Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 544
Alerts This Week
Warning Icon 1 544

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 1 articles for you...
203

Mageia 8: MGASA-2022-0220 Moderate: Firefox Memory Corruption Risks

A malicious website could have learned the size of a cross-origin resource that supported Range requests (CVE-2022-31736). A malicious webpage could have caused an out-of-bounds write in WebGL, leading to memory corruption and a potentially exploitable crash (CVE-2022-31737). . MGASA-2022-0220 - Updated firefox/nss/nspr packages fix security vulnerability Publication date: 04 Jun 2022 URL: https://advisories.mageia.org/MGASA-2022-0220.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-31736, CVE-2022-31737, CVE-2022-31738, CVE-2022-31740, CVE-2022-31741, CVE-2022-31742, CVE-2022-31747 A malicious website could have learned the size of a cross-origin resource that supported Range requests (CVE-2022-31736). A malicious webpage could have caused an out-of-bounds write in WebGL, leading to memory corruption and a potentially exploitable crash (CVE-2022-31737). When exiting fullscreen mode, an iframe could have confused the browser about the current state of fullscreen, resulting in potential user confusion or spoofing attacks (CVE-2022-31738). On arm64, WASM code could have resulted in incorrect assembly generation leading to a register allocation problem, and a potentially exploitable crash (CVE-2022-31740). A crafted CMS message could have been processed incorrectly, leading to an invalid memory read, and potentially further memory corruption (CVE-2022-31741). An attacker could have exploited a timing attack by sending a large number of allowCredential entries and detecting the difference between invalid key handles and cross-origin key handles. This could have led to cross-origin account linking in violation of WebAuthn goals (CVE-2022-31742). Mozilla developers Andrew McCreight, Nicolas B. Pierron, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox ESR 91.9. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrarycode (CVE-2022-31747). References: - https://bugs.mageia.org/show_bug.cgi?id=30498 - https://groups.google.com/a/mozilla.org/g/dev-tech-crypto/c/e9q0AqO8t2k - https://groups.google.com/a/mozilla.org/g/dev-tech-crypto/c/ZghhNaaxnUA - https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_79.html - https://www.mozilla.org/en-US/security/advisories/mfsa2022-21/ - https://www.cve.org/CVERecord?id=CVE-2022-31736 - https://www.cve.org/CVERecord?id=CVE-2022-31737 - https://www.cve.org/CVERecord?id=CVE-2022-31738 - https://www.cve.org/CVERecord?id=CVE-2022-31740 - https://www.cve.org/CVERecord?id=CVE-2022-31741 - https://www.cve.org/CVERecord?id=CVE-2022-31742 - https://www.cve.org/CVERecord?id=CVE-2022-31747 SRPMS: - 8/core/firefox-91.10.0-1.mga8 - 8/core/firefox-l10n-91.10.0-1.mga8 - 8/core/nspr-4.34-1.mga8 - 8/core/nss-3.79.0-1.mga8 . The update for Mageia 2022-0220 addresses various vulnerabilities found in Firefox and associated applications for users of the Mageia operating system.. firefox security update, mageia advisory, memory safety issues, exploit mitigation. . LinuxSecurity.com Team

Calendar%202 Jun 04, 2022 Mageia
172

Ubuntu: 4140-1 Moderate: Firefox Mouse Pointer Hijack Threat

Firefox could be made to hijack the mouse pointer it if opened a malicious website.. =========================================================================Ubuntu Security Notice USN-4140-1 September 25, 2019 firefox vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 19.04 - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Firefox could be made to hijack the mouse pointer it if opened a malicious website. Software Description: - firefox: Mozilla Open Source web browser Details: It was discovered that no user notification was given when pointer lock is enabled. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to hijack the mouse pointer and confuse users. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 19.04: firefox 69.0.1+build1-0ubuntu0.19.04.1 Ubuntu 18.04 LTS: firefox 69.0.1+build1-0ubuntu0.18.04.1 Ubuntu 16.04 LTS: firefox 69.0.1+build1-0ubuntu0.16.04.1 After a standard system update you need to restart Firefox to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4140-1 CVE-2019-11754 Package Information: https://launchpad.net/ubuntu/+source/firefox/69.0.1+build1-0ubuntu0.19.04.1 https://launchpad.net/ubuntu/+source/firefox/69.0.1+build1-0ubuntu0.18.04.1 https://launchpad.net/ubuntu/+source/firefox/69.0.1+build1-0ubuntu0.16.04.1 . A recent Ubuntu Security Notice highlights a vulnerability in Firefox that may allow attackers to manipulate the mouse cursor via compromised websites.. Ubuntu Security Notice, Firefox Exploit, Pointer Hijacking, Web Browser Security. . LinuxSecurity.com Team

Calendar%202 Sep 25, 2019 Ubuntu
172

Ubuntu 16.04 LTS: USN-2936-3 Critical: Firefox Regression Issue

USN-2936-1 introduced a regression in Firefox.. =========================================================================Ubuntu Security Notice USN-2936-3 May 19, 2016 firefox regression ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS - Ubuntu 15.10 - Ubuntu 14.04 LTS - Ubuntu 12.04 LTS Summary: USN-2936-1 introduced a regression in Firefox. Software Description: - firefox: Mozilla Open Source web browser Details: USN-2936-1 fixed vulnerabilities in Firefox. The update caused an issue where a device update POST request was sent every time about:preferences#sync was shown. This update fixes the problem. We apologize for the inconvenience. Original advisory details: Christian Holler, Tyson Smith, Phil Ringalda, Gary Kwong, Jesse Ruderman, Mats Palmgren, Carsten Book, Boris Zbarsky, David Bolter, Randell Jesup, Andrew McCreight, and Steve Fink discovered multiple memory safety issues in Firefox. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking Firefox. (CVE-2016-2804, CVE-2016-2806, CVE-2016-2807) An invalid write was discovered when using the JavaScript .watch() method in some circumstances. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking Firefox. (CVE-2016-2808) Looben Yang discovered a use-after-free and buffer overflow in service workers. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invokingFirefox. (CVE-2016-2811, CVE-2016-2812) Sascha Just discovered a buffer overflow in libstagefright in some circumstances. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking Firefox. (CVE-2016-2814) Muneaki Nishimura discovered that CSP is not applied correctly to web content sent with the multipart/x-mixed-replace MIME type. An attacker could potentially exploit this to conduct cross-site scripting (XSS) attacks when they would otherwise be prevented. (CVE-2016-2816) Muneaki Nishimura discovered that the chrome.tabs.update API for web extensions allows for navigation to javascript: URLs. A malicious extension could potentially exploit this to conduct cross-site scripting (XSS) attacks. (CVE-2016-2817) Mark Goodwin discovered that about:healthreport accepts certain events from any content present in the remote-report iframe. If another vulnerability allowed the injection of web content in the remote-report iframe, an attacker could potentially exploit this to change the user's sharing preferences. (CVE-2016-2820) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS: firefox 46.0.1+build1-0ubuntu0.16.04.2 Ubuntu 15.10: firefox 46.0.1+build1-0ubuntu0.15.10.2 Ubuntu 14.04 LTS: firefox 46.0.1+build1-0ubuntu0.14.04.3 Ubuntu 12.04 LTS: firefox 46.0.1+build1-0ubuntu0.12.04.2 After a standard system update you need to restart Firefox to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2936-3 https://ubuntu.com/security/notices/USN-2936-1 https://bugs.launchpad.net/ubuntu/+source/firefox/+bug/1583389 Package Information: https://launchpad.net/ubuntu/+source/firefox/46.0.1+build1-0ubuntu0.16.04.2 https://launchpad.net/ubuntu/+source/firefox/46.0.1+build1-0ubuntu0.15.10.2 https://launchpad.net/ubuntu/+source/firefox/46.0.1+build1-0ubuntu0.14.04.3 https://launchpad.net/ubuntu/+source/firefox/46.0.1+build1-0ubuntu0.12.04.2 . Addressing the Firefox issue arising from USN-2936-1 on Ubuntu in order to mitigate security vulnerabilities and enhance system performance.. ubuntu security notice, firefox update, regression fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 19, 2016 Critical Ubuntu
98

