Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.51925
Category:Red Hat Local Security Checks
Title:RedHat Security Advisory RHSA-2005:336
Summary:NOSUMMARY
Description:Description:

The remote host is missing updates announced in
advisory RHSA-2005:336.

Mozilla Firefox is an open source Web browser.

A buffer overflow bug was found in the way Firefox processes GIF images. It
is possible for an attacker to create a specially crafted GIF image, which
when viewed by a victim will execute arbitrary code as the victim. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CVE-2005-0399 to this issue.

A bug was found in the way Firefox processes XUL content. If a malicious
web page can trick a user into dragging an object, it is possible to load
malicious XUL content. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CVE-2005-0401 to this issue.

A bug was found in the way Firefox bookmarks content to the sidebar. If a
user can be tricked into bookmarking a malicious web page into the sidebar
panel, that page could execute arbitrary programs. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CVE-2005-0402 to this issue.

Users of Firefox are advised to upgrade to this updated package which
contains Firefox version 1.0.2 and is not vulnerable to these issues.

Solution:
Please note that this update is available via
Red Hat Network. To use Red Hat Network, launch the Red
Hat Update Agent with the following command: up2date

http://rhn.redhat.com/errata/RHSA-2005-336.html

Risk factor : High

CVSS Score:
5.1

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2005-0399
12881
http://www.securityfocus.com/bid/12881
14654
http://secunia.com/advisories/14654
15495
http://www.securityfocus.com/bid/15495
19823
http://secunia.com/advisories/19823
20050323 Mozilla Foundation GIF Overflow
http://xforce.iss.net/xforce/alerts/id/191
ADV-2005-0296
http://www.vupen.com/english/advisories/2005/0296
GLSA-200503-30
http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml
P-160
http://www.ciac.org/ciac/bulletins/p-160.shtml
RHSA-2005:323
http://www.redhat.com/support/errata/RHSA-2005-323.html
RHSA-2005:335
http://www.redhat.com/support/errata/RHSA-2005-335.html
RHSA-2005:336
http://www.redhat.com/support/errata/RHSA-2005-336.html
RHSA-2005:337
http://www.redhat.com/support/errata/RHSA-2005-337.html
SCOSA-2005.49
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt
SUSE-SA:2006:022
http://www.novell.com/linux/security/advisories/2006_04_25.html
VU#557948
http://www.kb.cert.org/vuls/id/557948
gif-extension-overflow(19269)
https://exchange.xforce.ibmcloud.com/vulnerabilities/19269
http://www.mozilla.org/security/announce/mfsa2005-30.html
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=150877
oval:org.mitre.oval:def:100028
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100028
oval:org.mitre.oval:def:11377
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11377
Common Vulnerability Exposure (CVE) ID: CVE-2005-0401
12885
http://www.securityfocus.com/bid/12885
20050324 Firescrolling 2 [Firefox 1.0.1]
http://marc.info/?l=bugtraq&m=111168413007891&w=2
RHSA-2005:384
http://www.redhat.com/support/errata/RHSA-2005-384.html
http://mikx.de/firescrolling2/
http://www.mozilla.org/security/announce/mfsa2005-32.html
oval:org.mitre.oval:def:100026
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100026
oval:org.mitre.oval:def:9650
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9650
Common Vulnerability Exposure (CVE) ID: CVE-2005-0402
http://www.mozilla.org/security/announce/mfsa2005-31.html
https://bugzilla.mozilla.org/show_bug.cgi?id=284627
oval:org.mitre.oval:def:100027
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100027
oval:org.mitre.oval:def:11868
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11868
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.