Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 436
Alerts This Week
Warning Icon 1 436

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -1 articles for you...
100

SUSE: 2025:02280-1 critical: tomcat vulnerabilities and security risks

* bsc#1242722 * bsc#1243815 * bsc#1244649 * bsc#1244656 . # Security update for tomcat Announcement ID: SUSE-SU-2025:02280-1 Release Date: 2025-07-10T16:05:23Z Rating: important References: * bsc#1242722 * bsc#1243815 * bsc#1244649 * bsc#1244656 Cross-References: * CVE-2025-46701 * CVE-2025-48988 * CVE-2025-49125 CVSS scores: * CVE-2025-46701 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-46701 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2025-46701 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2025-48988 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-48988 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-48988 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-49125 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-49125 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2025-49125 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * openSUSE Leap 15.6 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux EnterpriseServer 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Manager Server 4.3 * Web and Scripting Module 15-SP6 * Web and Scripting Module 15-SP7 An update that solves three vulnerabilities and has one security fix can now be installed. ## Description: This update for tomcat fixes the following issues: * CVE-2025-46701: Fixed refactor CGI servlet to access resources via WebResources (bsc#1243815). * CVE-2025-48988: Fixed limits the total number of parts in a multi-part request and limits the size of the headers provided with each part (bsc#1244656). * CVE-2025-49125: Fixed expand checks for webAppMount (bsc#1244649). Other bugfixes: * Made permissions more secure (bsc#1242722) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-2280=1 * Web and Scripting Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Web-Scripting-15-SP6-2025-2280=1 * Web and Scripting Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Web-Scripting-15-SP7-2025-2280=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2025-2280=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2025-2280=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2025-2280=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patchSUSE-SLE-Product-HPC-15-SP5-ESPOS-2025-2280=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2025-2280=1 * SUSE Linux Enterprise Server 15 SP3 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2025-2280=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2025-2280=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2025-2280=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2025-2280=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2025-2280=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2025-2280=1 * SUSE Manager Server 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.3-2025-2280=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2025-2280=1 ## Package List: * openSUSE Leap 15.6 (noarch) * tomcat-lib-9.0.106-150200.86.1 * tomcat-jsp-2_3-api-9.0.106-150200.86.1 * tomcat-9.0.106-150200.86.1 * tomcat-webapps-9.0.106-150200.86.1 * tomcat-el-3_0-api-9.0.106-150200.86.1 * tomcat-admin-webapps-9.0.106-150200.86.1 * tomcat-embed-9.0.106-150200.86.1 * tomcat-javadoc-9.0.106-150200.86.1 * tomcat-servlet-4_0-api-9.0.106-150200.86.1 * tomcat-docs-webapp-9.0.106-150200.86.1 * tomcat-jsvc-9.0.106-150200.86.1 * Web and Scripting Module 15-SP6 (noarch) * tomcat-lib-9.0.106-150200.86.1 * tomcat-jsp-2_3-api-9.0.106-150200.86.1 * tomcat-9.0.106-150200.86.1 * tomcat-webapps-9.0.106-150200.86.1 * tomcat-el-3_0-api-9.0.106-150200.86.1 * tomcat-admin-webapps-9.0.106-150200.86.1 * tomcat-servlet-4_0-api-9.0.106-150200.86.1 * Web and Scripting Module 15-SP7 (noarch) *tomcat-lib-9.0.106-150200.86.1 * tomcat-jsp-2_3-api-9.0.106-150200.86.1 * tomcat-9.0.106-150200.86.1 * tomcat-webapps-9.0.106-150200.86.1 * tomcat-el-3_0-api-9.0.106-150200.86.1 * tomcat-admin-webapps-9.0.106-150200.86.1 * tomcat-servlet-4_0-api-9.0.106-150200.86.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (noarch) * tomcat-lib-9.0.106-150200.86.1 * tomcat-jsp-2_3-api-9.0.106-150200.86.1 * tomcat-9.0.106-150200.86.1 * tomcat-webapps-9.0.106-150200.86.1 * tomcat-el-3_0-api-9.0.106-150200.86.1 * tomcat-admin-webapps-9.0.106-150200.86.1 * tomcat-servlet-4_0-api-9.0.106-150200.86.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * tomcat-lib-9.0.106-150200.86.1 * tomcat-jsp-2_3-api-9.0.106-150200.86.1 * tomcat-9.0.106-150200.86.1 * tomcat-webapps-9.0.106-150200.86.1 * tomcat-el-3_0-api-9.0.106-150200.86.1 * tomcat-admin-webapps-9.0.106-150200.86.1 * tomcat-servlet-4_0-api-9.0.106-150200.86.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * tomcat-lib-9.0.106-150200.86.1 * tomcat-jsp-2_3-api-9.0.106-150200.86.1 * tomcat-9.0.106-150200.86.1 * tomcat-webapps-9.0.106-150200.86.1 * tomcat-el-3_0-api-9.0.106-150200.86.1 * tomcat-admin-webapps-9.0.106-150200.86.1 * tomcat-servlet-4_0-api-9.0.106-150200.86.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * tomcat-lib-9.0.106-150200.86.1 * tomcat-jsp-2_3-api-9.0.106-150200.86.1 * tomcat-9.0.106-150200.86.1 * tomcat-webapps-9.0.106-150200.86.1 * tomcat-el-3_0-api-9.0.106-150200.86.1 * tomcat-admin-webapps-9.0.106-150200.86.1 * tomcat-servlet-4_0-api-9.0.106-150200.86.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * tomcat-lib-9.0.106-150200.86.1 * tomcat-jsp-2_3-api-9.0.106-150200.86.1 * tomcat-9.0.106-150200.86.1 * tomcat-webapps-9.0.106-150200.86.1 * tomcat-el-3_0-api-9.0.106-150200.86.1 * tomcat-admin-webapps-9.0.106-150200.86.1 * tomcat-servlet-4_0-api-9.0.106-150200.86.1 * SUSE Linux Enterprise Server 15 SP3 LTSS (noarch) * tomcat-lib-9.0.106-150200.86.1 * tomcat-jsp-2_3-api-9.0.106-150200.86.1 * tomcat-9.0.106-150200.86.1 * tomcat-webapps-9.0.106-150200.86.1 * tomcat-el-3_0-api-9.0.106-150200.86.1 * tomcat-admin-webapps-9.0.106-150200.86.1 * tomcat-servlet-4_0-api-9.0.106-150200.86.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * tomcat-lib-9.0.106-150200.86.1 * tomcat-jsp-2_3-api-9.0.106-150200.86.1 * tomcat-9.0.106-150200.86.1 * tomcat-webapps-9.0.106-150200.86.1 * tomcat-el-3_0-api-9.0.106-150200.86.1 * tomcat-admin-webapps-9.0.106-150200.86.1 * tomcat-servlet-4_0-api-9.0.106-150200.86.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * tomcat-lib-9.0.106-150200.86.1 * tomcat-jsp-2_3-api-9.0.106-150200.86.1 * tomcat-9.0.106-150200.86.1 * tomcat-webapps-9.0.106-150200.86.1 * tomcat-el-3_0-api-9.0.106-150200.86.1 * tomcat-admin-webapps-9.0.106-150200.86.1 * tomcat-servlet-4_0-api-9.0.106-150200.86.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (noarch) * tomcat-lib-9.0.106-150200.86.1 * tomcat-jsp-2_3-api-9.0.106-150200.86.1 * tomcat-9.0.106-150200.86.1 * tomcat-webapps-9.0.106-150200.86.1 * tomcat-el-3_0-api-9.0.106-150200.86.1 * tomcat-admin-webapps-9.0.106-150200.86.1 * tomcat-servlet-4_0-api-9.0.106-150200.86.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * tomcat-lib-9.0.106-150200.86.1 * tomcat-jsp-2_3-api-9.0.106-150200.86.1 * tomcat-9.0.106-150200.86.1 * tomcat-webapps-9.0.106-150200.86.1 * tomcat-el-3_0-api-9.0.106-150200.86.1 * tomcat-admin-webapps-9.0.106-150200.86.1 * tomcat-servlet-4_0-api-9.0.106-150200.86.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * tomcat-lib-9.0.106-150200.86.1 * tomcat-jsp-2_3-api-9.0.106-150200.86.1 *tomcat-9.0.106-150200.86.1 * tomcat-webapps-9.0.106-150200.86.1 * tomcat-el-3_0-api-9.0.106-150200.86.1 * tomcat-admin-webapps-9.0.106-150200.86.1 * tomcat-servlet-4_0-api-9.0.106-150200.86.1 * SUSE Manager Server 4.3 (noarch) * tomcat-lib-9.0.106-150200.86.1 * tomcat-jsp-2_3-api-9.0.106-150200.86.1 * tomcat-9.0.106-150200.86.1 * tomcat-webapps-9.0.106-150200.86.1 * tomcat-el-3_0-api-9.0.106-150200.86.1 * tomcat-admin-webapps-9.0.106-150200.86.1 * tomcat-servlet-4_0-api-9.0.106-150200.86.1 * SUSE Enterprise Storage 7.1 (noarch) * tomcat-lib-9.0.106-150200.86.1 * tomcat-jsp-2_3-api-9.0.106-150200.86.1 * tomcat-9.0.106-150200.86.1 * tomcat-webapps-9.0.106-150200.86.1 * tomcat-el-3_0-api-9.0.106-150200.86.1 * tomcat-admin-webapps-9.0.106-150200.86.1 * tomcat-servlet-4_0-api-9.0.106-150200.86.1 ## References: * https://www.suse.com/security/cve/CVE-2025-46701.html * https://www.suse.com/security/cve/CVE-2025-48988.html * https://www.suse.com/security/cve/CVE-2025-49125.html * https://bugzilla.suse.com/show_bug.cgi?id=1242722 * https://bugzilla.suse.com/show_bug.cgi?id=1243815 * https://bugzilla.suse.com/show_bug.cgi?id=1244649 * https://bugzilla.suse.com/show_bug.cgi?id=1244656 . Recent SUSE update tackles critical tomcat security flaws, offering solutions for various vulnerabilities. Immediate upgrade advised.. SUSE tomcat update important security patches. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 10, 2025 Important SuSE
198

