginfo-3.0.4-1.el4.x86_64.rpm nss-3.12.1.1-3.el4.i386.rpm nss-3.12.1.1-3.el4.x86_64.rpm nss-debuginfo-3.12.1.1-3.el4.x86_64.rpm nss-devel-3.12.1.1-3.el4.x86_64.rpm Red Hat Enterprise Linux ES version4: Source: i386: firefox-3.0.4-1.el4.i386.rpm firefox-debuginfo-3.0.4-1.el4.i386.rpm nss-3.12.1.1-3.el4.i386.rpm nss-debuginfo-3.12.1.1-3.el4.i386.rpm nss-devel-3.12.1.1-3.el4.i386.rpm ia64: firefox-3.0.4-1.el4.ia64.rpm firefox-debuginfo-3.0.4-1.el4.ia64.rpm nss-3.12.1.1-3.el4.i386.rpm nss-3.12.1.1-3.el4.ia64.rpm nss-debuginfo-3.12.1.1-3.el4.ia64.rpm nss-devel-3.12.1.1-3.el4.ia64.rpm x86_64: firefox-3.0.4-1.el4.x86_64.rpm firefox-debuginfo-3.0.4-1.el4.x86_64.rpm nss-3.12.1.1-3.el4.i386.rpm nss-3.12.1.1-3.el4.x86_64.rpm nss-debuginfo-3.12.1.1-3.el4.x86_64.rpm nss-devel-3.12.1.1-3.el4.x86_64.rpm Red Hat Enterprise Linux WS version 4: Source: i386: firefox-3.0.4-1.el4.i386.rpm firefox-debuginfo-3.0.4-1.el4.i386.rpm nss-3.12.1.1-3.el4.i386.rpm nss-debuginfo-3.12.1.1-3.el4.i386.rpm nss-devel-3.12.1.1-3.el4.i386.rpm ia64: firefox-3.0.4-1.el4.ia64.rpm firefox-debuginfo-3.0.4-1.el4.ia64.rpm nss-3.12.1.1-3.el4.i386.rpm nss-3.12.1.1-3.el4.ia64.rpm nss-debuginfo-3.12.1.1-3.el4.ia64.rpm nss-devel-3.12.1.1-3.el4.ia64.rpm x86_64: firefox-3.0.4-1.el4.x86_64.rpm firefox-debuginfo-3.0.4-1.el4.x86_64.rpm nss-3.12.1.1-3.el4.i386.rpm nss-3.12.1.1-3.el4.x86_64.rpm nss-debuginfo-3.12.1.1-3.el4.x86_64.rpm nss-devel-3.12.1.1-3.el4.x86_64.rpm Red Hat Enterprise Linux Desktop (v. 5client): Source: i386: devhelp-0.12-20.el5.i386.rpm devhelp-debuginfo-0.12-20.el5.i386.rpm firefox-3.0.4-1.el5.i386.rpm firefox-debuginfo-3.0.4-1.el5.i386.rpm nss-3.12.1.1-3.el5.i386.rpm nss-debuginfo-3.12.1.1-3.el5.i386.rpm nss-tools-3.12.1.1-3.el5.i386.rpm xulrunner-1.9.0.4-1.el5.i386.rpm xulrunner-debuginfo-1.9.0.4-1.el5.i386.rpm yelp-2.16.0-22.el5.i386.rpm yelp-debuginfo-2.16.0-22.el5.i386.rpm x86_64: devhelp-0.12-20.el5.i386.rpm devhelp-0.12-20.el5.x86_64.rpm devhelp-debuginfo-0.12-20.el5.i386.rpm devhelp-debuginfo-0.12-20.el5.x86_64.rpm firefox-3.0.4-1.el5.i386.rpm firefox-3.0.4-1.el5.x86_64.rpm firefox-debuginfo-3.0.4-1.el5.i386.rpm firefox-debuginfo-3.0.4-1.el5.x86_64.rpm nss-3.12.1.1-3.el5.i386.rpm nss-3.12.1.1-3.el5.x86_64.rpm nss-debuginfo-3.12.1.1-3.el5.i386.rpm nss-debuginfo-3.12.1.1-3.el5.x86_64.rpm nss-tools-3.12.1.1-3.el5.x86_64.rpm xulrunner-1.9.0.4-1.el5.i386.rpm xulrunner-1.9.0.4-1.el5.x86_64.rpm xulrunner-debuginfo-1.9.0.4-1.el5.i386.rpm xulrunner-debuginfo-1.9.0.4-1.el5.x86_64.rpm yelp-2.16.0-22.el5.x86_64.rpm yelp-debuginfo-2.16.0-22.el5.x86_64.rpm RHEL Desktop Workstation (v. 5client): Source: i386: devhelp-debuginfo-0.12-20.el5.i386.rpm devhelp-devel-0.12-20.el5.i386.rpm nss-debuginfo-3.12.1.1-3.el5.i386.rpm nss-devel-3.12.1.1-3.el5.i386.rpm nss-pkcs11-devel-3.12.1.1-3.el5.i386.rpm xulrunner-debuginfo-1.9.0.4-1.el5.i386.rpm xulrunner-devel-1.9.0.4-1.el5.i386.rpm