Update to new upstream Firefox version 3.0.15, fixing multiple security issues detailed in the upstream advisories: https://www.mozilla.org/en-US/security/known-vulnerabilities/firefox-3.0/ Update also includes all packages depending on gecko-libs rebuilt against new version of Firefox / XULRunner.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-10981 2009-11-04 10:56:11 -------------------------------------------------------------------------------- Name : gnome-web-photo Product : Fedora 10 Version : 0.3 Release : 23.fc10 URL : https://download.gnome.org/sources/gnome-web-photo/0.3/ Summary : HTML pages thumbnailer Description : gnome-web-photo contains a thumbnailer that will be used by GNOME applications, including the file manager, to generate screenshots of web pages. -------------------------------------------------------------------------------- Update Information: Update to new upstream Firefox version 3.0.15, fixing multiple security issues detailed in the upstream advisories: https://www.mozilla.org/en-US/security/known-vulnerabilities/firefox-3.0/ Update also includes all packages depending on gecko-libs rebuilt against new version of Firefox / XULRunner. -------------------------------------------------------------------------------- ChangeLog: * Tue Oct 27 2009 Jan Horak - 0.3-23 - Rebuild against newer gecko * Wed Sep 9 2009 Jan Horak - 0.3-22 - Rebuild against newer gecko * Tue Aug 4 2009 Jan Horak - 0.3-21 - Rebuild against newer gecko * Tue Jul 21 2009 Jan Horak - 0.3-20 - Rebuild against newer gecko * Thu Jun 11 2009 Christopher Aillon - 0.3-19 - Rebuild against newer gecko * Mon Apr 27 2009 Christopher Aillon - 0.3-18 - Rebuild against newer gecko * Tue Apr 21 2009 Christopher Aillon - 0.3-17 - Rebuild against newer gecko * Fri Mar 27 2009 Christopher Aillon - 0.3-16 - Rebuild against newer gecko * Fri Mar 6 2009 Jan Horak - 0.3-15 - Rebuild againstnewer gecko * Wed Feb 4 2009 Christopher Aillon - 0.3-14 - Rebuild against newer gecko * Wed Dec 17 2008 Christopher Aillon - 0.3-13 - Rebuild against newer gecko -------------------------------------------------------------------------------- References: [ 1 ] Bug #530567 - CVE-2009-3380 Firefox crashes with evidence of memory corruption https://bugzilla.redhat.com/show_bug.cgi?id=530567 [ 2 ] Bug #530569 - CVE-2009-3382 Firefox crashes with evidence of memory corruption https://bugzilla.redhat.com/show_bug.cgi?id=530569 [ 3 ] Bug #530168 - CVE-2009-3376 Firefox download filename spoofing with RTL override https://bugzilla.redhat.com/show_bug.cgi?id=530168 [ 4 ] Bug #530167 - CVE-2009-3375 Firefox cross-origin data theft through document.getSelection() https://bugzilla.redhat.com/show_bug.cgi?id=530167 [ 5 ] Bug #530162 - CVE-2009-1563 Firefox heap buffer overflow in string to number conversion https://bugzilla.redhat.com/show_bug.cgi?id=530162 [ 6 ] Bug #530157 - CVE-2009-3374 Firefox chrome privilege escalation in XPCVariant::VariantDataToJS() https://bugzilla.redhat.com/show_bug.cgi?id=530157 [ 7 ] Bug #530156 - CVE-2009-3373 Firefox heap buffer overflow in GIF color map parser https://bugzilla.redhat.com/show_bug.cgi?id=530156 [ 8 ] Bug #530155 - CVE-2009-3372 Firefox crash in proxy auto-configuration regexp parsing https://bugzilla.redhat.com/show_bug.cgi?id=530155 [ 9 ] Bug #524815 - CVE-2009-3274 Firefox: Predictable /tmp pathname use https://bugzilla.redhat.com/show_bug.cgi?id=524815 [ 10 ] Bug #530151 - CVE-2009-3370 Firefox form history vulnerable to stealing https://bugzilla.redhat.com/show_bug.cgi?id=530151 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update gnome-web-photo' at the command line. For more information, refer to "Managing Software with yum", available at . All packagesare signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list