Arch Linux: 202107-20 High Severity: Firefox Code Execution and Spoofing

The package firefox before version 90.0-1 is vulnerable to multiple issues including arbitrary code execution, content spoofing and insufficient validation. . Arch Linux Security Advisory ASA-202107-20 ========================================= Severity: High Date : 2021-07-14 CVE-ID : CVE-2021-29970 CVE-2021-29972 CVE-2021-29974 CVE-2021-29975 CVE-2021-29976 CVE-2021-29977 CVE-2021-30547 Package : firefox Type : multiple issues Remote : Yes Link : https://security.archlinux.org/AVG-2148 Summary ====== The package firefox before version 90.0-1 is vulnerable to multiple issues including arbitrary code execution, content spoofing and insufficient validation. Resolution ========= Upgrade to 90.0-1. # pacman -Syu "firefox> =90.0-1" The problems have been fixed upstream in version 90.0. Workaround ========= None. Description ========== - CVE-2021-29970 (arbitrary code execution) A malicious webpage could have triggered a use-after-free, memory corruption, and a potentially exploitable crash. This bug only affected Firefox before version 90 and Thunderbird before version 78.12 when accessibility was enabled. - CVE-2021-29972 (arbitrary code execution) A user-after-free vulnerability was found via testing, and traced to an out-of-date Cairo library. Updating the library resolved the issue, and may have remediated other, unknown security vulnerabilities as well. - CVE-2021-29974 (insufficient validation) When network partitioning was enabled, e.g. as a result of Enhanced Tracking Protection settings, a TLS error page would allow the user to override an error on a domain which had specified HTTP Strict Transport Security (which implies that the error should not be override-able.) This issue did not affect the network connections, and they were correctly upgraded to HTTPS automatically. - CVE-2021-29975 (content spoofing) Through a series of DOM manipulations, a message, over which the attacker had control of the text but not HTML or formatting, could be overlaid on top of another domain(with the new domain correctly shown in the address bar) resulting in possible user confusion. - CVE-2021-29976 (arbitrary code execution) Mozilla developers reported memory safety bugs present in Firefox 89 and Thunderbird 78.11. Some of these bugs showed evidence of memory corruption and Mozilla presumes that with enough effort some of these could have been exploited to run arbitrary code. - CVE-2021-29977 (arbitrary code execution) Mozilla developers reported memory safety bugs present in Firefox 89. Some of these bugs showed evidence of memory corruption and Mozilla presumes that with enough effort some of these could have been exploited to run arbitrary code. - CVE-2021-30547 (arbitrary code execution) An out of bounds write in ANGLE could have allowed an attacker to corrupt memory leading to a potentially exploitable crash in the Chromium browser engine before version 91.0.4472.101, Firefox before version 90 and Thunderbird before version 78.12. Impact ===== A remote attacker could execute arbitrary code or spoof content using a crafted webpage. References ========= https://www.mozilla.org/en-US/security/advisories/mfsa2021-28/ https://www.mozilla.org/en-US/security/advisories/mfsa2021-30/ https://bugzilla.mozilla.org/show_bug.cgi?id=1709976 https://bugzilla.mozilla.org/show_bug.cgi?id=1696816 https://bugzilla.mozilla.org/show_bug.cgi?id=1704843 https://bugzilla.mozilla.org/show_bug.cgi?id=1713259 https://bugzilla.mozilla.org/buglist.cgi?bug_id=1700895%2C1703334%2C1706910%2C1711576%2C1714391 https://bugzilla.mozilla.org/buglist.cgi?bug_id=1665836%2C1686138%2C1704316%2C1706314%2C1709931%2C1712084%2C1712357%2C1714066 https://chromereleases.googleblog.com/2021/06/stable-channel-update-for-desktop.html https://bugzilla.mozilla.org/show_bug.cgi?id=1715766 https://security.archlinux.org/CVE-2021-29970 https://security.archlinux.org/CVE-2021-29972 https://security.archlinux.org/CVE-2021-29974 https://security.archlinux.org/CVE-2021-29975 https://security.archlinux.org/CVE-2021-29976 https://security.archlinux.org/CVE-2021-29977 https://security.archlinux.org/CVE-2021-30547 . Significant flaws discovered in Firefox editions earlier than 90.0-1, concentrating on remote code execution and deceptive content presentation.. firefox issues, arch linux security, high severity threat, code execution exploit. . LinuxSecurity.com Team

Calendar%202 Jul 16, 2021 ArchLinux
202

openSUSE: 2018:2728-1 Moderate Security Update For Chromium

An update that contains security fixes can now be installed.. openSUSE Security Update: Security update for chromium ______________________________________________________________________________ Announcement ID: openSUSE-SU-2018:2728-1 Rating: moderate References: #1108114 #1108175 Affected Products: openSUSE Leap 42.3 openSUSE Leap 15.0 ______________________________________________________________________________ An update that contains security fixes can now be installed. Description: This update for Chromium to version 69.0.3497.92 fixes the following issues: Security issues fixed ((boo#1108114): - Function signature mismatch in WebAssembly - URL Spoofing in Omnibox The following tracked packaging issues were fixed: - the chromium package incorrectly provied swiftshader resolvables (boo#1108175) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 42.3: zypper in -t patch openSUSE-2018-1005=1 - openSUSE Leap 15.0: zypper in -t patch openSUSE-2018-1005=1 Package List: - openSUSE Leap 42.3 (x86_64): chromedriver-69.0.3497.92-171.1 chromedriver-debuginfo-69.0.3497.92-171.1 chromium-69.0.3497.92-171.1 chromium-debuginfo-69.0.3497.92-171.1 chromium-debugsource-69.0.3497.92-171.1 - openSUSE Leap 15.0 (x86_64): chromedriver-69.0.3497.92-lp150.2.13.1 chromedriver-debuginfo-69.0.3497.92-lp150.2.13.1 chromium-69.0.3497.92-lp150.2.13.1 chromium-debuginfo-69.0.3497.92-lp150.2.13.1 chromium-debugsource-69.0.3497.92-lp150.2.13.1 References: https://bugzilla.suse.com/1108114 https://bugzilla.suse.com/1108175 -- . OpenSUSE: 2021:4854-2 critical security patch addressing Firefox vulnerabilities. Update through preferredprocedures.. OpenSUSE Leap 42.3, Chromium Security, Update Installation, Browser Threats, OS Patching. . LinuxSecurity.com Team

