Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.57689
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-1225-1)
Summary:The remote host is missing an update for the Debian 'mozilla-firefox' package(s) announced via the DSA-1225-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'mozilla-firefox' package(s) announced via the DSA-1225-1 advisory.

Vulnerability Insight:
This update covers packages for the little endian MIPS architecture missing in the original advisory. For reference please find below the original advisory text:

Several security related problems have been discovered in Mozilla and derived products such as Mozilla Firefox. The Common Vulnerabilities and Exposures project identifies the following vulnerabilities:

CVE-2006-4310

Tomas Kempinsky discovered that malformed FTP server responses could lead to denial of service.

CVE-2006-5462

Ulrich Kuhn discovered that the correction for a cryptographic flaw in the handling of PKCS-1 certificates was incomplete, which allows the forgery of certificates.

CVE-2006-5463

shutdown discovered that modification of JavaScript objects during execution could lead to the execution of arbitrary JavaScript bytecode.

CVE-2006-5464

Jesse Ruderman and Martijn Wargers discovered several crashes in the layout engine, which might also allow execution of arbitrary code.

CVE-2006-5748

Igor Bukanov and Jesse Ruderman discovered several crashes in the JavaScript engine, which might allow execution of arbitrary code.

This update also addresses several crashes, which could be triggered by malicious websites and fixes a regression introduced in the previous Mozilla update.

For the stable distribution (sarge) these problems have been fixed in version 1.0.4-2sarge13.

For the unstable distribution (sid) these problems have been fixed in the current iceweasel package 2.0+dfsg-1.

We recommend that you upgrade your mozilla-firefox package.

Affected Software/OS:
'mozilla-firefox' package(s) on Debian 3.1.

Solution:
Please install the updated package(s).