Red Hat: RHSA-2013:0614-01 Critical: Xulrunner Web Exploit

Updated xulrunner packages that fix one security issue are now available for Red Hat Enterprise Linux 5 and 6. The Red Hat Security Response Team has rated this update as having critical [More...]. ==================================================================== Red Hat Security Advisory Synopsis: Critical: xulrunner security update Advisory ID: RHSA-2013:0614-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2013:0614.html Issue date: 2013-03-08 CVE Names: CVE-2013-0787 ==================================================================== 1. Summary: Updated xulrunner packages that fix one security issue are now available for Red Hat Enterprise Linux 5 and 6. The Red Hat Security Response Team has rated this update as having critical security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: RHEL Desktop Workstation (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64 Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux Desktop (v. 6) - i386, x86_64 Red Hat Enterprise Linux Desktop Optional (v. 6) - i386, x86_64 Red Hat Enterprise Linux HPC Node Optional (v. 6) - x86_64 Red Hat Enterprise Linux Server (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Optional (v. 6) - i386, x86_64 3. Description: XULRunner provides the XUL Runtime environment for applications using the Gecko layout engine. A flaw was found in the way XULRunner handled malformed web content. A web page containing malicious content could cause an application linked against XULRunner (such as Mozilla Firefox) to crash or execute arbitrary codewith the privileges of the user running the application. (CVE-2013-0787) Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges VUPEN Security via the TippingPoint Zero Day Initiative project as the original reporter. For technical details regarding this flaw, refer to the Mozilla security advisories. You can find a link to the Mozilla advisories in the References section of this erratum. All XULRunner users should upgrade to these updated packages, which correct this issue. After installing the update, applications using XULRunner must be restarted for the changes to take effect. 4. Solution: Before applying this update, make sure all previously-released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/articles/11258 5. Bugs fixed (http://bugzilla.redhat.com/): 918876 - CVE-2013-0787 Mozilla: Use-after-free in HTML Editor (MFSA 2013-29) 6. Package List: Red Hat Enterprise Linux Desktop (v. 5 client): Source: i386: xulrunner-17.0.3-2.el5_9.i386.rpm xulrunner-debuginfo-17.0.3-2.el5_9.i386.rpm x86_64: xulrunner-17.0.3-2.el5_9.i386.rpm xulrunner-17.0.3-2.el5_9.x86_64.rpm xulrunner-debuginfo-17.0.3-2.el5_9.i386.rpm xulrunner-debuginfo-17.0.3-2.el5_9.x86_64.rpm RHEL Desktop Workstation (v. 5 client): Source: i386: xulrunner-debuginfo-17.0.3-2.el5_9.i386.rpm xulrunner-devel-17.0.3-2.el5_9.i386.rpm x86_64: xulrunner-debuginfo-17.0.3-2.el5_9.i386.rpm xulrunner-debuginfo-17.0.3-2.el5_9.x86_64.rpm xulrunner-devel-17.0.3-2.el5_9.i386.rpm xulrunner-devel-17.0.3-2.el5_9.x86_64.rpm Red Hat Enterprise Linux (v. 5server): Source: i386: xulrunner-17.0.3-2.el5_9.i386.rpm xulrunner-debuginfo-17.0.3-2.el5_9.i386.rpm xulrunner-devel-17.0.3-2.el5_9.i386.rpm ia64: xulrunner-17.0.3-2.el5_9.ia64.rpm xulrunner-debuginfo-17.0.3-2.el5_9.ia64.rpm xulrunner-devel-17.0.3-2.el5_9.ia64.rpm ppc: xulrunner-17.0.3-2.el5_9.ppc.rpm xulrunner-17.0.3-2.el5_9.ppc64.rpm xulrunner-debuginfo-17.0.3-2.el5_9.ppc.rpm xulrunner-debuginfo-17.0.3-2.el5_9.ppc64.rpm xulrunner-devel-17.0.3-2.el5_9.ppc.rpm xulrunner-devel-17.0.3-2.el5_9.ppc64.rpm s390x: xulrunner-17.0.3-2.el5_9.s390.rpm xulrunner-17.0.3-2.el5_9.s390x.rpm xulrunner-debuginfo-17.0.3-2.el5_9.s390.rpm xulrunner-debuginfo-17.0.3-2.el5_9.s390x.rpm xulrunner-devel-17.0.3-2.el5_9.s390.rpm xulrunner-devel-17.0.3-2.el5_9.s390x.rpm x86_64: xulrunner-17.0.3-2.el5_9.i386.rpm xulrunner-17.0.3-2.el5_9.x86_64.rpm xulrunner-debuginfo-17.0.3-2.el5_9.i386.rpm xulrunner-debuginfo-17.0.3-2.el5_9.x86_64.rpm xulrunner-devel-17.0.3-2.el5_9.i386.rpm xulrunner-devel-17.0.3-2.el5_9.x86_64.rpm Red Hat Enterprise Linux Desktop (v. 6): Source: i386: xulrunner-17.0.3-2.el6_4.i686.rpm xulrunner-debuginfo-17.0.3-2.el6_4.i686.rpm x86_64: xulrunner-17.0.3-2.el6_4.i686.rpm xulrunner-17.0.3-2.el6_4.x86_64.rpm xulrunner-debuginfo-17.0.3-2.el6_4.i686.rpm xulrunner-debuginfo-17.0.3-2.el6_4.x86_64.rpm Red Hat Enterprise Linux Desktop Optional (v. 6): Source: i386: xulrunner-debuginfo-17.0.3-2.el6_4.i686.rpm xulrunner-devel-17.0.3-2.el6_4.i686.rpm x86_64: xulrunner-debuginfo-17.0.3-2.el6_4.i686.rpm xulrunner-debuginfo-17.0.3-2.el6_4.x86_64.rpm xulrunner-devel-17.0.3-2.el6_4.i686.rpm xulrunner-devel-17.0.3-2.el6_4.x86_64.rpm Red Hat Enterprise Linux HPC Node Optional (v. 6): Source: x86_64: xulrunner-17.0.3-2.el6_4.i686.rpm xulrunner-17.0.3-2.el6_4.x86_64.rpm xulrunner-debuginfo-17.0.3-2.el6_4.i686.rpm xulrunner-debuginfo-17.0.3-2.el6_4.x86_64.rpm xulrunner-devel-17.0.3-2.el6_4.i686.rpm xulrunner-devel-17.0.3-2.el6_4.x86_64.rpm Red Hat Enterprise Linux Server (v.6): Source: i386: xulrunner-17.0.3-2.el6_4.i686.rpm xulrunner-debuginfo-17.0.3-2.el6_4.i686.rpm ppc64: xulrunner-17.0.3-2.el6_4.ppc.rpm xulrunner-17.0.3-2.el6_4.ppc64.rpm xulrunner-debuginfo-17.0.3-2.el6_4.ppc.rpm xulrunner-debuginfo-17.0.3-2.el6_4.ppc64.rpm s390x: xulrunner-17.0.3-2.el6_4.s390.rpm xulrunner-17.0.3-2.el6_4.s390x.rpm xulrunner-debuginfo-17.0.3-2.el6_4.s390.rpm xulrunner-debuginfo-17.0.3-2.el6_4.s390x.rpm x86_64: xulrunner-17.0.3-2.el6_4.i686.rpm xulrunner-17.0.3-2.el6_4.x86_64.rpm xulrunner-debuginfo-17.0.3-2.el6_4.i686.rpm xulrunner-debuginfo-17.0.3-2.el6_4.x86_64.rpm Red Hat Enterprise Linux Server Optional (v. 6): Source: i386: xulrunner-debuginfo-17.0.3-2.el6_4.i686.rpm xulrunner-devel-17.0.3-2.el6_4.i686.rpm ppc64: xulrunner-debuginfo-17.0.3-2.el6_4.ppc.rpm xulrunner-debuginfo-17.0.3-2.el6_4.ppc64.rpm xulrunner-devel-17.0.3-2.el6_4.ppc.rpm xulrunner-devel-17.0.3-2.el6_4.ppc64.rpm s390x: xulrunner-debuginfo-17.0.3-2.el6_4.s390.rpm xulrunner-debuginfo-17.0.3-2.el6_4.s390x.rpm xulrunner-devel-17.0.3-2.el6_4.s390.rpm xulrunner-devel-17.0.3-2.el6_4.s390x.rpm x86_64: xulrunner-debuginfo-17.0.3-2.el6_4.i686.rpm xulrunner-debuginfo-17.0.3-2.el6_4.x86_64.rpm xulrunner-devel-17.0.3-2.el6_4.i686.rpm xulrunner-devel-17.0.3-2.el6_4.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 6): Source: i386: xulrunner-17.0.3-2.el6_4.i686.rpm xulrunner-debuginfo-17.0.3-2.el6_4.i686.rpm x86_64: xulrunner-17.0.3-2.el6_4.i686.rpm xulrunner-17.0.3-2.el6_4.x86_64.rpm xulrunner-debuginfo-17.0.3-2.el6_4.i686.rpm xulrunner-debuginfo-17.0.3-2.el6_4.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 6): Source: i386: xulrunner-debuginfo-17.0.3-2.el6_4.i686.rpm xulrunner-devel-17.0.3-2.el6_4.i686.rpm x86_64: xulrunner-debuginfo-17.0.3-2.el6_4.i686.rpm xulrunner-debuginfo-17.0.3-2.el6_4.x86_64.rpm xulrunner-devel-17.0.3-2.el6_4.i686.rpm xulrunner-devel-17.0.3-2.el6_4.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature areavailable from https://access.redhat.com/security/team/key#package 7. References: https://access.redhat.com/security/cve/CVE-2013-0787 https://access.redhat.com/security/updates/classification#critical https://www.mozilla.org/en-US/security/known-vulnerabilities/firefox-esr/ 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2013 Red Hat, Inc. . Recent xulrunner updates for Red Hat address a significant security vulnerability. Implement the upgrade immediately to maintain system integrity.. Xulrunner Update, Red Hat Advisory, Critical Fix, Web Exploit. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 08, 2013 Critical Red Hat
202