Calendar%202 Sep 15, 2018 OpenSUSE
89

Fedora 26: 2017-0ad0e2f390 Critical: WebkitGTK4 Code Execution Risk

This update addresses the following vulnerabilities: * [CVE-2017-13866](https://www.cve.org/CVERecord?id=CVE-2017-13866), [CVE-2017-13870](https://www.cve.org/CVERecord?id=CVE-2017-13870), [CVE-2017-7156](https://www.cve.org/CVERecord?id=CVE-2017-7156), [CVE-2017-13856](https://www.cve.org/CVERecord?id=CVE-2017-13856). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-0ad0e2f390 2018-01-09 15:17:15.719766 --------------------------------------------------------------------------------Name : webkitgtk4 Product : Fedora 26 Version : 2.18.4 Release : 1.fc26 URL : https://www.webkitgtk.org/ Summary : GTK+ Web content engine library Description : WebKitGTK+ is the port of the portable web rendering engine WebKit to the GTK+ platform. This package contains WebKitGTK+ for GTK+ 3. --------------------------------------------------------------------------------Update Information: This update addresses the following vulnerabilities: * [CVE-2017-13866](https://www.cve.org/CVERecord?id=CVE-2017-13866), [CVE-2017-13870](https://www.cve.org/CVERecord?id=CVE-2017-13870), [CVE-2017-7156](https://www.cve.org/CVERecord?id=CVE-2017-7156), [CVE-2017-13856](https://www.cve.org/CVERecord?id=CVE-2017-13856) Additional fixes: * Make WebDriver implementation more spec compliant. * Fix a bug when trying to remove cookies before a web process is spawned. * WebKitWebDriver process no longer links to libjavascriptcoregtk. * Fix several memory leaks in GStreamer media backend. --------------------------------------------------------------------------------References: [ 1 ] Bug #1527747 - CVE-2017-13856 webkitgtk: Processing maliciously crafted web content may lead to arbitrary code execution https://bugzilla.redhat.com/show_bug.cgi?id=1527747 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnfupgrade webkitgtk4' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Tackling vulnerabilities in webkitgtk4 for Fedora 26. Upgrade immediately to safeguard yourself from serious risks.. Fedora WebkitGTK4 Security, System Update Alerts, Critical Web Flaws, Code Execution Risks. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 09, 2018 Critical Fedora
172

Ubuntu 14.10: USN-2458-1 Moderate: Firefox Crash And Code Risks

Firefox could be made to crash or run programs as your login if it opened a malicious website.. =========================================================================Ubuntu Security Notice USN-2458-1 January 14, 2015 firefox vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.10 - Ubuntu 14.04 LTS - Ubuntu 12.04 LTS Summary: Firefox could be made to crash or run programs as your login if it opened a malicious website. Software Description: - firefox: Mozilla Open Source web browser Details: Christian Holler, Patrick McManus, Christoph Diehl, Gary Kwong, Jesse Ruderman, Byron Campen, Terrence Cole, and Nils Ohlmeier discovered multiple memory safety issues in Firefox. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking Firefox. (CVE-2014-8634, CVE-2014-8635) Bobby Holley discovered that some DOM objects with certain properties can bypass XrayWrappers in some circumstances. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to bypass security restrictions. (CVE-2014-8636) Michal Zalewski discovered a use of uninitialized memory when rendering malformed bitmap images on a canvas element. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to steal confidential information. (CVE-2014-8637) Muneaki Nishimura discovered that requests from navigator.sendBeacon() lack an origin header. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to conduct cross-site request forgery (XSRF) attacks. (CVE-2014-8638) Xiaofeng Zheng discovered that a web proxy returning a 407 response could inject cookies in tothe originally requested domain. If a user connected to a malicious web proxy, an attacker could potentially exploit this to conduct session-fixation attacks. (CVE-2014-8639) Holger Fuhrmannek discovered a crash in Web Audio while manipulating timelines. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service. (CVE-2014-8640) Mitchell Harper discovered a use-after-free in WebRTC. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking Firefox. (CVE-2014-8641) Brian Smith discovered that OCSP responses would fail to verify if signed by a delegated OCSP responder certificate with the id-pkix-ocsp-nocheck extension, potentially allowing a user to connect to a site with a revoked certificate. (CVE-2014-8642) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.10: firefox 35.0+build3-0ubuntu0.14.10.2 Ubuntu 14.04 LTS: firefox 35.0+build3-0ubuntu0.14.04.2 Ubuntu 12.04 LTS: firefox 35.0+build3-0ubuntu0.12.04.2 After a standard system update you need to restart Firefox to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2458-1 CVE-2014-8634, CVE-2014-8635, CVE-2014-8636, CVE-2014-8637, CVE-2014-8638, CVE-2014-8639, CVE-2014-8640, CVE-2014-8641, CVE-2014-8642 Package Information: https://launchpad.net/ubuntu/+source/firefox/35.0+build3-0ubuntu0.14.10.2 https://launchpad.net/ubuntu/+source/firefox/35.0+build3-0ubuntu0.14.04.2 https://launchpad.net/ubuntu/+source/firefox/35.0+build3-0ubuntu0.12.04.2 . Users of Firefox are encountering crashes and potential code execution threats due to flaws found in the latest versions.It's important to update immediately.. firefox Security Issues, Ubuntu Updates, Web Browser Threats, Application Exploits. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 14, 2015 Important Ubuntu
200

Scientific Linux: SLSA-2023:2150-3 Important: Chromium Security Enhancement

Critical: firefox security update. Date: Tue, 6 Aug 2013 08:39:49 -0500 Reply-To: Pat Riehecky Sender: Security Errata for Scientific Linux From: Pat Riehecky Subject: FASTBUGS for SL 5x i386, x86_64 now available MIME-Version: 1.0 The following FASTBUGS have been uploaded to i386: cman-2.0.115-109.el5_9.4.i386.rpm cman-devel-2.0.115-109.el5_9.4.i386.rpm kmod-cciss-3.6.28-2.el5_9.i686.rpm kmod-cciss-PAE-3.6.28-2.el5_9.i686.rpm kmod-cciss-xen-3.6.28-2.el5_9.i686.rpm libxml2-2.6.26-2.1.21.el5_9.3.i386.rpm libxml2-devel-2.6.26-2.1.21.el5_9.3.i386.rpm libxml2-python-2.6.26-2.1.21.el5_9.3.i386.rpm poppler-0.5.4-19.el5_9.2.i386.rpm poppler-devel-0.5.4-19.el5_9.2.i386.rpm poppler-utils-0.5.4-19.el5_9.2.i386.rpm x86_64: cman-2.0.115-109.el5_9.4.x86_64.rpm cman-devel-2.0.115-109.el5_9.4.i386.rpm cman-devel-2.0.115-109.el5_9.4.x86_64.rpm kmod-cciss-3.6.28-2.el5_9.x86_64.rpm kmod-cciss-xen-3.6.28-2.el5_9.x86_64.rpm libxml2-2.6.26-2.1.21.el5_9.3.i386.rpm libxml2-2.6.26-2.1.21.el5_9.3.x86_64.rpm libxml2-devel-2.6.26-2.1.21.el5_9.3.i386.rpm libxml2-devel-2.6.26-2.1.21.el5_9.3.x86_64.rpm libxml2-python-2.6.26-2.1.21.el5_9.3.x86_64.rpm poppler-0.5.4-19.el5_9.2.i386.rpm poppler-0.5.4-19.el5_9.2.x86_64.rpm poppler-devel-0.5.4-19.el5_9.2.i386.rpm poppler-devel-0.5.4-19.el5_9.2.x86_64.rpm poppler-utils-0.5.4-19.el5_9.2.x86_64.rpm Date: Wed, 7 Aug 2013 14:00:18 +0000 Reply-To: scientific-linux-users@ Sender: Security Errata for Scientific Linux From: Pat Riehecky Subject: Security ERRATA Critical: firefox on SL5.x, SL6.x i386/x86_64 MIME-Version: 1.0 Synopsis: Critical: firefox security update Advisory ID: SLSA-2013:1140-1 Issue Date: 2013-08-07 CVE Numbers: CVE-2013-1701 CVE-2013-1709 CVE-2013-1710 CVE-2013-1713 CVE-2013-1714 CVE-2013-1717 -- Several flaws were found in the processing of malformed web content. A web page containing malicious content could cause Firefox to crash or, potentially, execute arbitrary code with the privileges of the user running Firefox. (CVE-2013-1701) A flaw was found in theway Firefox generated Certificate Request Message Format (CRMF) requests. An attacker could use this flaw to perform cross-site scripting (XSS) attacks or execute arbitrary code with the privileges of the user running Firefox. (CVE-2013-1710) A flaw was found in the way Firefox handled the interaction between frames and browser history. An attacker could use this flaw to trick Firefox into treating malicious content as if it came from the browser history, allowing for XSS attacks. (CVE-2013-1709) It was found that the same-origin policy could be bypassed due to the way Uniform Resource Identifiers (URI) were checked in JavaScript. An attacker could use this flaw to perform XSS attacks, or install malicious add-ons from third-party pages. (CVE-2013-1713) It was found that web workers could bypass the same-origin policy. An attacker could use this flaw to perform XSS attacks. (CVE-2013-1714) It was found that, in certain circumstances, Firefox incorrectly handled Java applets. If a user launched an untrusted Java applet via Firefox, the applet could use this flaw to obtain read-only access to files on the user's local system. (CVE-2013-1717) After installing the update, Firefox must be restarted for the changes to take effect. -- SL5 x86_64 firefox-17.0.8-1.el5_9.i386.rpm firefox-17.0.8-1.el5_9.x86_64.rpm firefox-debuginfo-17.0.8-1.el5_9.i386.rpm firefox-debuginfo-17.0.8-1.el5_9.x86_64.rpm xulrunner-17.0.8-3.el5_9.i386.rpm xulrunner-17.0.8-3.el5_9.x86_64.rpm xulrunner-debuginfo-17.0.8-3.el5_9.i386.rpm xulrunner-debuginfo-17.0.8-3.el5_9.x86_64.rpm xulrunner-devel-17.0.8-3.el5_9.i386.rpm xulrunner-devel-17.0.8-3.el5_9.x86_64.rpm i386 firefox-17.0.8-1.el5_9.i386.rpm firefox-debuginfo-17.0.8-1.el5_9.i386.rpm xulrunner-17.0.8-3.el5_9.i386.rpm xulrunner-debuginfo-17.0.8-3.el5_9.i386.rpm xulrunner-devel-17.0.8-3.el5_9.i386.rpm SL6 x86_64 firefox-17.0.8-1.el6_4.i686.rpm firefox-17.0.8-1.el6_4.x86_64.rpm firefox-debuginfo-17.0.8-1.el6_4.i686.rpm firefox-debuginfo-17.0.8-1.el6_4.x86_64.rpm xulrunner-17.0.8-3.el6_4.i686.rpm xulrunner-17.0.8-3.el6_4.x86_64.rpm xulrunner-debuginfo-17.0.8-3.el6_4.i686.rpm xulrunner-debuginfo-17.0.8-3.el6_4.x86_64.rpm xulrunner-devel-17.0.8-3.el6_4.i686.rpm xulrunner-devel-17.0.8-3.el6_4.x86_64.rpm i386 firefox-17.0.8-1.el6_4.i686.rpm firefox-debuginfo-17.0.8-1.el6_4.i686.rpm xulrunner-17.0.8-3.el6_4.i686.rpm xulrunner-debuginfo-17.0.8-3.el6_4.i686.rpm xulrunner-devel-17.0.8-3.el6_4.i686.rpm - Scientific Linux Development Team . Important Firefox update for Scientific Linux resolves several security flaws, including the potential for remote code execution.. firefox Security Update, Scientific Linux Advisory, Web Threat Mitigation, Critical Security Fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Aug 07, 2013 Important Scientific Linux
98

