Description: | Description:
The remote host is missing an update to chmsee announced via advisory FEDORA-2008-2662.
A gtk2 chm document viewer.
It uses chmlib to extract files. It uses gecko to display pages. It supports displaying multilingual pages due to gecko. It features bookmarks and tabs. The tabs could be used to jump inside the chm file conveniently. Its UI is clean and handy, also is well localized. It is actively developed and maintained. The author of chmsee is Jungle Ji and several other great people.
Update Information:
Mozilla Firefox is an open source Web browser. Several flaws were found in the processing of some malformed web content. A web page containing such malicious content could cause Firefox to crash or, potentially, execute arbitrary code as the user running Firefox. (CVE-2008-1233, CVE-2008-1235, CVE-2008-1236, CVE-2008-1237) Several flaws were found in the display of malformed web content. A web page containing specially-crafted content could, potentially, trick a Firefox user into surrendering sensitive information. (CVE-2008-1234, CVE-2008-1238, CVE-2008-1241) All Firefox users should upgrade to these updated packages, which correct these issues, and are rebuilt against the update Firefox packages. ChangeLog:
* Tue Mar 25 2008 Christopher Aillon 1.0.0-1.30 - Rebuild against newer gecko * Tue Mar 4 2008 bbbush - 1.0.0-1.29 - re-add firefox_version * Fri Feb 8 2008 Christopher Aillon - 1.0.0-1.28 - Rebuild against newer gecko References:
[ 1 ] Bug #438715 - CVE-2008-1234 universal XSS using event handlers https://bugzilla.redhat.com/show_bug.cgi?id=438715 [ 2 ] Bug #438713 - CVE-2008-1233 Mozilla products XPCNativeWrapper pollution https://bugzilla.redhat.com/show_bug.cgi?id=438713 [ 3 ] Bug #438718 - CVE-2008-1236 browser engine crashes https://bugzilla.redhat.com/show_bug.cgi?id=438718 [ 4 ] Bug #438724 - CVE-2008-1238 Referrer spoofing bug https://bugzilla.redhat.com/show_bug.cgi?id=438724 [ 5 ] Bug #438721 - CVE-2008-1237 javascript crashes https://bugzilla.redhat.com/show_bug.cgi?id=438721 [ 6 ] Bug #438730 - CVE-2008-1241 XUL popup spoofing https://bugzilla.redhat.com/show_bug.cgi?id=438730 [ 7 ] Bug #438717 - CVE-2008-1235 chrome privilege via wrong principal https://bugzilla.redhat.com/show_bug.cgi?id=438717
Solution: Apply the appropriate updates.
This update can be installed with the yum update program. Use su -c 'yum update chmsee' at the command line. For more information, refer to Managing Software with yum, available at http://docs.fedoraproject.org/yum/.
Hint * Unlike other chm viewers, chmsee extracts files from chm file, and then read and display them. The extracted files could be found in $HOME/.chmsee/bookshelf directory. You can clean those files at any time and there is a special config option for that. * The bookmark is related to each file so not all bookmarks will be loaded, only current file's. * Try to remove $HOME/.chmsee if you encounter any problem after an upgrade.
http://www.securityspace.com/smysecure/catid.html?in=FEDORA-2008-2662
Risk factor : Critical
CVSS Score: 9.3
|