openSUSE 11.4: 2011:0957-2 Important Update for MozillaFirefox

An update that fixes 10 vulnerabilities is now available. It includes one version update.. openSUSE Security Update: MozillaFirefox: Update to Firefox 6 ______________________________________________________________________________ Announcement ID: openSUSE-SU-2011:0957-2 Rating: important References: #712224 Cross-References: CVE-2011-0084 CVE-2011-2985 CVE-2011-2986 CVE-2011-2987 CVE-2011-2988 CVE-2011-2989 CVE-2011-2990 CVE-2011-2991 CVE-2011-2992 CVE-2011-2993 Affected Products: openSUSE 11.4 ______________________________________________________________________________ An update that fixes 10 vulnerabilities is now available. It includes one version update. Description: Mozilla Firefox was updated to version 6. It brings new features, fixes bugs and security issues. Following security issues were fixed: https://www.mozilla.org/en-US/security/advisories/mfsa2011-29/ Mozilla Foundation Security Advisory 2011-29 (MFSA 2011-29) * Miscellaneous memory safety hazards: Mozilla identified and fixed several memory safety bugs in the browser engine used in Firefox 4, Firefox 5 and other Mozilla-based products. Some of these bugs showed evidence of memory corruption under certain circumstances, and we presume that with enough effort at least some of these could be exploited to run arbitrary code. Aral Yaman reported a WebGL crash which affected Firefox 4 and Firefox 5. (CVE-2011-2989) Vivekanand Bolajwar reported a JavaScript crash which affected Firefox 4 and Firefox 5. (CVE-2011-2991) Bert Hubert and Theo Snelleman of Fox-IT reported a crash in the Ogg reader which affected Firefox 4 and Firefox 5. (CVE-2011-2992) Mozilla developers and community members Robert Kaiser, Jesse Ruderman, moz_bug_r_a4, Mardeg, Gary Kwong, Christoph Diehl, Martijn Wargers, Travis Emmitt, Bob Clary and Jonathan Watt reported memory safetyissues which affected Firefox 4 and Firefox 5. (CVE-2011-2985) * Unsigned scripts can call script inside signed JAR Rafael Gieschke reported that unsigned JavaScript could call into script inside a signed JAR thereby inheriting the identity of the site that signed the JAR as well as any permissions that a user had granted the signed JAR. (CVE-2011-2993) * String crash using WebGL shaders Michael Jordon of Context IS reported that an overly long shader program could cause a buffer overrun and crash in a string class used to store the shader source code. (CVE-2011-2988) * Heap overflow in ANGLE library Michael Jordon of Context IS reported a potentially exploitable heap overflow in the ANGLE library used by Mozilla's WebGL implementation. (CVE-2011-2987) * Crash in SVGTextElement.getCharNumAtPosition() Security researcher regenrecht reported via TippingPoint's Zero Day Initiative that a SVG text manipulation routine contained a dangling pointer vulnerability. (CVE-2011-0084) * Credential leakage using Content Security Policy reports Mike Cardwell reported that Content Security Policy violation reports failed to strip out proxy authorization credentials from the list of request headers. Daniel Veditz reported that redirecting to a website with Content Security Policy resulted in the incorrect resolution of hosts in the constructed policy. (CVE-2011-2990) * Cross-origin data theft using canvas and Windows D2D nasalislarvatus3000 reported that when using Windows D2D hardware acceleration, image data from one domain could be inserted into a canvas and read by a different domain. (CVE-2011-2986) Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE 11.4: zypper in -t patch MozillaFirefox-5020 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE 11.4 (i586x86_64) [New Version: 6.0]: MozillaFirefox-6.0-2.2.1 MozillaFirefox-branding-upstream-6.0-2.2.1 MozillaFirefox-buildsymbols-6.0-2.2.1 MozillaFirefox-devel-6.0-2.2.1 MozillaFirefox-translations-common-6.0-2.2.1 MozillaFirefox-translations-other-6.0-2.2.1 References: https://www.suse.com/security/cve/CVE-2011-0084.html https://www.suse.com/security/cve/CVE-2011-2985.html https://www.suse.com/security/cve/CVE-2011-2986.html https://www.suse.com/security/cve/CVE-2011-2987.html https://www.suse.com/security/cve/CVE-2011-2988.html https://www.suse.com/security/cve/CVE-2011-2989.html https://www.suse.com/security/cve/CVE-2011-2990.html https://www.suse.com/security/cve/CVE-2011-2991.html https://www.suse.com/security/cve/CVE-2011-2992.html https://www.suse.com/security/cve/CVE-2011-2993.html -- . The latest openSUSE update addresses significant vulnerabilities in Mozilla Firefox, improving both the browser's security and overall performance.. MozillaFirefox Update, openSUSE Security, Browser Safety, Memory Safeguards. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Aug 29, 2011 Important OpenSUSE
98