Red Hat Enterprise Linux: RHSA-2008:1036-01 Critical: Firefox Threats

An updated firefox package that fixes various security issues is now available for Red Hat Enterprise Linux 4 and 5. This update has been rated as having critical security impact by the Red Hat Security Response Team.. ==================================================================== Red Hat Security Advisory Synopsis: Critical: firefox security update Advisory ID: RHSA-2008:1036-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2008:1036.html Issue date: 2008-12-16 CVE Names: CVE-2008-5500 CVE-2008-5501 CVE-2008-5502 CVE-2008-5505 CVE-2008-5506 CVE-2008-5507 CVE-2008-5508 CVE-2008-5510 CVE-2008-5511 CVE-2008-5512 CVE-2008-5513 ==================================================================== 1. Summary: An updated firefox package that fixes various security issues is now available for Red Hat Enterprise Linux 4 and 5. This update has been rated as having critical security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Enterprise Linux Desktop version 4 - i386, x86_64 Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64 Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64 RHEL Desktop Workstation (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64 3. Description: Mozilla Firefox is an open source Web browser. Several flaws were found in the processing of malformed web content. A web page containing malicious content could cause Firefox to crash or, potentially, execute arbitrary code as the user running Firefox. (CVE-2008-5500, CVE-2008-5501, CVE-2008-5502, CVE-2008-5511, CVE-2008-5512, CVE-2008-5513) Several flaws were found in the way malformed contentwas processed. A website containing specially-crafted content could potentially trick a Firefox user into surrendering sensitive information. (CVE-2008-5506, CVE-2008-5507) A flaw was found in the way Firefox stored attributes in XML User Interface Language (XUL) elements. A web site could use this flaw to track users across browser sessions, even if users did not allow the site to store cookies in the victim's browser. (CVE-2008-5505) A flaw was found in the way malformed URLs were processed by Firefox. This flaw could prevent various URL sanitization mechanisms from properly parsing a malicious URL. (CVE-2008-5508) A flaw was found in Firefox's CSS parser. A malicious web page could inject NULL characters into a CSS input string, possibly bypassing an application's script sanitization routines. (CVE-2008-5510) For technical details regarding these flaws, please see the Mozilla security advisories for Firefox 3.0.5. You can find a link to the Mozilla advisories in the References section. Note: after the errata packages are installed, Firefox must be restarted for the update to take effect. All firefox users should upgrade to these updated packages, which contain backported patches that correct these issues. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. This update is available via Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at 5. Package List: Red Hat Enterprise Linux AS version4: Source: i386: firefox-3.0.5-1.el4.i386.rpm firefox-debuginfo-3.0.5-1.el4.i386.rpm nspr-4.7.3-1.el4.i386.rpm nspr-debuginfo-4.7.3-1.el4.i386.rpm nspr-devel-4.7.3-1.el4.i386.rpm nss-3.12.2.0-1.el4.i386.rpm nss-debuginfo-3.12.2.0-1.el4.i386.rpm nss-devel-3.12.2.0-1.el4.i386.rpm ia64: firefox-3.0.5-1.el4.ia64.rpm firefox-debuginfo-3.0.5-1.el4.ia64.rpm nspr-4.7.3-1.el4.i386.rpm nspr-4.7.3-1.el4.ia64.rpm nspr-debuginfo-4.7.3-1.el4.ia64.rpm nspr-devel-4.7.3-1.el4.ia64.rpm nss-3.12.2.0-1.el4.i386.rpm nss-3.12.2.0-1.el4.ia64.rpm nss-debuginfo-3.12.2.0-1.el4.ia64.rpm nss-devel-3.12.2.0-1.el4.ia64.rpm ppc: firefox-3.0.5-1.el4.ppc.rpm firefox-debuginfo-3.0.5-1.el4.ppc.rpm nspr-4.7.3-1.el4.ppc.rpm nspr-4.7.3-1.el4.ppc64.rpm nspr-debuginfo-4.7.3-1.el4.ppc.rpm nspr-debuginfo-4.7.3-1.el4.ppc64.rpm nspr-devel-4.7.3-1.el4.ppc.rpm nss-3.12.2.0-1.el4.ppc.rpm nss-3.12.2.0-1.el4.ppc64.rpm nss-debuginfo-3.12.2.0-1.el4.ppc.rpm nss-debuginfo-3.12.2.0-1.el4.ppc64.rpm nss-devel-3.12.2.0-1.el4.ppc.rpm s390: firefox-3.0.5-1.el4.s390.rpm firefox-debuginfo-3.0.5-1.el4.s390.rpm nspr-4.7.3-1.el4.s390.rpm nspr-debuginfo-4.7.3-1.el4.s390.rpm nspr-devel-4.7.3-1.el4.s390.rpm nss-3.12.2.0-1.el4.s390.rpm nss-debuginfo-3.12.2.0-1.el4.s390.rpm nss-devel-3.12.2.0-1.el4.s390.rpm s390x: firefox-3.0.5-1.el4.s390x.rpm firefox-debuginfo-3.0.5-1.el4.s390x.rpm nspr-4.7.3-1.el4.s390.rpm nspr-4.7.3-1.el4.s390x.rpm nspr-debuginfo-4.7.3-1.el4.s390x.rpm nspr-devel-4.7.3-1.el4.s390x.rpm nss-3.12.2.0-1.el4.s390.rpm nss-3.12.2.0-1.el4.s390x.rpm nss-debuginfo-3.12.2.0-1.el4.s390x.rpm nss-devel-3.12.2.0-1.el4.s390x.rpm x86_64: firefox-3.0.5-1.el4.x86_64.rpm firefox-debuginfo-3.0.5-1.el4.x86_64.rpm nspr-4.7.3-1.el4.i386.rpm nspr-4.7.3-1.el4.x86_64.rpm nspr-debuginfo-4.7.3-1.el4.x86_64.rpm nspr-devel-4.7.3-1.el4.x86_64.rpm