| Description: | The remote host is missing updates announced in advisory SUSE-SA:2006:068.
MozillaFirefox has been updated to the security update release 1.5.0.8, MozillaThunderbird has been updated to 1.5.0.8, and the Mozilla Seamonkey suite has been updated to 1.0.6 to fix the following security issues.
Full details of the security problems can be found on: http://www.mozilla.org/projects/security/known-vulnerabilities.html
MFSA2006-65: This issue is split into 3 sub-entries, for ongoing stability improvements in the Mozilla browsers: CVE-2006-5464: Layout engine flaws were fixed. CVE-2006-5747: A xml.prototype.hasOwnProperty flaw was fixed. CVE-2006-5748: Fixes were applied to the Javascript engine.
MFSA2006-66/CVE-2006-5462: MFSA 2006-60 reported that RSA digital signatures with a low exponent (typically 3) could be forged. Firefox and Thunderbird 1.5.0.7, which incorporated NSS version 3.10.2, were incompletely patched and remained vulnerable to a variant of this attack.
MFSA2006-67/CVE-2006-5463: shutdown demonstrated that it was possible to modify a Script object while it was executing, potentially leading to the execution of arbitrary JavaScript bytecode.
Note that Mozilla Suite updates for products before SUSE Linux 10.1 / SLES 10 are not available yet due to backporting problems.
Solution: Update your system with the packages as indicated in the referenced security advisory.
http://www.securityspace.com/smysecure/catid.html?in=SUSE-SA:2006:068
Risk factor : High |