Red Hat Enterprise Linux 4: RHSA-2011:0313-01 Critical SeaMonkey Update

Updated seamonkey packages that fix several security issues are now available for Red Hat Enterprise Linux 4. The Red Hat Security Response Team has rated this update as having critical security impact. Common Vulnerability Scoring System (CVSS) base scores,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Critical: seamonkey security update Advisory ID: RHSA-2011:0313-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2011:0313.html Issue date: 2011-03-01 CVE Names: CVE-2011-0051 CVE-2011-0053 CVE-2011-0059 ==================================================================== 1. Summary: Updated seamonkey packages that fix several security issues are now available for Red Hat Enterprise Linux 4. The Red Hat Security Response Team has rated this update as having critical security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Enterprise Linux Desktop version 4 - i386, x86_64 Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64 3. Description: SeaMonkey is an open source web browser, email and newsgroup client, IRC chat client, and HTML editor. A flaw was found in the way SeaMonkey handled dialog boxes. An attacker could use this flaw to create a malicious web page that would present a blank dialog box that has non-functioning buttons. If a user closes the dialog box window, it could unexpectedly grant the malicious web page elevated privileges. (CVE-2011-0051) Several flaws were found in the processing of malformed web content. A web page containing malicious content could causeSeaMonkey to crash or, potentially, execute arbitrary code with the privileges of the user running SeaMonkey. (CVE-2011-0053) A flaw was found in the way SeaMonkey handled plug-ins that perform HTTP requests. If a plug-in performed an HTTP request, and the server sent a 307 redirect response, the plug-in was not notified, and the HTTP request was forwarded. The forwarded request could contain custom headers, which could result in a Cross Site Request Forgery attack. (CVE-2011-0059) All SeaMonkey users should upgrade to these updated packages, which correct these issues. After installing the update, SeaMonkey must be restarted for the changes to take effect. 4. Solution: Before applying this update, make sure all previously-released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at 5. Bugs fixed (http://bugzilla.redhat.com/): 675082 - CVE-2011-0053 Mozilla miscellaneous memory safety hazards (MFSA 2011-01) 675087 - CVE-2011-0051 Mozilla recursive eval call causes confirm dialog to evaluate to true (MFSA 2011-02) 681369 - CVE-2011-0059 Mozilla CSRF risk with plugins and 307 redirects (MFSA 2011-10) 6. Package List: Red Hat Enterprise Linux AS version4: Source: i386: seamonkey-1.0.9-67.el4_8.i386.rpm seamonkey-chat-1.0.9-67.el4_8.i386.rpm seamonkey-debuginfo-1.0.9-67.el4_8.i386.rpm seamonkey-devel-1.0.9-67.el4_8.i386.rpm seamonkey-dom-inspector-1.0.9-67.el4_8.i386.rpm seamonkey-js-debugger-1.0.9-67.el4_8.i386.rpm seamonkey-mail-1.0.9-67.el4_8.i386.rpm ia64: seamonkey-1.0.9-67.el4_8.ia64.rpm seamonkey-chat-1.0.9-67.el4_8.ia64.rpm seamonkey-debuginfo-1.0.9-67.el4_8.ia64.rpm seamonkey-devel-1.0.9-67.el4_8.ia64.rpm seamonkey-dom-inspector-1.0.9-67.el4_8.ia64.rpm seamonkey-js-debugger-1.0.9-67.el4_8.ia64.rpm seamonkey-mail-1.0.9-67.el4_8.ia64.rpm ppc: seamonkey-1.0.9-67.el4_8.ppc.rpm seamonkey-chat-1.0.9-67.el4_8.ppc.rpm seamonkey-debuginfo-1.0.9-67.el4_8.ppc.rpm seamonkey-devel-1.0.9-67.el4_8.ppc.rpm seamonkey-dom-inspector-1.0.9-67.el4_8.ppc.rpm seamonkey-js-debugger-1.0.9-67.el4_8.ppc.rpm seamonkey-mail-1.0.9-67.el4_8.ppc.rpm s390: seamonkey-1.0.9-67.el4_8.s390.rpm seamonkey-chat-1.0.9-67.el4_8.s390.rpm seamonkey-debuginfo-1.0.9-67.el4_8.s390.rpm seamonkey-devel-1.0.9-67.el4_8.s390.rpm seamonkey-dom-inspector-1.0.9-67.el4_8.s390.rpm seamonkey-js-debugger-1.0.9-67.el4_8.s390.rpm seamonkey-mail-1.0.9-67.el4_8.s390.rpm s390x: seamonkey-1.0.9-67.el4_8.s390x.rpm seamonkey-chat-1.0.9-67.el4_8.s390x.rpm seamonkey-debuginfo-1.0.9-67.el4_8.s390x.rpm seamonkey-devel-1.0.9-67.el4_8.s390x.rpm seamonkey-dom-inspector-1.0.9-67.el4_8.s390x.rpm seamonkey-js-debugger-1.0.9-67.el4_8.s390x.rpm seamonkey-mail-1.0.9-67.el4_8.s390x.rpm x86_64: seamonkey-1.0.9-67.el4_8.x86_64.rpm seamonkey-chat-1.0.9-67.el4_8.x86_64.rpm seamonkey-debuginfo-1.0.9-67.el4_8.x86_64.rpm seamonkey-devel-1.0.9-67.el4_8.x86_64.rpm seamonkey-dom-inspector-1.0.9-67.el4_8.x86_64.rpm seamonkey-js-debugger-1.0.9-67.el4_8.x86_64.rpm seamonkey-mail-1.0.9-67.el4_8.x86_64.rpm Red Hat Enterprise Linux Desktop version4: Source: i386: seamonkey-1.0.9-67.el4_8.i386.rpm seamonkey-chat-1.0.9-67.el4_8.i386.rpm seamonkey-debuginfo-1.0.9-67.el4_8.i386.rpm seamonkey-devel-1.0.9-67.el4_8.i386.rpm seamonkey-dom-inspector-1.0.9-67.el4_8.i386.rpm seamonkey-js-debugger-1.0.9-67.el4_8.i386.rpm seamonkey-mail-1.0.9-67.el4_8.i386.rpm x86_64: seamonkey-1.0.9-67.el4_8.x86_64.rpm seamonkey-chat-1.0.9-67.el4_8.x86_64.rpm seamonkey-debuginfo-1.0.9-67.el4_8.x86_64.rpm seamonkey-devel-1.0.9-67.el4_8.x86_64.rpm seamonkey-dom-inspector-1.0.9-67.el4_8.x86_64.rpm seamonkey-js-debugger-1.0.9-67.el4_8.x86_64.rpm seamonkey-mail-1.0.9-67.el4_8.x86_64.rpm Red Hat Enterprise Linux ES version 4: Source: i386: seamonkey-1.0.9-67.el4_8.i386.rpm seamonkey-chat-1.0.9-67.el4_8.i386.rpm seamonkey-debuginfo-1.0.9-67.el4_8.i386.rpm seamonkey-devel-1.0.9-67.el4_8.i386.rpm seamonkey-dom-inspector-1.0.9-67.el4_8.i386.rpm seamonkey-js-debugger-1.0.9-67.el4_8.i386.rpm seamonkey-mail-1.0.9-67.el4_8.i386.rpm ia64: seamonkey-1.0.9-67.el4_8.ia64.rpm seamonkey-chat-1.0.9-67.el4_8.ia64.rpm seamonkey-debuginfo-1.0.9-67.el4_8.ia64.rpm seamonkey-devel-1.0.9-67.el4_8.ia64.rpm seamonkey-dom-inspector-1.0.9-67.el4_8.ia64.rpm seamonkey-js-debugger-1.0.9-67.el4_8.ia64.rpm seamonkey-mail-1.0.9-67.el4_8.ia64.rpm x86_64: seamonkey-1.0.9-67.el4_8.x86_64.rpm seamonkey-chat-1.0.9-67.el4_8.x86_64.rpm seamonkey-debuginfo-1.0.9-67.el4_8.x86_64.rpm seamonkey-devel-1.0.9-67.el4_8.x86_64.rpm seamonkey-dom-inspector-1.0.9-67.el4_8.x86_64.rpm seamonkey-js-debugger-1.0.9-67.el4_8.x86_64.rpm seamonkey-mail-1.0.9-67.el4_8.x86_64.rpm Red Hat Enterprise Linux WS version4: Source: i386: seamonkey-1.0.9-67.el4_8.i386.rpm seamonkey-chat-1.0.9-67.el4_8.i386.rpm seamonkey-debuginfo-1.0.9-67.el4_8.i386.rpm seamonkey-devel-1.0.9-67.el4_8.i386.rpm seamonkey-dom-inspector-1.0.9-67.el4_8.i386.rpm seamonkey-js-debugger-1.0.9-67.el4_8.i386.rpm seamonkey-mail-1.0.9-67.el4_8.i386.rpm ia64: seamonkey-1.0.9-67.el4_8.ia64.rpm seamonkey-chat-1.0.9-67.el4_8.ia64.rpm seamonkey-debuginfo-1.0.9-67.el4_8.ia64.rpm seamonkey-devel-1.0.9-67.el4_8.ia64.rpm seamonkey-dom-inspector-1.0.9-67.el4_8.ia64.rpm seamonkey-js-debugger-1.0.9-67.el4_8.ia64.rpm seamonkey-mail-1.0.9-67.el4_8.ia64.rpm x86_64: seamonkey-1.0.9-67.el4_8.x86_64.rpm seamonkey-chat-1.0.9-67.el4_8.x86_64.rpm seamonkey-debuginfo-1.0.9-67.el4_8.x86_64.rpm seamonkey-devel-1.0.9-67.el4_8.x86_64.rpm seamonkey-dom-inspector-1.0.9-67.el4_8.x86_64.rpm seamonkey-js-debugger-1.0.9-67.el4_8.x86_64.rpm seamonkey-mail-1.0.9-67.el4_8.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/#package 7. References: https://access.redhat.com/security/cve/CVE-2011-0051 https://access.redhat.com/security/cve/CVE-2011-0053 https://access.redhat.com/security/cve/CVE-2011-0059 https://access.redhat.com/security/updates/classification/#critical 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2011 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.4 (GNU/Linux) iD8DBQFNbZ9dXlSAg2UNWIIRAkI0AJwL3t4328J6ZnXFVPPkpRYnOoxSrACfdf2p pcAvnhIGk9lSWUcZmNUDH4M=oFBz -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Refreshed Firefox distributions for Fedora tackle severe vulnerabilities, safeguarding platform stability and enhancing user protection.. Seamonkey Update, Red Hat Security Patch, Critical Exploit Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 02, 2011 Critical Red Hat
200