nss-3.12.2.0-1.el4.i386.rpm nss-3.12.2.0-1.el4.x86_64.rpm nss-debuginfo-3.12.2.0-1.el4.x86_64.rpm nss-devel-3.12.2.0-1.el4.x86_64.rpm Red Hat Enterprise Linux Desktopversion 4: Source: i386: firefox-3.0.5-1.el4.i386.rpm firefox-debuginfo-3.0.5-1.el4.i386.rpm nspr-4.7.3-1.el4.i386.rpm nspr-debuginfo-4.7.3-1.el4.i386.rpm nspr-devel-4.7.3-1.el4.i386.rpm nss-3.12.2.0-1.el4.i386.rpm nss-debuginfo-3.12.2.0-1.el4.i386.rpm nss-devel-3.12.2.0-1.el4.i386.rpm x86_64: firefox-3.0.5-1.el4.x86_64.rpm firefox-debuginfo-3.0.5-1.el4.x86_64.rpm nspr-4.7.3-1.el4.i386.rpm nspr-4.7.3-1.el4.x86_64.rpm nspr-debuginfo-4.7.3-1.el4.x86_64.rpm nspr-devel-4.7.3-1.el4.x86_64.rpm nss-3.12.2.0-1.el4.i386.rpm nss-3.12.2.0-1.el4.x86_64.rpm nss-debuginfo-3.12.2.0-1.el4.x86_64.rpm nss-devel-3.12.2.0-1.el4.x86_64.rpm Red Hat Enterprise Linux ES version 4: Source: i386: firefox-3.0.5-1.el4.i386.rpm firefox-debuginfo-3.0.5-1.el4.i386.rpm nspr-4.7.3-1.el4.i386.rpm nspr-debuginfo-4.7.3-1.el4.i386.rpm nspr-devel-4.7.3-1.el4.i386.rpm nss-3.12.2.0-1.el4.i386.rpm nss-debuginfo-3.12.2.0-1.el4.i386.rpm nss-devel-3.12.2.0-1.el4.i386.rpm ia64: firefox-3.0.5-1.el4.ia64.rpm firefox-debuginfo-3.0.5-1.el4.ia64.rpm nspr-4.7.3-1.el4.i386.rpm nspr-4.7.3-1.el4.ia64.rpm nspr-debuginfo-4.7.3-1.el4.ia64.rpm nspr-devel-4.7.3-1.el4.ia64.rpm nss-3.12.2.0-1.el4.i386.rpm nss-3.12.2.0-1.el4.ia64.rpm nss-debuginfo-3.12.2.0-1.el4.ia64.rpm nss-devel-3.12.2.0-1.el4.ia64.rpm x86_64: firefox-3.0.5-1.el4.x86_64.rpm firefox-debuginfo-3.0.5-1.el4.x86_64.rpm nspr-4.7.3-1.el4.i386.rpm nspr-4.7.3-1.el4.x86_64.rpm nspr-debuginfo-4.7.3-1.el4.x86_64.rpm nspr-devel-4.7.3-1.el4.x86_64.rpm nss-3.12.2.0-1.el4.i386.rpm nss-3.12.2.0-1.el4.x86_64.rpm nss-debuginfo-3.12.2.0-1.el4.x86_64.rpm nss-devel-3.12.2.0-1.el4.x86_64.rpm Red Hat Enterprise Linux WS version4: Source: i386: firefox-3.0.5-1.el4.i386.rpm firefox-debuginfo-3.0.5-1.el4.i386.rpm nspr-4.7.3-1.el4.i386.rpm nspr-debuginfo-4.7.3-1.el4.i386.rpm nspr-devel-4.7.3-1.el4.i386.rpm nss-3.12.2.0-1.el4.i386.rpm nss-debuginfo-3.12.2.0-1.el4.i386.rpm nss-devel-3.12.2.0-1.el4.i386.rpm ia64: firefox-3.0.5-1.el4.ia64.rpm firefox-debuginfo-3.0.5-1.el4.ia64.rpm nspr-4.7.3-1.el4.i386.rpm nspr-4.7.3-1.el4.ia64.rpm nspr-debuginfo-4.7.3-1.el4.ia64.rpm nspr-devel-4.7.3-1.el4.ia64.rpm nss-3.12.2.0-1.el4.i386.rpm nss-3.12.2.0-1.el4.ia64.rpm nss-debuginfo-3.12.2.0-1.el4.ia64.rpm nss-devel-3.12.2.0-1.el4.ia64.rpm x86_64: firefox-3.0.5-1.el4.x86_64.rpm firefox-debuginfo-3.0.5-1.el4.x86_64.rpm nspr-4.7.3-1.el4.i386.rpm nspr-4.7.3-1.el4.x86_64.rpm nspr-debuginfo-4.7.3-1.el4.x86_64.rpm nspr-devel-4.7.3-1.el4.x86_64.rpm nss-3.12.2.0-1.el4.i386.rpm nss-3.12.2.0-1.el4.x86_64.rpm nss-debuginfo-3.12.2.0-1.el4.x86_64.rpm nss-devel-3.12.2.0-1.el4.x86_64.rpm Red Hat Enterprise Linux Desktop (v. 5 client): Source: i386: firefox-3.0.5-1.el5_2.i386.rpm firefox-debuginfo-3.0.5-1.el5_2.i386.rpm nspr-4.7.3-2.el5.i386.rpm nspr-debuginfo-4.7.3-2.el5.i386.rpm nss-3.12.2.0-2.el5.i386.rpm nss-debuginfo-3.12.2.0-2.el5.i386.rpm nss-tools-3.12.2.0-2.el5.i386.rpm xulrunner-1.9.0.5-1.el5_2.i386.rpm xulrunner-debuginfo-1.9.0.5-1.el5_2.i386.rpm x86_64: firefox-3.0.5-1.el5_2.i386.rpm firefox-3.0.5-1.el5_2.x86_64.rpm firefox-debuginfo-3.0.5-1.el5_2.i386.rpm firefox-debuginfo-3.0.5-1.el5_2.x86_64.rpm nspr-4.7.3-2.el5.i386.rpm nspr-4.7.3-2.el5.x86_64.rpm nspr-debuginfo-4.7.3-2.el5.i386.rpm nspr-debuginfo-4.7.3-2.el5.x86_64.rpm nss-3.12.2.0-2.el5.i386.rpm nss-3.12.2.0-2.el5.x86_64.rpm nss-debuginfo-3.12.2.0-2.el5.i386.rpm nss-debuginfo-3.12.2.0-2.el5.x86_64.rpm nss-tools-3.12.2.0-2.el5.x86_64.rpm xulrunner-1.9.0.5-1.el5_2.i386.rpm xulrunner-1.9.0.5-1.el5_2.x86_64.rpm xulrunner-debuginfo-1.9.0.5-1.el5_2.i386.rpm xulrunner-debuginfo-1.9.0.5-1.el5_2.x86_64.rpm RHEL Desktop Workstation (v.5 client): Source: i386: nspr-debuginfo-4.7.3-2.el5.i386.rpm nspr-devel-4.7.3-2.el5.i386.rpm nss-debuginfo-3.12.2.0-2.el5.i386.rpm nss-devel-3.12.2.0-2.el5.i386.rpm nss-pkcs11-devel-3.12.2.0-2.el5.i386.rpm xulrunner-debuginfo-1.9.0.5-1.el5_2.i386.rpm xulrunner-devel-1.9.0.5-1.el5_2.i386.rpm xulrunner-devel-unstable-1.9.0.5-1.el5_2.i386.rpm x86_64: nspr-debuginfo-4.7.3-2.el5.i386.rpm nspr-debuginfo-4.7.3-2.el5.x86_64.rpm nspr-devel-4.7.3-2.el5.i386.rpm nspr-devel-4.7.3-2.el5.x86_64.rpm nss-debuginfo-3.12.2.0-2.el5.i386.rpm nss-debuginfo-3.12.2.0-2.el5.x86_64.rpm nss-devel-3.12.2.0-2.el5.i386.rpm nss-devel-3.12.2.0-2.el5.x86_64.rpm nss-pkcs11-devel-3.12.2.0-2.el5.i386.rpm nss-pkcs11-devel-3.12.2.0-2.el5.x86_64.rpm xulrunner-debuginfo-1.9.0.5-1.el5_2.i386.rpm xulrunner-debuginfo-1.9.0.5-1.el5_2.x86_64.rpm xulrunner-devel-1.9.0.5-1.el5_2.i386.rpm xulrunner-devel-1.9.0.5-1.el5_2.x86_64.rpm xulrunner-devel-unstable-1.9.0.5-1.el5_2.x86_64.rpm Red Hat Enterprise Linux (v. 5server): Source: i386: firefox-3.0.5-1.el5_2.i386.rpm firefox-debuginfo-3.0.5-1.el5_2.i386.rpm nspr-4.7.3-2.el5.i386.rpm