Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.64871
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-1886-1)
Summary:The remote host is missing an update for the Debian 'iceweasel' package(s) announced via the DSA-1886-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'iceweasel' package(s) announced via the DSA-1886-1 advisory.

Vulnerability Insight:
Several remote vulnerabilities have been discovered in the Iceweasel web browser, an unbranded version of the Firefox browser. The Common Vulnerabilities and Exposures project identifies the following problems:

CVE-2009-3079

'moz_bug_r_a4' discovered that a programming error in the FeedWriter module could lead to the execution of Javascript code with elevated privileges.

CVE-2009-1310

Prateek Saxena discovered a cross-site scripting vulnerability in the MozSearch plugin interface.

For the stable distribution (lenny), these problems have been fixed in version 3.0.6-3.

As indicated in the Etch release notes, security support for the Mozilla products in the oldstable distribution needed to be stopped before the end of the regular Etch security maintenance life cycle. You are strongly encouraged to upgrade to stable or switch to a still supported browser.

For the unstable distribution (sid), these problems have been fixed in version 3.0.14-1.

For the experimental distribution, these problems have been fixed in version 3.5.3-1.

We recommend that you upgrade your iceweasel packages.

Affected Software/OS:
'iceweasel' package(s) on Debian 5.

Solution:
Please install the updated package(s).

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2009-1310
1022097
http://www.securitytracker.com/id?1022097
264308
http://sunsolve.sun.com/search/document.do?assetkey=1-66-264308-1
34656
http://www.securityfocus.com/bid/34656
34758
http://secunia.com/advisories/34758
34843
http://secunia.com/advisories/34843
34894
http://secunia.com/advisories/34894
35065
http://secunia.com/advisories/35065
36757
http://secunia.com/advisories/36757
ADV-2009-1125
http://www.vupen.com/english/advisories/2009/1125
DSA-1886
http://www.debian.org/security/2009/dsa-1886
FEDORA-2009-3875
https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00683.html
MDVSA-2009:111
http://www.mandriva.com/security/advisories?name=MDVSA-2009:111
RHSA-2009:0436
http://www.redhat.com/support/errata/RHSA-2009-0436.html
SUSE-SR:2009:010
http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html
USN-764-1
https://usn.ubuntu.com/764-1/
http://www.mozilla.org/security/announce/2009/mfsa2009-20.html
https://bugzilla.mozilla.org/show_bug.cgi?id=483086
oval:org.mitre.oval:def:11520
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11520
oval:org.mitre.oval:def:6242
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6242
Common Vulnerability Exposure (CVE) ID: CVE-2009-3079
1022873
http://www.securitytracker.com/id?1022873
36343
http://www.securityfocus.com/bid/36343
36670
http://secunia.com/advisories/36670
36671
http://secunia.com/advisories/36671
37098
http://secunia.com/advisories/37098
RHSA-2009:1430
http://www.redhat.com/support/errata/RHSA-2009-1430.html
SUSE-SA:2009:048
http://www.novell.com/linux/security/advisories/2009_48_firefox.html
http://www.mozilla.org/security/announce/2009/mfsa2009-51.html
https://bugzilla.mozilla.org/show_bug.cgi?id=454363
oval:org.mitre.oval:def:10390
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10390
oval:org.mitre.oval:def:6250
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6250
CopyrightCopyright (C) 2009 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.