Scientific Linux: CVE-2010-0174 Critical SeaMonkey Security Update

Critical: seamonkey security update. Date: Tue, 30 Mar 2010 13:56:34 -0500 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: FASTBUGS for SL 5.x i386/x86_64 Comments: To: "This email address is being protected from spambots. You need JavaScript enabled to view it." The following FASTBUGS have been uploaded to i386: strace-4.5.18-5.el5_4.4.i386.rpm x86_64: kmod-kvm-83-105.el5_4.28.x86_64.rpm kvm-83-105.el5_4.28.x86_64.rpm kvm-qemu-img-83-105.el5_4.28.x86_64.rpm kvm-tools-83-105.el5_4.28.x86_64.rpm strace-4.5.18-5.el5_4.4.x86_64.rpm -Connie Sieh -Troy Dawson Date: Wed, 31 Mar 2010 16:57:23 -0500 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA Critical: seamonkey on SL3.x, SL4.x i386/x86_64 Comments: To: "This email address is being protected from spambots. You need JavaScript enabled to view it." Synopsis: Critical: seamonkey security update Issue date: 2010-03-30 CVE Names: CVE-2010-0174 CVE-2010-0175 CVE-2010-0176 CVE-2010-0177 Several use-after-free flaws were found in SeaMonkey. Visiting a web page containing malicious content could result in SeaMonkey executing arbitrary code with the privileges of the user running SeaMonkey. (CVE-2010-0175, CVE-2010-0176, CVE-2010-0177) Several flaws were found in the processing of malformed web content. A web page containing malicious content could cause SeaMonkey to crash or, potentially, execute arbitrary code with the privileges of the user running SeaMonkey. (CVE-2010-0174) After installing the update, SeaMonkey must be restarted for the changes to take effect. SL 3.0.x SRPMS: seamonkey-1.0.9-0.52.el3.src.rpm i386: seamonkey-1.0.9-0.52.el3.i386.rpm seamonkey-chat-1.0.9-0.52.el3.i386.rpm seamonkey-devel-1.0.9-0.52.el3.i386.rpm seamonkey-dom-inspector-1.0.9-0.52.el3.i386.rpm seamonkey-js-debugger-1.0.9-0.52.el3.i386.rpm seamonkey-mail-1.0.9-0.52.el3.i386.rpm seamonkey-nspr-1.0.9-0.52.el3.i386.rpm seamonkey-nspr-devel-1.0.9-0.52.el3.i386.rpm seamonkey-nss-1.0.9-0.52.el3.i386.rpm seamonkey-nss-devel-1.0.9-0.52.el3.i386.rpm x86_64: seamonkey-1.0.9-0.52.el3.i386.rpm seamonkey-1.0.9-0.52.el3.x86_64.rpm seamonkey-chat-1.0.9-0.52.el3.i386.rpm seamonkey-chat-1.0.9-0.52.el3.x86_64.rpm seamonkey-devel-1.0.9-0.52.el3.x86_64.rpm seamonkey-dom-inspector-1.0.9-0.52.el3.i386.rpm seamonkey-dom-inspector-1.0.9-0.52.el3.x86_64.rpm seamonkey-js-debugger-1.0.9-0.52.el3.i386.rpm seamonkey-js-debugger-1.0.9-0.52.el3.x86_64.rpm seamonkey-mail-1.0.9-0.52.el3.i386.rpm seamonkey-mail-1.0.9-0.52.el3.x86_64.rpm seamonkey-nspr-1.0.9-0.52.el3.i386.rpm seamonkey-nspr-1.0.9-0.52.el3.x86_64.rpm seamonkey-nspr-devel-1.0.9-0.52.el3.x86_64.rpm seamonkey-nss-1.0.9-0.52.el3.i386.rpm seamonkey-nss-1.0.9-0.52.el3.x86_64.rpm seamonkey-nss-devel-1.0.9-0.52.el3.x86_64.rpm SL 4.x SRPMS: seamonkey-1.0.9-54.el4_8.src.rpm i386: seamonkey-1.0.9-54.el4_8.i386.rpm seamonkey-chat-1.0.9-54.el4_8.i386.rpm seamonkey-devel-1.0.9-54.el4_8.i386.rpm seamonkey-dom-inspector-1.0.9-54.el4_8.i386.rpm seamonkey-js-debugger-1.0.9-54.el4_8.i386.rpm seamonkey-mail-1.0.9-54.el4_8.i386.rpm x86_64: seamonkey-1.0.9-54.el4_8.x86_64.rpm seamonkey-chat-1.0.9-54.el4_8.x86_64.rpm seamonkey-devel-1.0.9-54.el4_8.x86_64.rpm seamonkey-dom-inspector-1.0.9-54.el4_8.x86_64.rpm seamonkey-js-debugger-1.0.9-54.el4_8.x86_64.rpm seamonkey-mail-1.0.9-54.el4_8.x86_64.rpm -Connie Sieh -Troy Dawson . Numerous vulnerabilities in SeaMonkey pose threats to users; urgent update required for SL3.x and SL4.x versions.. Seamonkey Security Update, Scientific Linux, Unix Code Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 31, 2010 Critical Scientific Linux
98