Update to new upstream Firefox version 3.0.13, fixing multiple security issues detailed in the upstream advisories: https://www.mozilla.org/en-US/security/known-vulnerabilities/firefox-3.0/ Update also includes all packages depending on gecko-libs rebuilt against new version of Firefox / XULRunner. Note: Issues described in MFSA 2009-42 and MFSA 2009-43 were previously addressed via rebase of the NSS packages.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-8288 2009-08-05 00:00:31 -------------------------------------------------------------------------------- Name : gnome-web-photo Product : Fedora 10 Version : 0.3 Release : 21.fc10 URL : https://download.gnome.org/sources/gnome-web-photo/0.3/ Summary : HTML pages thumbnailer Description : gnome-web-photo contains a thumbnailer that will be used by GNOME applications, including the file manager, to generate screenshots of web pages. -------------------------------------------------------------------------------- Update Information: Update to new upstream Firefox version 3.0.13, fixing multiple security issues detailed in the upstream advisories: https://www.mozilla.org/en-US/security/known-vulnerabilities/firefox-3.0/ Update also includes all packages depending on gecko-libs rebuilt against new version of Firefox / XULRunner. Note: Issues described in MFSA 2009-42 and MFSA 2009-43 were previously addressed via rebase of the NSS packages. -------------------------------------------------------------------------------- ChangeLog: * Tue Aug 4 2009 Jan Horak - 0.3-21 - Rebuild against newer gecko * Tue Jul 21 2009 Jan Horak - 0.3-20 - Rebuild against newer gecko * Thu Jun 11 2009 Christopher Aillon - 0.3-19 - Rebuild against newer gecko * Mon Apr 27 2009 Christopher Aillon - 0.3-18 - Rebuild against newer gecko * Tue Apr 21 2009 Christopher Aillon - 0.3-17 - Rebuild against newer gecko * Fri Mar 27 2009 Christopher Aillon -0.3-16 - Rebuild against newer gecko * Fri Mar 6 2009 Jan Horak - 0.3-15 - Rebuild against newer gecko * Wed Feb 4 2009 Christopher Aillon - 0.3-14 - Rebuild against newer gecko * Wed Dec 17 2008 Christopher Aillon - 0.3-13 - Rebuild against newer gecko -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update gnome-web-photo' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list
Update to new upstream Firefox version 3.0.12, fixing multiple security issues detailed in the upstream advisories: https://www.mozilla.org/en-US/security/known-vulnerabilities/firefox-3.0/ Update also includes all packages depending on gecko-libs rebuilt against new version of Firefox / XULRunner.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-7961 2009-07-23 18:32:19 -------------------------------------------------------------------------------- Name : gnome-web-photo Product : Fedora 10 Version : 0.3 Release : 20.fc10 URL : https://download.gnome.org/sources/gnome-web-photo/0.3/ Summary : HTML pages thumbnailer Description : gnome-web-photo contains a thumbnailer that will be used by GNOME applications, including the file manager, to generate screenshots of web pages. -------------------------------------------------------------------------------- Update Information: Update to new upstream Firefox version 3.0.12, fixing multiple security issues detailed in the upstream advisories: https://www.mozilla.org/en-US/security/known-vulnerabilities/firefox-3.0/ Update also includes all packages depending on gecko-libs rebuilt against new version of Firefox / XULRunner. -------------------------------------------------------------------------------- ChangeLog: * Tue Jul 21 2009 Jan Horak - 0.3-20 - Rebuild against newer gecko * Thu Jun 11 2009 Christopher Aillon - 0.3-19 - Rebuild against newer gecko * Mon Apr 27 2009 Christopher Aillon - 0.3-18 - Rebuild against newer gecko * Tue Apr 21 2009 Christopher Aillon - 0.3-17 - Rebuild against newer gecko * Fri Mar 27 2009 Christopher Aillon - 0.3-16 - Rebuild against newer gecko * Fri Mar 6 2009 Jan Horak - 0.3-15 - Rebuild against newer gecko * Wed Feb 4 2009 Christopher Aillon - 0.3-14 - Rebuild against newer gecko * Wed Dec 17 2008 Christopher Aillon - 0.3-13 - Rebuild against newergecko -------------------------------------------------------------------------------- References: [ 1 ] Bug #512131 - CVE-2009-2463 Mozilla Base64 decoding crash https://bugzilla.redhat.com/show_bug.cgi?id=512131 [ 2 ] Bug #512133 - CVE-2009-2464 Mozilla crash with multiple RDFs in XUL tree