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2006-4310
BugTraq ID: 19678
http://www.securityfocus.com/bid/19678
Bugtraq: 20060822 (exploit) firefox 1.5.0.6 linux DoS (Google Search)
http://www.securityfocus.com/archive/1/444064/100/0/threaded
Debian Security Information: DSA-1224 (Google Search)
http://www.debian.org/security/2006/dsa-1224
Debian Security Information: DSA-1225 (Google Search)
http://www.debian.org/security/2006/dsa-1225
Debian Security Information: DSA-1227 (Google Search)
http://www.debian.org/security/2006/dsa-1227
http://secunia.com/advisories/23197
http://secunia.com/advisories/23202
http://secunia.com/advisories/23235
http://securityreason.com/securityalert/1444
Common Vulnerability Exposure (CVE) ID: CVE-2006-5462
1017180
http://securitytracker.com/id?1017180
1017181
http://securitytracker.com/id?1017181
1017182
http://securitytracker.com/id?1017182
102781
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102781-1
20061101-01-P
ftp://patches.sgi.com/support/free/security/advisories/20061101-01-P
22066
http://secunia.com/advisories/22066
22722
http://secunia.com/advisories/22722
22727
http://secunia.com/advisories/22727
22737
http://secunia.com/advisories/22737
22763
http://secunia.com/advisories/22763
22770
http://secunia.com/advisories/22770
22815
http://secunia.com/advisories/22815
22817
http://secunia.com/advisories/22817
22929
http://secunia.com/advisories/22929
22965
http://secunia.com/advisories/22965
22980
http://secunia.com/advisories/22980
23009
http://secunia.com/advisories/23009
23013
http://secunia.com/advisories/23013
23197
23202
23235
23263
http://secunia.com/advisories/23263
23287
http://secunia.com/advisories/23287
23297
http://secunia.com/advisories/23297
23883
http://secunia.com/advisories/23883
24711
http://secunia.com/advisories/24711
ADV-2006-3748
http://www.vupen.com/english/advisories/2006/3748
ADV-2006-4387
http://www.vupen.com/english/advisories/2006/4387
ADV-2007-0293
http://www.vupen.com/english/advisories/2007/0293
ADV-2007-1198
http://www.vupen.com/english/advisories/2007/1198
ADV-2008-0083
http://www.vupen.com/english/advisories/2008/0083
DSA-1224
DSA-1225
DSA-1227
GLSA-200612-06
http://security.gentoo.org/glsa/glsa-200612-06.xml
GLSA-200612-07
http://security.gentoo.org/glsa/glsa-200612-07.xml
GLSA-200612-08
http://security.gentoo.org/glsa/glsa-200612-08.xml
HPSBUX02153
http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00771742
MDKSA-2006:205
http://www.mandriva.com/security/advisories?name=MDKSA-2006:205
MDKSA-2006:206
http://www.mandriva.com/security/advisories?name=MDKSA-2006:206
RHSA-2006:0733
http://rhn.redhat.com/errata/RHSA-2006-0733.html
RHSA-2006:0734
http://rhn.redhat.com/errata/RHSA-2006-0734.html
RHSA-2006:0735
http://rhn.redhat.com/errata/RHSA-2006-0735.html
SSRT061181
SUSE-SA:2006:068
http://www.novell.com/linux/security/advisories/2006_68_mozilla.html
TA06-312A
http://www.us-cert.gov/cas/techalerts/TA06-312A.html
USN-381-1
http://www.ubuntu.com/usn/usn-381-1
USN-382-1
http://www.ubuntu.com/usn/usn-382-1
VU#335392
http://www.kb.cert.org/vuls/id/335392
http://support.avaya.com/elmodocs2/security/ASA-2006-246.htm
http://www.mozilla.org/security/announce/2006/mfsa2006-60.html
http://www.mozilla.org/security/announce/2006/mfsa2006-66.html
https://bugzilla.mozilla.org/show_bug.cgi?id=356215
mozilla-nss-security-bypass(30098)
https://exchange.xforce.ibmcloud.com/vulnerabilities/30098
oval:org.mitre.oval:def:10478
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10478
Common Vulnerability Exposure (CVE) ID: CVE-2006-5463
1017184
http://securitytracker.com/id?1017184
1017185
http://securitytracker.com/id?1017185
1017186
http://securitytracker.com/id?1017186
103011
http://sunsolve.sun.com/search/document.do?assetkey=1-26-103011-1
200185
http://sunsolve.sun.com/search/document.do?assetkey=1-66-200185-1
20061109 rPSA-2006-0206-1 firefox thunderbird
http://www.securityfocus.com/archive/1/451099/100/0/threaded
20957
http://www.securityfocus.com/bid/20957
22774
http://secunia.com/advisories/22774
ADV-2007-2663
http://www.vupen.com/english/advisories/2007/2663
VU#714496
http://www.kb.cert.org/vuls/id/714496
http://www.mozilla.org/security/announce/2006/mfsa2006-67.html
https://bugzilla.mozilla.org/show_bug.cgi?id=355655
https://issues.rpath.com/browse/RPL-765
mozilla-script-code-execution(30116)
https://exchange.xforce.ibmcloud.com/vulnerabilities/30116
oval:org.mitre.oval:def:10357
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10357
Common Vulnerability Exposure (CVE) ID: CVE-2006-5464
1017177
http://securitytracker.com/id?1017177
1017178
http://securitytracker.com/id?1017178
1017179
http://securitytracker.com/id?1017179
103121
http://sunsolve.sun.com/search/document.do?assetkey=1-26-103121-1
200587
http://sunsolve.sun.com/search/document.do?assetkey=1-66-200587-1
27328
http://secunia.com/advisories/27328
ADV-2007-3588
http://www.vupen.com/english/advisories/2007/3588
VU#495288
http://www.kb.cert.org/vuls/id/495288
http://www.mozilla.org/security/announce/2006/mfsa2006-65.html
https://bugzilla.mozilla.org/show_bug.cgi?id=307809
https://bugzilla.mozilla.org/show_bug.cgi?id=310267
https://bugzilla.mozilla.org/show_bug.cgi?id=350370
https://bugzilla.mozilla.org/show_bug.cgi?id=351328
mozilla-layout-dos(30092)
https://exchange.xforce.ibmcloud.com/vulnerabilities/30092
oval:org.mitre.oval:def:9304
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9304
Common Vulnerability Exposure (CVE) ID: CVE-2006-5748
BugTraq ID: 20957
Bugtraq: 20061109 rPSA-2006-0206-1 firefox thunderbird (Google Search)
Cert/CC Advisory: TA06-312A
CERT/CC vulnerability note: VU#390480
http://www.kb.cert.org/vuls/id/390480
HPdes Security Advisory: HPSBUX02153
HPdes Security Advisory: SSRT061181
https://bugzilla.mozilla.org/show_bug.cgi?id=349527
https://bugzilla.mozilla.org/show_bug.cgi?id=350238
https://bugzilla.mozilla.org/show_bug.cgi?id=351116
https://bugzilla.mozilla.org/show_bug.cgi?id=351973
https://bugzilla.mozilla.org/show_bug.cgi?id=352271
https://bugzilla.mozilla.org/show_bug.cgi?id=352606
https://bugzilla.mozilla.org/show_bug.cgi?id=353165
https://bugzilla.mozilla.org/show_bug.cgi?id=354145
https://bugzilla.mozilla.org/show_bug.cgi?id=354151
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11408
RedHat Security Advisories: RHSA-2006:0733
RedHat Security Advisories: RHSA-2006:0734
RedHat Security Advisories: RHSA-2006:0735
http://secunia.com/advisories/27603
SGI Security Advisory: 20061101-01-P
http://sunsolve.sun.com/search/document.do?assetkey=1-26-103139-1
http://sunsolve.sun.com/search/document.do?assetkey=1-66-201335-1
SuSE Security Announcement: SUSE-SA:2006:068 (Google Search)
http://www.vupen.com/english/advisories/2007/3821
XForce ISS Database: mozilla-javascript-engine-code-execution(30096)
https://exchange.xforce.ibmcloud.com/vulnerabilities/30096
CopyrightCopyright (C) 2008 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.