Red Hat: RHSA-2009:1430-01 Critical: firefox Web Exploit Risks

Updated firefox packages that fix several security issues are now available for Red Hat Enterprise Linux 4 and 5. This update has been rated as having critical security impact by the Red Hat Security Response Team.. ==================================================================== Red Hat Security Advisory Synopsis: Critical: firefox security update Advisory ID: RHSA-2009:1430-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2009:1430.html Issue date: 2009-09-09 CVE Names: CVE-2009-2654 CVE-2009-3070 CVE-2009-3071 CVE-2009-3072 CVE-2009-3074 CVE-2009-3075 CVE-2009-3076 CVE-2009-3077 CVE-2009-3078 CVE-2009-3079 ==================================================================== 1. Summary: Updated firefox packages that fix several security issues are now available for Red Hat Enterprise Linux 4 and 5. This update has been rated as having critical security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Enterprise Linux Desktop version 4 - i386, x86_64 Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64 Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64 RHEL Desktop Workstation (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64 3. Description: Mozilla Firefox is an open source Web browser. XULRunner provides the XUL Runtime environment for Mozilla Firefox. nspr provides the Netscape Portable Runtime (NSPR). Several flaws were found in the processing of malformed web content. A web page containing malicious content could cause Firefox to crash or, potentially, execute arbitrary code with the privileges of the user running Firefox. (CVE-2009-3070, CVE-2009-3071, CVE-2009-3072,CVE-2009-3074, CVE-2009-3075) A use-after-free flaw was found in Firefox. An attacker could use this flaw to crash Firefox or, potentially, execute arbitrary code with the privileges of the user running Firefox. (CVE-2009-3077) A flaw was found in the way Firefox handles malformed JavaScript. A website with an object containing malicious JavaScript could execute that JavaScript with the privileges of the user running Firefox. (CVE-2009-3079) Descriptions in the dialogs when adding and removing PKCS #11 modules were not informative. An attacker able to trick a user into installing a malicious PKCS #11 module could use this flaw to install their own Certificate Authority certificates on a user's machine, making it possible to trick the user into believing they are viewing a trusted site or, potentially, execute arbitrary code with the privileges of the user running Firefox. (CVE-2009-3076) A flaw was found in the way Firefox displays the address bar when window.open() is called in a certain way. An attacker could use this flaw to conceal a malicious URL, possibly tricking a user into believing they are viewing a trusted site. (CVE-2009-2654) A flaw was found in the way Firefox displays certain Unicode characters. An attacker could use this flaw to conceal a malicious URL, possibly tricking a user into believing they are viewing a trusted site. (CVE-2009-3078) For technical details regarding these flaws, refer to the Mozilla security advisories for Firefox 3.0.14. You can find a link to the Mozilla advisories in the References section of this errata. All Firefox users should upgrade to these updated packages, which contain Firefox version 3.0.14, which corrects these issues. After installing the update, Firefox must be restarted for the changes to take effect. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. This update is available via Red Hat Network. Details on how to use the Red Hat Network to apply this update areavailable at 5. Bugs fixed (http://bugzilla.redhat.com/): 521311 - CVE-2009-2654 firefox: URL bar spoofing vulnerability 521686 - CVE-2009-3070 Firefox 3.5 3.0.14 browser engine crashes 521687 - CVE-2009-3071 Firefox 3.5.2 3.0.14 browser engine crashes 521688 - CVE-2009-3072 Firefox 3.5.3 3.0.14 browser engine crashes 521690 - CVE-2009-3074 Firefox 3.5 3.0.14 JavaScript engine crashes 521691 - CVE-2009-3075 Firefox 3.5.2 3.0.14 JavaScript engine crashes 521692 - CVE-2009-3076 Firefox 3.0.14 Insufficient warning for PKCS11 module installation and removal 521693 - CVE-2009-3077 Firefox 3.5.3 3.0.14 TreeColumns dangling pointer vulnerability 521694 - CVE-2009-3078 