xulrunner-devel-unstable-1.9.0.4-1.el5.i386.rpm x86_64: devhelp-debuginfo-0.12-20.el5.i386.rpm devhelp-debuginfo-0.12-20.el5.x86_64.rpm devhelp-devel-0.12-20.el5.i386.rpm devhelp-devel-0.12-20.el5.x86_64.rpm nss-debuginfo-3.12.1.1-3.el5.i386.rpm nss-debuginfo-3.12.1.1-3.el5.x86_64.rpm nss-devel-3.12.1.1-3.el5.i386.rpm nss-devel-3.12.1.1-3.el5.x86_64.rpm nss-pkcs11-devel-3.12.1.1-3.el5.i386.rpm nss-pkcs11-devel-3.12.1.1-3.el5.x86_64.rpm xulrunner-debuginfo-1.9.0.4-1.el5.i386.rpm xulrunner-debuginfo-1.9.0.4-1.el5.x86_64.rpm xulrunner-devel-1.9.0.4-1.el5.i386.rpm xulrunner-devel-1.9.0.4-1.el5.x86_64.rpm xulrunner-devel-unstable-1.9.0.4-1.el5.x86_64.rpm Red Hat Enterprise Linux (v. 5server): Source: i386: devhelp-0.12-20.el5.i386.rpm devhelp-debuginfo-0.12-20.el5.i386.rpm devhelp-devel-0.12-20.el5.i386.rpm firefox-3.0.4-1.el5.i386.rpm firefox-debuginfo-3.0.4-1.el5.i386.rpm nss-3.12.1.1-3.el5.i386.rpm nss-debuginfo-3.12.1.1-3.el5.i386.rpm nss-devel-3.12.1.1-3.el5.i386.rpm nss-pkcs11-devel-3.12.1.1-3.el5.i386.rpm nss-tools-3.12.1.1-3.el5.i386.rpm xulrunner-1.9.0.4-1.el5.i386.rpm xulrunner-debuginfo-1.9.0.4-1.el5.i386.rpm xulrunner-devel-1.9.0.4-1.el5.i386.rpm xulrunner-devel-unstable-1.9.0.4-1.el5.i386.rpm yelp-2.16.0-22.el5.i386.rpm yelp-debuginfo-2.16.0-22.el5.i386.rpm ia64: devhelp-0.12-20.el5.ia64.rpm devhelp-debuginfo-0.12-20.el5.ia64.rpm devhelp-devel-0.12-20.el5.ia64.rpm firefox-3.0.4-1.el5.ia64.rpm firefox-debuginfo-3.0.4-1.el5.ia64.rpm nss-3.12.1.1-3.el5.i386.rpm nss-3.12.1.1-3.el5.ia64.rpm nss-debuginfo-3.12.1.1-3.el5.i386.rpm nss-debuginfo-3.12.1.1-3.el5.ia64.rpm nss-devel-3.12.1.1-3.el5.ia64.rpm nss-pkcs11-devel-3.12.1.1-3.el5.ia64.rpm nss-tools-3.12.1.1-3.el5.ia64.rpm xulrunner-1.9.0.4-1.el5.ia64.rpm xulrunner-debuginfo-1.9.0.4-1.el5.ia64.rpm xulrunner-devel-1.9.0.4-1.el5.ia64.rpm xulrunner-devel-unstable-1.9.0.4-1.el5.ia64.rpm yelp-2.16.0-22.el5.ia64.rpm yelp-debuginfo-2.16.0-22.el5.ia64.rpm ppc: devhelp-0.12-20.el5.ppc.rpm devhelp-debuginfo-0.12-20.el5.ppc.rpm devhelp-devel-0.12-20.el5.ppc.rpm firefox-3.0.4-1.el5.ppc.rpm firefox-debuginfo-3.0.4-1.el5.ppc.rpm nss-3.12.1.1-3.el5.ppc.rpm nss-3.12.1.1-3.el5.ppc64.rpm nss-debuginfo-3.12.1.1-3.el5.ppc.rpm nss-debuginfo-3.12.1.1-3.el5.ppc64.rpm nss-devel-3.12.1.1-3.el5.ppc.rpm nss-devel-3.12.1.1-3.el5.ppc64.rpm nss-pkcs11-devel-3.12.1.1-3.el5.ppc.rpm nss-pkcs11-devel-3.12.1.1-3.el5.ppc64.rpm nss-tools-3.12.1.1-3.el5.ppc.rpm xulrunner-1.9.0.4-1.el5.ppc.rpm xulrunner-1.9.0.4-1.el5.ppc64.rpm xulrunner-debuginfo-1.9.0.4-1.el5.ppc.rpm xulrunner-debuginfo-1.9.0.4-1.el5.ppc64.rpm xulrunner-devel-1.9.0.4-1.el5.ppc.rpm xulrunner-devel-1.9.0.4-1.el5.ppc64.rpm xulrunner-devel-unstable-1.9.0.4-1.el5.ppc.rpm yelp-2.16.0-22.el5.ppc.rpm yelp-debuginfo-2.16.0-22.el5.ppc.rpm s390x: devhelp-0.12-20.el5.s390.rpm devhelp-0.12-20.el5.s390x.rpm devhelp-debuginfo-0.12-20.el5.s390.rpm devhelp-debuginfo-0.12-20.el5.s390x.rpm devhelp-devel-0.12-20.el5.s390.rpm