nspr-debuginfo-4.7.3-2.el5.i386.rpm nspr-devel-4.7.3-2.el5.i386.rpm nss-3.12.2.0-2.el5.i386.rpm nss-debuginfo-3.12.2.0-2.el5.i386.rpm nss-devel-3.12.2.0-2.el5.i386.rpm nss-pkcs11-devel-3.12.2.0-2.el5.i386.rpm nss-tools-3.12.2.0-2.el5.i386.rpm xulrunner-1.9.0.5-1.el5_2.i386.rpm xulrunner-debuginfo-1.9.0.5-1.el5_2.i386.rpm xulrunner-devel-1.9.0.5-1.el5_2.i386.rpm xulrunner-devel-unstable-1.9.0.5-1.el5_2.i386.rpm ia64: firefox-3.0.5-1.el5_2.ia64.rpm firefox-debuginfo-3.0.5-1.el5_2.ia64.rpm nspr-4.7.3-2.el5.i386.rpm nspr-4.7.3-2.el5.ia64.rpm nspr-debuginfo-4.7.3-2.el5.i386.rpm nspr-debuginfo-4.7.3-2.el5.ia64.rpm nspr-devel-4.7.3-2.el5.ia64.rpm nss-3.12.2.0-2.el5.i386.rpm nss-3.12.2.0-2.el5.ia64.rpm nss-debuginfo-3.12.2.0-2.el5.i386.rpm nss-debuginfo-3.12.2.0-2.el5.ia64.rpm nss-devel-3.12.2.0-2.el5.ia64.rpm nss-pkcs11-devel-3.12.2.0-2.el5.ia64.rpm nss-tools-3.12.2.0-2.el5.ia64.rpm xulrunner-1.9.0.5-1.el5_2.ia64.rpm xulrunner-debuginfo-1.9.0.5-1.el5_2.ia64.rpm xulrunner-devel-1.9.0.5-1.el5_2.ia64.rpm xulrunner-devel-unstable-1.9.0.5-1.el5_2.ia64.rpm ppc: firefox-3.0.5-1.el5_2.ppc.rpm firefox-debuginfo-3.0.5-1.el5_2.ppc.rpm nspr-4.7.3-2.el5.ppc.rpm nspr-4.7.3-2.el5.ppc64.rpm nspr-debuginfo-4.7.3-2.el5.ppc.rpm nspr-debuginfo-4.7.3-2.el5.ppc64.rpm nspr-devel-4.7.3-2.el5.ppc.rpm nspr-devel-4.7.3-2.el5.ppc64.rpm nss-3.12.2.0-2.el5.ppc.rpm nss-3.12.2.0-2.el5.ppc64.rpm nss-debuginfo-3.12.2.0-2.el5.ppc.rpm nss-debuginfo-3.12.2.0-2.el5.ppc64.rpm nss-devel-3.12.2.0-2.el5.ppc.rpm nss-devel-3.12.2.0-2.el5.ppc64.rpm nss-pkcs11-devel-3.12.2.0-2.el5.ppc.rpm nss-pkcs11-devel-3.12.2.0-2.el5.ppc64.rpm nss-tools-3.12.2.0-2.el5.ppc.rpm xulrunner-1.9.0.5-1.el5_2.ppc.rpm xulrunner-1.9.0.5-1.el5_2.ppc64.rpm xulrunner-debuginfo-1.9.0.5-1.el5_2.ppc.rpm xulrunner-debuginfo-1.9.0.5-1.el5_2.ppc64.rpm xulrunner-devel-1.9.0.5-1.el5_2.ppc.rpm xulrunner-devel-1.9.0.5-1.el5_2.ppc64.rpm xulrunner-devel-unstable-1.9.0.5-1.el5_2.ppc.rpm s390x: firefox-3.0.5-1.el5_2.s390.rpm firefox-3.0.5-1.el5_2.s390x.rpm firefox-debuginfo-3.0.5-1.el5_2.s390.rpm firefox-debuginfo-3.0.5-1.el5_2.s390x.rpm nspr-4.7.3-2.el5.s390.rpm nspr-4.7.3-2.el5.s390x.rpm nspr-debuginfo-4.7.3-2.el5.s390.rpm nspr-debuginfo-4.7.3-2.el5.s390x.rpm nspr-devel-4.7.3-2.el5.s390.rpm nspr-devel-4.7.3-2.el5.s390x.rpm nss-3.12.2.0-2.el5.s390.rpm nss-3.12.2.0-2.el5.s390x.rpm nss-debuginfo-3.12.2.0-2.el5.s390.rpm nss-debuginfo-3.12.2.0-2.el5.s390x.rpm nss-devel-3.12.2.0-2.el5.s390.rpm nss-devel-3.12.2.0-2.el5.s390x.rpm nss-pkcs11-devel-3.12.2.0-2.el5.s390.rpm nss-pkcs11-devel-3.12.2.0-2.el5.s390x.rpm nss-tools-3.12.2.0-2.el5.s390x.rpm xulrunner-1.9.0.5-1.el5_2.s390.rpm xulrunner-1.9.0.5-1.el5_2.s390x.rpm xulrunner-debuginfo-1.9.0.5-1.el5_2.s390.rpm xulrunner-debuginfo-1.9.0.5-1.el5_2.s390x.rpm xulrunner-devel-1.9.0.5-1.el5_2.s390.rpm xulrunner-devel-1.9.0.5-1.el5_2.s390x.rpm xulrunner-devel-unstable-1.9.0.5-1.el5_2.s390x.rpm x86_64: firefox-3.0.5-1.el5_2.i386.rpm firefox-3.0.5-1.el5_2.x86_64.rpm firefox-debuginfo-3.0.5-1.el5_2.i386.rpm firefox-debuginfo-3.0.5-1.el5_2.x86_64.rpm nspr-4.7.3-2.el5.i386.rpm nspr-4.7.3-2.el5.x86_64.rpm nspr-debuginfo-4.7.3-2.el5.i386.rpm nspr-debuginfo-4.7.3-2.el5.x86_64.rpm nspr-devel-4.7.3-2.el5.i386.rpm nspr-devel-4.7.3-2.el5.x86_64.rpm nss-3.12.2.0-2.el5.i386.rpm nss-3.12.2.0-2.el5.x86_64.rpm nss-debuginfo-3.12.2.0-2.el5.i386.rpm nss-debuginfo-3.12.2.0-2.el5.x86_64.rpm nss-devel-3.12.2.0-2.el5.i386.rpm nss-devel-3.12.2.0-2.el5.x86_64.rpm nss-pkcs11-devel-3.12.2.0-2.el5.i386.rpm nss-pkcs11-devel-3.12.2.0-2.el5.x86_64.rpm nss-tools-3.12.2.0-2.el5.x86_64.rpm xulrunner-1.9.0.5-1.el5_2.i386.rpm xulrunner-1.9.0.5-1.el5_2.x86_64.rpm xulrunner-debuginfo-1.9.0.5-1.el5_2.i386.rpm xulrunner-debuginfo-1.9.0.5-1.el5_2.x86_64.rpm xulrunner-devel-1.9.0.5-1.el5_2.i386.rpm xulrunner-devel-1.9.0.5-1.el5_2.x86_64.rpm xulrunner-devel-unstable-1.9.0.5-1.el5_2.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/#package 6. References: https://www.cve.org/CVERecord?id=CVE-2008-5500 https://www.cve.org/CVERecord?id=CVE-2008-5501 https://www.cve.org/CVERecord?id=CVE-2008-5502 https://www.cve.org/CVERecord?id=CVE-2008-5505 https://www.cve.org/CVERecord?id=CVE-2008-5506 https://www.cve.org/CVERecord?id=CVE-2008-5507 https://www.cve.org/CVERecord?id=CVE-2008-5508 https://www.cve.org/CVERecord?id=CVE-2008-5510 https://www.cve.org/CVERecord?id=CVE-2008-5511 https://www.cve.org/CVERecord?id=CVE-2008-5512 https://www.cve.org/CVERecord?id=CVE-2008-5513 https://www.mozilla.org/en-US/security/known-vulnerabilities/firefox-3.0/ 7. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2008 Red Hat, Inc. . Significant Chrome security patch issued for Ubuntu, vital for protection against threats and attack methods.. firefox Security Update, Red Hat Enterprise, Critical Security Update, Firefox Threats. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 16, 2008 Critical Red Hat
98