Firefox 3.5.3 3.0.14 Location bar spoofing via tall line-height Unicode characters521695 - CVE-2009-3079 Firefox 3.5.3 3.0.14 Chrome privilege escalation with FeedWriter 6. Package List: Red Hat Enterprise Linux AS version4: Source: i386: firefox-3.0.14-1.el4.i386.rpm firefox-debuginfo-3.0.14-1.el4.i386.rpm nspr-4.7.5-1.el4_8.i386.rpm nspr-debuginfo-4.7.5-1.el4_8.i386.rpm nspr-devel-4.7.5-1.el4_8.i386.rpm ia64: firefox-3.0.14-1.el4.ia64.rpm firefox-debuginfo-3.0.14-1.el4.ia64.rpm nspr-4.7.5-1.el4_8.i386.rpm nspr-4.7.5-1.el4_8.ia64.rpm nspr-debuginfo-4.7.5-1.el4_8.i386.rpm nspr-debuginfo-4.7.5-1.el4_8.ia64.rpm nspr-devel-4.7.5-1.el4_8.ia64.rpm ppc: firefox-3.0.14-1.el4.ppc.rpm firefox-debuginfo-3.0.14-1.el4.ppc.rpm nspr-4.7.5-1.el4_8.ppc.rpm nspr-4.7.5-1.el4_8.ppc64.rpm nspr-debuginfo-4.7.5-1.el4_8.ppc.rpm nspr-debuginfo-4.7.5-1.el4_8.ppc64.rpm nspr-devel-4.7.5-1.el4_8.ppc.rpm s390: firefox-3.0.14-1.el4.s390.rpm firefox-debuginfo-3.0.14-1.el4.s390.rpm nspr-4.7.5-1.el4_8.s390.rpm nspr-debuginfo-4.7.5-1.el4_8.s390.rpm nspr-devel-4.7.5-1.el4_8.s390.rpm s390x: firefox-3.0.14-1.el4.s390x.rpm firefox-debuginfo-3.0.14-1.el4.s390x.rpm nspr-4.7.5-1.el4_8.s390.rpm nspr-4.7.5-1.el4_8.s390x.rpm nspr-debuginfo-4.7.5-1.el4_8.s390.rpm nspr-debuginfo-4.7.5-1.el4_8.s390x.rpm nspr-devel-4.7.5-1.el4_8.s390x.rpm x86_64: firefox-3.0.14-1.el4.x86_64.rpm firefox-debuginfo-3.0.14-1.el4.x86_64.rpm nspr-4.7.5-1.el4_8.i386.rpm nspr-4.7.5-1.el4_8.x86_64.rpm nspr-debuginfo-4.7.5-1.el4_8.i386.rpm nspr-debuginfo-4.7.5-1.el4_8.x86_64.rpm nspr-devel-4.7.5-1.el4_8.x86_64.rpm Red Hat Enterprise Linux Desktop version 4: Source: i386: firefox-3.0.14-1.el4.i386.rpm firefox-debuginfo-3.0.14-1.el4.i386.rpm nspr-4.7.5-1.el4_8.i386.rpm nspr-debuginfo-4.7.5-1.el4_8.i386.rpm nspr-devel-4.7.5-1.el4_8.i386.rpm x86_64: firefox-3.0.14-1.el4.x86_64.rpm firefox-debuginfo-3.0.14-1.el4.x86_64.rpm nspr-4.7.5-1.el4_8.i386.rpm nspr-4.7.5-1.el4_8.x86_64.rpm nspr-debuginfo-4.7.5-1.el4_8.i386.rpm nspr-debuginfo-4.7.5-1.el4_8.x86_64.rpm nspr-devel-4.7.5-1.el4_8.x86_64.rpm Red Hat Enterprise Linux ES version4: Source: i386: firefox-3.0.14-1.el4.i386.rpm firefox-debuginfo-3.0.14-1.el4.i386.rpm nspr-4.7.5-1.el4_8.i386.rpm nspr-debuginfo-4.7.5-1.el4_8.i386.rpm nspr-devel-4.7.5-1.el4_8.i386.rpm ia64: firefox-3.0.14-1.el4.ia64.rpm firefox-debuginfo-3.0.14-1.el4.ia64.rpm nspr-4.7.5-1.el4_8.i386.rpm nspr-4.7.5-1.el4_8.ia64.rpm nspr-debuginfo-4.7.5-1.el4_8.i386.rpm nspr-debuginfo-4.7.5-1.el4_8.ia64.rpm nspr-devel-4.7.5-1.el4_8.ia64.rpm x86_64: firefox-3.0.14-1.el4.x86_64.rpm firefox-debuginfo-3.0.14-1.el4.x86_64.rpm nspr-4.7.5-1.el4_8.i386.rpm nspr-4.7.5-1.el4_8.x86_64.rpm nspr-debuginfo-4.7.5-1.el4_8.i386.rpm nspr-debuginfo-4.7.5-1.el4_8.x86_64.rpm nspr-devel-4.7.5-1.el4_8.x86_64.rpm Red Hat Enterprise Linux WS version 4: Source: i386: firefox-3.0.14-1.el4.i386.rpm firefox-debuginfo-3.0.14-1.el4.i386.rpm nspr-4.7.5-1.el4_8.i386.rpm nspr-debuginfo-4.7.5-1.el4_8.i386.rpm nspr-devel-4.7.5-1.el4_8.i386.rpm ia64: firefox-3.0.14-1.el4.ia64.rpm firefox-debuginfo-3.0.14-1.el4.ia64.rpm nspr-4.7.5-1.el4_8.i386.rpm nspr-4.7.5-1.el4_8.ia64.rpm nspr-debuginfo-4.7.5-1.el4_8.i386.rpm nspr-debuginfo-4.7.5-1.el4_8.ia64.rpm nspr-devel-4.7.5-1.el4_8.ia64.rpm x86_64: firefox-3.0.14-1.el4.x86_64.rpm firefox-debuginfo-3.0.14-1.el4.x86_64.rpm nspr-4.7.5-1.el4_8.i386.rpm nspr-4.7.5-1.el4_8.x86_64.rpm nspr-debuginfo-4.7.5-1.el4_8.i386.rpm nspr-debuginfo-4.7.5-1.el4_8.x86_64.rpm nspr-devel-4.7.5-1.el4_8.x86_64.rpm Red Hat Enterprise Linux Desktop (v. 5client): Source: i386: firefox-3.0.14-1.el5_4.i386.rpm firefox-debuginfo-3.0.14-1.el5_4.i386.rpm nspr-4.7.5-1.el5_4.i386.rpm nspr-debuginfo-4.7.5-1.el5_4.i386.rpm xulrunner-1.9.0.14-1.el5_4.i386.rpm xulrunner-debuginfo-1.9.0.14-1.el5_4.i386.rpm x86_64: firefox-3.0.14-1.el5_4.i386.rpm firefox-3.0.14-1.el5_4.x86_64.rpm firefox-debuginfo-3.0.14-1.el5_4.i386.rpm firefox-debuginfo-3.0.14-1.el5_4.x86_64.rpm nspr-4.7.5-1.el5_4.i386.rpm nspr-4.7.5-1.el5_4.x86_64.rpm nspr-debuginfo-4.7.5-1.el5_4.i386.rpm nspr-debuginfo-4.7.5-1.el5_4.x86_64.rpm xulrunner-1.9.0.14-1.el5_4.i386.rpm xulrunner-1.9.0.14-1.el5_4.x86_64.rpm xulrunner-debuginfo-1.9.0.14-1.el5_4.i386.rpm xulrunner-debuginfo-1.9.0.14-1.el5_4.x86_64.rpm RHEL Desktop Workstation (v. 5 client): Source: i386: nspr-debuginfo-4.7.5-1.el5_4.i386.rpm