devhelp-devel-0.12-20.el5.s390x.rpm firefox-3.0.4-1.el5.s390.rpm firefox-3.0.4-1.el5.s390x.rpm firefox-debuginfo-3.0.4-1.el5.s390.rpm firefox-debuginfo-3.0.4-1.el5.s390x.rpm nss-3.12.1.1-3.el5.s390.rpm nss-3.12.1.1-3.el5.s390x.rpm nss-debuginfo-3.12.1.1-3.el5.s390.rpm nss-debuginfo-3.12.1.1-3.el5.s390x.rpm nss-devel-3.12.1.1-3.el5.s390.rpm nss-devel-3.12.1.1-3.el5.s390x.rpm nss-pkcs11-devel-3.12.1.1-3.el5.s390.rpm nss-pkcs11-devel-3.12.1.1-3.el5.s390x.rpm nss-tools-3.12.1.1-3.el5.s390x.rpm xulrunner-1.9.0.4-1.el5.s390.rpm xulrunner-1.9.0.4-1.el5.s390x.rpm xulrunner-debuginfo-1.9.0.4-1.el5.s390.rpm xulrunner-debuginfo-1.9.0.4-1.el5.s390x.rpm xulrunner-devel-1.9.0.4-1.el5.s390.rpm xulrunner-devel-1.9.0.4-1.el5.s390x.rpm xulrunner-devel-unstable-1.9.0.4-1.el5.s390x.rpm yelp-2.16.0-22.el5.s390x.rpm yelp-debuginfo-2.16.0-22.el5.s390x.rpm x86_64: devhelp-0.12-20.el5.i386.rpm devhelp-0.12-20.el5.x86_64.rpm devhelp-debuginfo-0.12-20.el5.i386.rpm devhelp-debuginfo-0.12-20.el5.x86_64.rpm devhelp-devel-0.12-20.el5.i386.rpm devhelp-devel-0.12-20.el5.x86_64.rpm firefox-3.0.4-1.el5.i386.rpm firefox-3.0.4-1.el5.x86_64.rpm firefox-debuginfo-3.0.4-1.el5.i386.rpm firefox-debuginfo-3.0.4-1.el5.x86_64.rpm nss-3.12.1.1-3.el5.i386.rpm nss-3.12.1.1-3.el5.x86_64.rpm nss-debuginfo-3.12.1.1-3.el5.i386.rpm nss-debuginfo-3.12.1.1-3.el5.x86_64.rpm nss-devel-3.12.1.1-3.el5.i386.rpm nss-devel-3.12.1.1-3.el5.x86_64.rpm nss-pkcs11-devel-3.12.1.1-3.el5.i386.rpm nss-pkcs11-devel-3.12.1.1-3.el5.x86_64.rpm nss-tools-3.12.1.1-3.el5.x86_64.rpm xulrunner-1.9.0.4-1.el5.i386.rpm xulrunner-1.9.0.4-1.el5.x86_64.rpm xulrunner-debuginfo-1.9.0.4-1.el5.i386.rpm xulrunner-debuginfo-1.9.0.4-1.el5.x86_64.rpm xulrunner-devel-1.9.0.4-1.el5.i386.rpm xulrunner-devel-1.9.0.4-1.el5.x86_64.rpm xulrunner-devel-unstable-1.9.0.4-1.el5.x86_64.rpm yelp-2.16.0-22.el5.x86_64.rpm yelp-debuginfo-2.16.0-22.el5.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://www.cve.org/CVERecord?id=CVE-2008-0017 https://www.cve.org/CVERecord?id=CVE-2008-5014 https://www.cve.org/CVERecord?id=CVE-2008-5015 https://www.cve.org/CVERecord?id=CVE-2008-5016 https://www.cve.org/CVERecord?id=CVE-2008-5017 https://www.cve.org/CVERecord?id=CVE-2008-5018 https://www.cve.org/CVERecord?id=CVE-2008-5019 https://www.cve.org/CVERecord?id=CVE-2008-5021 https://www.cve.org/CVERecord?id=CVE-2008-5022 https://www.cve.org/CVERecord?id=CVE-2008-5023 https://www.cve.org/CVERecord?id=CVE-2008-5024 https://www.mozilla.org/en-US/security/known-vulnerabilities/firefox-3.0/ 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2008 Red Hat, Inc. . A recent Firefox update addresses significant vulnerabilities within Red Hat environments. Users are encouraged to update for improved protection and browser integrity.. Firefox Update, Red Hat Security, Critical Issues, Browser Security, Software Update. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.