Description: | Description:
The remote host is missing an update to xulrunner announced via advisory FEDORA-2008-6518.
XULRunner provides the XUL Runtime environment for Gecko applications.
Update Information:
Updated firefox packages that fix several security issues are now available for Fedora 9. An integer overflow flaw was found in the way Firefox displayed certain web content. A malicious web site could cause Firefox to crash, or execute arbitrary code with the permissions of the user running Firefox. (CVE-2008-2785) A flaw was found in the way Firefox handled certain command line URLs. If another application passed Firefox a malformed URL, it could result in Firefox executing local malicious content with chrome privileges. (CVE-2008-2933) Updated packages update Mozilla Firefox to upstream version 3.0.1 to address these flaws: http://www.mozilla.org/security/known- vulnerabilities/firefox30.html#firefox3.0.1 This update also contains devhelp, epiphany, epiphany-extensions, and yelp packages rebuilt against new Firefox / Gecko libraries. ChangeLog:
* Wed Jul 16 2008 Christopher Aillon 1.9.0.1-1 - Update to 1.9.0.1 * Mon Jun 30 2008 Dennis Gilmore 1.9-1.1 - handle sparc arches
References:
[ 1 ] Bug #452204 - CVE-2008-2785 mozilla: CSS reference counter overflow (ZDI-CAN-349) https://bugzilla.redhat.com/show_bug.cgi?id=452204 [ 2 ] Bug #454697 - CVE-2008-2933 Firefox command line URL launches multi-tabs https://bugzilla.redhat.com/show_bug.cgi?id=454697
Solution: Apply the appropriate updates.
This update can be installed with the yum update program. Use su -c 'yum update xulrunner' at the command line. For more information, refer to Managing Software with yum, available at http://docs.fedoraproject.org/yum/.
http://www.securityspace.com/smysecure/catid.html?in=FEDORA-2008-6518
Risk factor : Critical
CVSS Score: 9.3
|