nspr-devel-4.7.5-1.el5_4.i386.rpm xulrunner-debuginfo-1.9.0.14-1.el5_4.i386.rpm xulrunner-devel-1.9.0.14-1.el5_4.i386.rpm xulrunner-devel-unstable-1.9.0.14-1.el5_4.i386.rpm x86_64: nspr-debuginfo-4.7.5-1.el5_4.i386.rpm nspr-debuginfo-4.7.5-1.el5_4.x86_64.rpm nspr-devel-4.7.5-1.el5_4.i386.rpm nspr-devel-4.7.5-1.el5_4.x86_64.rpm xulrunner-debuginfo-1.9.0.14-1.el5_4.i386.rpm xulrunner-debuginfo-1.9.0.14-1.el5_4.x86_64.rpm xulrunner-devel-1.9.0.14-1.el5_4.i386.rpm xulrunner-devel-1.9.0.14-1.el5_4.x86_64.rpm xulrunner-devel-unstable-1.9.0.14-1.el5_4.x86_64.rpm Red Hat Enterprise Linux (v. 5server): Source: i386: firefox-3.0.14-1.el5_4.i386.rpm firefox-debuginfo-3.0.14-1.el5_4.i386.rpm nspr-4.7.5-1.el5_4.i386.rpm nspr-debuginfo-4.7.5-1.el5_4.i386.rpm nspr-devel-4.7.5-1.el5_4.i386.rpm xulrunner-1.9.0.14-1.el5_4.i386.rpm xulrunner-debuginfo-1.9.0.14-1.el5_4.i386.rpm xulrunner-devel-1.9.0.14-1.el5_4.i386.rpm xulrunner-devel-unstable-1.9.0.14-1.el5_4.i386.rpm ia64: firefox-3.0.14-1.el5_4.ia64.rpm firefox-debuginfo-3.0.14-1.el5_4.ia64.rpm nspr-4.7.5-1.el5_4.i386.rpm nspr-4.7.5-1.el5_4.ia64.rpm nspr-debuginfo-4.7.5-1.el5_4.i386.rpm nspr-debuginfo-4.7.5-1.el5_4.ia64.rpm nspr-devel-4.7.5-1.el5_4.ia64.rpm xulrunner-1.9.0.14-1.el5_4.ia64.rpm xulrunner-debuginfo-1.9.0.14-1.el5_4.ia64.rpm xulrunner-devel-1.9.0.14-1.el5_4.ia64.rpm xulrunner-devel-unstable-1.9.0.14-1.el5_4.ia64.rpm ppc: firefox-3.0.14-1.el5_4.ppc.rpm firefox-debuginfo-3.0.14-1.el5_4.ppc.rpm nspr-4.7.5-1.el5_4.ppc.rpm nspr-4.7.5-1.el5_4.ppc64.rpm nspr-debuginfo-4.7.5-1.el5_4.ppc.rpm nspr-debuginfo-4.7.5-1.el5_4.ppc64.rpm nspr-devel-4.7.5-1.el5_4.ppc.rpm nspr-devel-4.7.5-1.el5_4.ppc64.rpm xulrunner-1.9.0.14-1.el5_4.ppc.rpm xulrunner-1.9.0.14-1.el5_4.ppc64.rpm xulrunner-debuginfo-1.9.0.14-1.el5_4.ppc.rpm xulrunner-debuginfo-1.9.0.14-1.el5_4.ppc64.rpm xulrunner-devel-1.9.0.14-1.el5_4.ppc.rpm xulrunner-devel-1.9.0.14-1.el5_4.ppc64.rpm xulrunner-devel-unstable-1.9.0.14-1.el5_4.ppc.rpm s390x: firefox-3.0.14-1.el5_4.s390.rpm firefox-3.0.14-1.el5_4.s390x.rpm firefox-debuginfo-3.0.14-1.el5_4.s390.rpm firefox-debuginfo-3.0.14-1.el5_4.s390x.rpm nspr-4.7.5-1.el5_4.s390.rpm nspr-4.7.5-1.el5_4.s390x.rpm nspr-debuginfo-4.7.5-1.el5_4.s390.rpm nspr-debuginfo-4.7.5-1.el5_4.s390x.rpm nspr-devel-4.7.5-1.el5_4.s390.rpm nspr-devel-4.7.5-1.el5_4.s390x.rpm xulrunner-1.9.0.14-1.el5_4.s390.rpm xulrunner-1.9.0.14-1.el5_4.s390x.rpm xulrunner-debuginfo-1.9.0.14-1.el5_4.s390.rpm xulrunner-debuginfo-1.9.0.14-1.el5_4.s390x.rpm xulrunner-devel-1.9.0.14-1.el5_4.s390.rpm xulrunner-devel-1.9.0.14-1.el5_4.s390x.rpm xulrunner-devel-unstable-1.9.0.14-1.el5_4.s390x.rpm x86_64: firefox-3.0.14-1.el5_4.i386.rpm firefox-3.0.14-1.el5_4.x86_64.rpm firefox-debuginfo-3.0.14-1.el5_4.i386.rpm firefox-debuginfo-3.0.14-1.el5_4.x86_64.rpm nspr-4.7.5-1.el5_4.i386.rpm nspr-4.7.5-1.el5_4.x86_64.rpm nspr-debuginfo-4.7.5-1.el5_4.i386.rpm nspr-debuginfo-4.7.5-1.el5_4.x86_64.rpm nspr-devel-4.7.5-1.el5_4.i386.rpm nspr-devel-4.7.5-1.el5_4.x86_64.rpm xulrunner-1.9.0.14-1.el5_4.i386.rpm xulrunner-1.9.0.14-1.el5_4.x86_64.rpm xulrunner-debuginfo-1.9.0.14-1.el5_4.i386.rpm xulrunner-debuginfo-1.9.0.14-1.el5_4.x86_64.rpm xulrunner-devel-1.9.0.14-1.el5_4.i386.rpm xulrunner-devel-1.9.0.14-1.el5_4.x86_64.rpm xulrunner-devel-unstable-1.9.0.14-1.el5_4.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://www.cve.org/CVERecord?id=CVE-2009-2654 https://www.cve.org/CVERecord?id=CVE-2009-3070 https://www.cve.org/CVERecord?id=CVE-2009-3071 https://www.cve.org/CVERecord?id=CVE-2009-3072 https://www.cve.org/CVERecord?id=CVE-2009-3074 https://www.cve.org/CVERecord?id=CVE-2009-3075 https://www.cve.org/CVERecord?id=CVE-2009-3076 https://www.cve.org/CVERecord?id=CVE-2009-3077 https://www.cve.org/CVERecord?id=CVE-2009-3078 https://www.cve.org/CVERecord?id=CVE-2009-3079 https://access.redhat.com/security/updates/classification#critical https://www.mozilla.org/en-US/security/known-vulnerabilities/firefox-3.0/ 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2009 Red Hat, Inc. . Uncover pivotal chrome enhancement RHSA-2010:1540-01 tackling browser vulnerabilities on CentOS platforms.. firefox update, red hat advisory, critical security patch. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 09, 2009 Critical Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200