Red Hat Enterprise Linux 4 and 5: RHSA-2008:0879-01 Critical Firefox Issues

An updated firefox package that fixes various security issues is now available for Red Hat Enterprise Linux 4 and 5. This update has been rated as having critical security impact by the Red Hat Security Response Team.. ==================================================================== Red Hat Security Advisory Synopsis: Critical: firefox security update Advisory ID: RHSA-2008:0879-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2008:0879.html Issue date: 2008-09-23 CVE Names: CVE-2008-3837 CVE-2008-4058 CVE-2008-4060 CVE-2008-4061 CVE-2008-4062 CVE-2008-4063 CVE-2008-4064 CVE-2008-4065 CVE-2008-4067 CVE-2008-4068 ==================================================================== 1. Summary: An updated firefox package that fixes various security issues is now available for Red Hat Enterprise Linux 4 and 5. This update has been rated as having critical security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Enterprise Linux Desktop version 4 - i386, x86_64 Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64 Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64 RHEL Desktop Workstation (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64 3. Description: Mozilla Firefox is an open source Web browser. Several flaws were found in the processing of malformed web content. A web page containing malicious content could cause Firefox to crash or, potentially, execute arbitrary code as the user running Firefox. (CVE-2008-4058, CVE-2008-4060, CVE-2008-4061, CVE-2008-4062, CVE-2008-4063, CVE-2008-4064) Several flaws were found in the way malformed web content wasdisplayed. A web page containing specially crafted content could potentially trick a Firefox user into surrendering sensitive information. (CVE-2008-4067, CVE-2008-4068) A flaw was found in the way Firefox handles mouse click events. A web page containing specially crafted JavaScript code could move the content window while a mouse-button was pressed, causing any item under the pointer to be dragged. This could, potentially, cause the user to perform an unsafe drag-and-drop action. (CVE-2008-3837) A flaw was found in Firefox that caused certain characters to be stripped from JavaScript code. This flaw could allow malicious JavaScript to bypass or evade script filters. (CVE-2008-4065) For technical details regarding these flaws, please see the Mozilla security advisories for Firefox 3.0.2. You can find a link to the Mozilla advisories in the References section. All firefox users should upgrade to this updated package, which contains backported patches that correct these issues. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. This update is available via Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at 5. Bugs fixed (http://bugzilla.redhat.com/): 463189 - CVE-2008-3837 Forced mouse drag 463190 - CVE-2008-4058 Mozilla privilege escalation via XPCnativeWrapper pollution 463198 - CVE-2008-4060 Mozilla privilege escalation via XPCnativeWrapper pollution 463199 - CVE-2008-4061 Mozilla layout engine crash 463201 - CVE-2008-4062 Mozilla crashes with evidence of memory corruption 463203 - CVE-2008-4063 Mozilla crashes with evidence of memory corruption 463204 - CVE-2008-4064 Mozilla crashes with evidence of memory corruption 463234 - CVE-2008-4065 Mozilla BOM characters stripped from JavaScript before execution 463246 - CVE-2008-4067 Mozilla resource: traversal vulnerability 463248 - CVE-2008-4068 Mozilla local HTML file recource: bypass 6.Package List: Red Hat Enterprise Linux AS version 4: Source: i386: firefox-3.0.2-3.el4.i386.rpm firefox-debuginfo-3.0.2-3.el4.i386.rpm ia64: firefox-3.0.2-3.el4.ia64.rpm firefox-debuginfo-3.0.2-3.el4.ia64.rpm ppc: firefox-3.0.2-3.el4.ppc.rpm firefox-debuginfo-3.0.2-3.el4.ppc.rpm s390: firefox-3.0.2-3.el4.s390.rpm firefox-debuginfo-3.0.2-3.el4.s390.rpm s390x: firefox-3.0.2-3.el4.s390x.rpm firefox-debuginfo-3.0.2-3.el4.s390x.rpm x86_64: firefox-3.0.2-3.el4.x86_64.rpm firefox-debuginfo-3.0.2-3.el4.x86_64.rpm Red Hat Enterprise Linux Desktop version 4: Source: i386: firefox-3.0.2-3.el4.i386.rpm firefox-debuginfo-3.0.2-3.el4.i386.rpm x86_64: firefox-3.0.2-3.el4.x86_64.rpm firefox-debuginfo-3.0.2-3.el4.x86_64.rpm Red Hat Enterprise Linux ES version 4: Source: i386: firefox-3.0.2-3.el4.i386.rpm firefox-debuginfo-3.0.2-3.el4.i386.rpm ia64: firefox-3.0.2-3.el4.ia64.rpm firefox-debuginfo-3.0.2-3.el4.ia64.rpm x86_64: firefox-3.0.2-3.el4.x86_64.rpm firefox-debuginfo-3.0.2-3.el4.x86_64.rpm Red Hat Enterprise Linux WS version 4: Source: i386: firefox-3.0.2-3.el4.i386.rpm firefox-debuginfo-3.0.2-3.el4.i386.rpm ia64: firefox-3.0.2-3.el4.ia64.rpm firefox-debuginfo-3.0.2-3.el4.ia64.rpm x86_64: firefox-3.0.2-3.el4.x86_64.rpm firefox-debuginfo-3.0.2-3.el4.x86_64.rpm Red Hat Enterprise Linux Desktop (v. 5client): Source: i386: devhelp-0.12-19.el5.i386.rpm devhelp-debuginfo-0.12-19.el5.i386.rpm firefox-3.0.2-3.el5.i386.rpm firefox-debuginfo-3.0.2-3.el5.i386.rpm nss-3.12.1.1-1.el5.i386.rpm nss-debuginfo-3.12.1.1-1.el5.i386.rpm nss-tools-3.12.1.1-1.el5.i386.rpm xulrunner-1.9.0.2-5.el5.i386.rpm xulrunner-debuginfo-1.9.0.2-5.el5.i386.rpm yelp-2.16.0-21.el5.i386.rpm yelp-debuginfo-2.16.0-21.el5.i386.rpm x86_64: devhelp-0.12-19.el5.i386.rpm devhelp-0.12-19.el5.x86_64.rpm devhelp-debuginfo-0.12-19.el5.i386.rpm devhelp-debuginfo-0.12-19.el5.x86_64.rpm firefox-3.0.2-3.el5.i386.rpm firefox-3.0.2-3.el5.x86_64.rpm firefox-debuginfo-3.0.2-3.el5.i386.rpm firefox-debuginfo-3.0.2-3.el5.x86_64.rpm nss-3.12.1.1-1.el5.i386.rpm nss-3.12.1.1-1.el5.x86_64.rpm nss-debuginfo-3.12.1.1-1.el5.i386.rpm nss-debuginfo-3.12.1.1-1.el5.x86_64.rpm nss-tools-3.12.1.1-1.el5.x86_64.rpm xulrunner-1.9.0.2-5.el5.i386.rpm xulrunner-1.9.0.2-5.el5.x86_64.rpm xulrunner-debuginfo-1.9.0.2-5.el5.i386.rpm xulrunner-debuginfo-1.9.0.2-5.el5.x86_64.rpm yelp-2.16.0-21.el5.x86_64.rpm yelp-debuginfo-2.16.0-21.el5.x86_64.rpm RHEL Desktop Workstation (v. 5client): Source: i386: devhelp-debuginfo-0.12-19.el5.i386.rpm