https://bugzilla.redhat.com/show_bug.cgi?id=512133 [ 3 ] Bug #512135 - CVE-2009-2465 Mozilla double frame construction crashes https://bugzilla.redhat.com/show_bug.cgi?id=512135 [ 4 ] Bug #512128 - CVE-2009-2462 Mozilla Browser engine crashes https://bugzilla.redhat.com/show_bug.cgi?id=512128 [ 5 ] Bug #512136 - CVE-2009-2466 Mozilla JavaScript engine crashes https://bugzilla.redhat.com/show_bug.cgi?id=512136 [ 6 ] Bug #512137 - CVE-2009-2467 Mozilla remote code execution during Flash player unloading https://bugzilla.redhat.com/show_bug.cgi?id=512137 [ 7 ] Bug #512142 - CVE-2009-2469 Mozilla remote code execution using watch and __defineSetter__ on SVG element https://bugzilla.redhat.com/show_bug.cgi?id=512142 [ 8 ] Bug #512146 - CVE-2009-2471 Mozilla setTimeout loses XPCNativeWrappers https://bugzilla.redhat.com/show_bug.cgi?id=512146 [ 9 ] Bug #512147 - CVE-2009-2472 Mozilla multiple cross origin wrapper bypasses https://bugzilla.redhat.com/show_bug.cgi?id=512147 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update gnome-web-photo' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailinglist
Update to the new upstream Firefox 3.0.6 / XULRunner 1.9.0.6 fixing multiple security issues.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2009-1399 2009-02-06 04:16:47 --------------------------------------------------------------------------------Name : gnome-web-photo Product : Fedora 9 Version : 0.3 Release : 17.fc9 URL : https://download.gnome.org/sources/gnome-web-photo/0.3/ Summary : HTML pages thumbnailer Description : gnome-web-photo contains a thumbnailer that will be used by GNOME applications, including the file manager, to generate screenshots of web pages. --------------------------------------------------------------------------------Update Information: Update to the new upstream Firefox 3.0.6 / XULRunner 1.9.0.6 fixing multiple security issues: https://www.mozilla.org/en-US/security/known-vulnerabilities/firefox-3.0/ This update also contains new builds of all applications depending on Gecko libraries, built against the new version. Note: after the updated packages are installed, Firefox must be restarted for the update to take effect. --------------------------------------------------------------------------------ChangeLog: * Wed Feb 4 2009 Christopher Aillon - 0.3-17 - Rebuild against newer gecko * Wed Dec 17 2008 Christopher Aillon - 0.3-16 - Rebuild against newer gecko * Wed Nov 12 2008 Christopher Aillon - 0.3-15 - Rebuild against newer gecko * Wed Sep 24 2008 Christopher Aillon - 0.3-14 - Rebuild against newer gecko * Mon Jul 21 2008 Martin Stransky - 0.3-13 - Rebuild against new xulrunner * Fri Jun 20 2008 Martin Stransky - 0.3-12 - Rebuild against new xulrunner --------------------------------------------------------------------------------References: [ 1 ] Bug #483141 - CVE-2009-0353 Firefox javascript crashes with evidence of memory corruption https://bugzilla.redhat.com/show_bug.cgi?id=483141 [ 2 ] Bug #483143- CVE-2009-0355 Firefox local file stealing with SessionStore https://bugzilla.redhat.com/show_bug.cgi?id=483143 [ 3 ] Bug #483145 - CVE-2009-0357 Firefox XMLHttpRequest allows reading HTTPOnly cookies https://bugzilla.redhat.com/show_bug.cgi?id=483145 [ 4 ] Bug #483139 - CVE-2009-0352 Firefox layout crashes with evidence of memory corruption https://bugzilla.redhat.com/show_bug.cgi?id=483139 [ 5 ] Bug #483142 - CVE-2009-0354 Firefox XSS using a chrome XBL method and window.eval https://bugzilla.redhat.com/show_bug.cgi?id=483142 [ 6 ] Bug #483144 - CVE-2009-0356 Firefox Chrome privilege escalation via local .desktop files https://bugzilla.redhat.com/show_bug.cgi?id=483144 [ 7 ] Bug #483150 - CVE-2009-0358 Firefox directives to not cache pages ignored https://bugzilla.redhat.com/show_bug.cgi?id=483150 --------------------------------------------------------------------------------This update can be installed with the "yum" update program. Use su -c 'yum update gnome-web-photo' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ Fedora-package-announce mailing list
Get the latest Linux and open source security news straight to your inbox.