devhelp-devel-0.12-19.el5.i386.rpm nss-debuginfo-3.12.1.1-1.el5.i386.rpm nss-devel-3.12.1.1-1.el5.i386.rpm nss-pkcs11-devel-3.12.1.1-1.el5.i386.rpm xulrunner-debuginfo-1.9.0.2-5.el5.i386.rpm xulrunner-devel-1.9.0.2-5.el5.i386.rpm xulrunner-devel-unstable-1.9.0.2-5.el5.i386.rpm x86_64: devhelp-debuginfo-0.12-19.el5.i386.rpm devhelp-debuginfo-0.12-19.el5.x86_64.rpm devhelp-devel-0.12-19.el5.i386.rpm devhelp-devel-0.12-19.el5.x86_64.rpm nss-debuginfo-3.12.1.1-1.el5.i386.rpm nss-debuginfo-3.12.1.1-1.el5.x86_64.rpm nss-devel-3.12.1.1-1.el5.i386.rpm nss-devel-3.12.1.1-1.el5.x86_64.rpm nss-pkcs11-devel-3.12.1.1-1.el5.i386.rpm nss-pkcs11-devel-3.12.1.1-1.el5.x86_64.rpm xulrunner-debuginfo-1.9.0.2-5.el5.i386.rpm xulrunner-debuginfo-1.9.0.2-5.el5.x86_64.rpm xulrunner-devel-1.9.0.2-5.el5.i386.rpm xulrunner-devel-1.9.0.2-5.el5.x86_64.rpm xulrunner-devel-unstable-1.9.0.2-5.el5.x86_64.rpm Red Hat Enterprise Linux (v. 5server): Source: i386: devhelp-0.12-19.el5.i386.rpm devhelp-debuginfo-0.12-19.el5.i386.rpm devhelp-devel-0.12-19.el5.i386.rpm firefox-3.0.2-3.el5.i386.rpm firefox-debuginfo-3.0.2-3.el5.i386.rpm nss-3.12.1.1-1.el5.i386.rpm nss-debuginfo-3.12.1.1-1.el5.i386.rpm nss-devel-3.12.1.1-1.el5.i386.rpm nss-pkcs11-devel-3.12.1.1-1.el5.i386.rpm nss-tools-3.12.1.1-1.el5.i386.rpm xulrunner-1.9.0.2-5.el5.i386.rpm xulrunner-debuginfo-1.9.0.2-5.el5.i386.rpm xulrunner-devel-1.9.0.2-5.el5.i386.rpm xulrunner-devel-unstable-1.9.0.2-5.el5.i386.rpm yelp-2.16.0-21.el5.i386.rpm yelp-debuginfo-2.16.0-21.el5.i386.rpm ia64: devhelp-0.12-19.el5.ia64.rpm devhelp-debuginfo-0.12-19.el5.ia64.rpm devhelp-devel-0.12-19.el5.ia64.rpm firefox-3.0.2-3.el5.ia64.rpm firefox-debuginfo-3.0.2-3.el5.ia64.rpm nss-3.12.1.1-1.el5.i386.rpm nss-3.12.1.1-1.el5.ia64.rpm nss-debuginfo-3.12.1.1-1.el5.i386.rpm nss-debuginfo-3.12.1.1-1.el5.ia64.rpm nss-devel-3.12.1.1-1.el5.ia64.rpm nss-pkcs11-devel-3.12.1.1-1.el5.ia64.rpm nss-tools-3.12.1.1-1.el5.ia64.rpm xulrunner-1.9.0.2-5.el5.ia64.rpm xulrunner-debuginfo-1.9.0.2-5.el5.ia64.rpm xulrunner-devel-1.9.0.2-5.el5.ia64.rpm xulrunner-devel-unstable-1.9.0.2-5.el5.ia64.rpm yelp-2.16.0-21.el5.ia64.rpm yelp-debuginfo-2.16.0-21.el5.ia64.rpm ppc: devhelp-0.12-19.el5.ppc.rpm devhelp-debuginfo-0.12-19.el5.ppc.rpm devhelp-devel-0.12-19.el5.ppc.rpm firefox-3.0.2-3.el5.ppc.rpm firefox-debuginfo-3.0.2-3.el5.ppc.rpm nss-3.12.1.1-1.el5.ppc.rpm nss-3.12.1.1-1.el5.ppc64.rpm nss-debuginfo-3.12.1.1-1.el5.ppc.rpm nss-debuginfo-3.12.1.1-1.el5.ppc64.rpm nss-devel-3.12.1.1-1.el5.ppc.rpm nss-devel-3.12.1.1-1.el5.ppc64.rpm nss-pkcs11-devel-3.12.1.1-1.el5.ppc.rpm nss-pkcs11-devel-3.12.1.1-1.el5.ppc64.rpm nss-tools-3.12.1.1-1.el5.ppc.rpm xulrunner-1.9.0.2-5.el5.ppc.rpm xulrunner-1.9.0.2-5.el5.ppc64.rpm xulrunner-debuginfo-1.9.0.2-5.el5.ppc.rpm xulrunner-debuginfo-1.9.0.2-5.el5.ppc64.rpm xulrunner-devel-1.9.0.2-5.el5.ppc.rpm xulrunner-devel-1.9.0.2-5.el5.ppc64.rpm xulrunner-devel-unstable-1.9.0.2-5.el5.ppc.rpm yelp-2.16.0-21.el5.ppc.rpm yelp-debuginfo-2.16.0-21.el5.ppc.rpm s390x: devhelp-0.12-19.el5.s390.rpm devhelp-0.12-19.el5.s390x.rpm devhelp-debuginfo-0.12-19.el5.s390.rpm devhelp-debuginfo-0.12-19.el5.s390x.rpm devhelp-devel-0.12-19.el5.s390.rpm devhelp-devel-0.12-19.el5.s390x.rpm firefox-3.0.2-3.el5.s390.rpm firefox-3.0.2-3.el5.s390x.rpm firefox-debuginfo-3.0.2-3.el5.s390.rpm firefox-debuginfo-3.0.2-3.el5.s390x.rpm nss-3.12.1.1-1.el5.s390.rpm nss-3.12.1.1-1.el5.s390x.rpm nss-debuginfo-3.12.1.1-1.el5.s390.rpm nss-debuginfo-3.12.1.1-1.el5.s390x.rpm nss-devel-3.12.1.1-1.el5.s390.rpm nss-devel-3.12.1.1-1.el5.s390x.rpm nss-pkcs11-devel-3.12.1.1-1.el5.s390.rpm nss-pkcs11-devel-3.12.1.1-1.el5.s390x.rpm nss-tools-3.12.1.1-1.el5.s390x.rpm xulrunner-1.9.0.2-5.el5.s390.rpm xulrunner-1.9.0.2-5.el5.s390x.rpm xulrunner-debuginfo-1.9.0.2-5.el5.s390.rpm xulrunner-debuginfo-1.9.0.2-5.el5.s390x.rpm xulrunner-devel-1.9.0.2-5.el5.s390.rpm xulrunner-devel-1.9.0.2-5.el5.s390x.rpm xulrunner-devel-unstable-1.9.0.2-5.el5.s390x.rpm yelp-2.16.0-21.el5.s390x.rpm yelp-debuginfo-2.16.0-21.el5.s390x.rpm x86_64: devhelp-0.12-19.el5.i386.rpm devhelp-0.12-19.el5.x86_64.rpm devhelp-debuginfo-0.12-19.el5.i386.rpm devhelp-debuginfo-0.12-19.el5.x86_64.rpm devhelp-devel-0.12-19.el5.i386.rpm devhelp-devel-0.12-19.el5.x86_64.rpm firefox-3.0.2-3.el5.i386.rpm firefox-3.0.2-3.el5.x86_64.rpm firefox-debuginfo-3.0.2-3.el5.i386.rpm firefox-debuginfo-3.0.2-3.el5.x86_64.rpm nss-3.12.1.1-1.el5.i386.rpm nss-3.12.1.1-1.el5.x86_64.rpm nss-debuginfo-3.12.1.1-1.el5.i386.rpm nss-debuginfo-3.12.1.1-1.el5.x86_64.rpm nss-devel-3.12.1.1-1.el5.i386.rpm nss-devel-3.12.1.1-1.el5.x86_64.rpm nss-pkcs11-devel-3.12.1.1-1.el5.i386.rpm nss-pkcs11-devel-3.12.1.1-1.el5.x86_64.rpm nss-tools-3.12.1.1-1.el5.x86_64.rpm xulrunner-1.9.0.2-5.el5.i386.rpm xulrunner-1.9.0.2-5.el5.x86_64.rpm xulrunner-debuginfo-1.9.0.2-5.el5.i386.rpm xulrunner-debuginfo-1.9.0.2-5.el5.x86_64.rpm xulrunner-devel-1.9.0.2-5.el5.i386.rpm xulrunner-devel-1.9.0.2-5.el5.x86_64.rpm xulrunner-devel-unstable-1.9.0.2-5.el5.x86_64.rpm yelp-2.16.0-21.el5.x86_64.rpm yelp-debuginfo-2.16.0-21.el5.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://www.cve.org/CVERecord?id=CVE-2008-3837 https://www.cve.org/CVERecord?id=CVE-2008-4058 https://www.cve.org/CVERecord?id=CVE-2008-4060 https://www.cve.org/CVERecord?id=CVE-2008-4061 https://www.cve.org/CVERecord?id=CVE-2008-4062 https://www.cve.org/CVERecord?id=CVE-2008-4063 https://www.cve.org/CVERecord?id=CVE-2008-4064 https://www.cve.org/CVERecord?id=CVE-2008-4065 https://www.cve.org/CVERecord?id=CVE-2008-4067 https://www.cve.org/CVERecord?id=CVE-2008-4068 https://www.mozilla.org/en-US/security/known-vulnerabilities/firefox-3.0/ 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2008 Red Hat, Inc. . Important security patch for Firefox released targeting Red Hat Enterprise Linux versions 4 and 5, mitigating serious online risks.. Red Hat, Enterprise Linux, Firefox Security, Critical Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 23, 2008 Critical Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200