Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.880689
Category:CentOS Local Security Checks
Title:CentOS Update for firefox CESA-2009:0449 centos5 i386
Summary:The remote host is missing an update for the 'firefox'; package(s) announced via the referenced advisory.
Description:Summary:
The remote host is missing an update for the 'firefox'
package(s) announced via the referenced advisory.

Vulnerability Insight:
Mozilla Firefox is an open source Web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

A flaw was found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code as the user running Firefox.
(CVE-2009-1313)

For technical details regarding this flaw, refer to the Mozilla security
advisory for Firefox 3.0.10. You can find a link to the Mozilla advisories
in the References section of this errata.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 3.0.10, which corrects this issue. After installing the
update, Firefox must be restarted for the change to take effect.

Affected Software/OS:
firefox on CentOS 5

Solution:
Please install the updated packages.

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2009-1313
1022126
http://securitytracker.com/id?1022126
1022127
http://securitytracker.com/id?1022127
34743
http://www.securityfocus.com/bid/34743
34851
http://secunia.com/advisories/34851
34866
http://secunia.com/advisories/34866
34910
http://secunia.com/advisories/34910
34919
http://secunia.com/advisories/34919
ADV-2009-1180
http://www.vupen.com/english/advisories/2009/1180
MDVSA-2009:111
http://www.mandriva.com/security/advisories?name=MDVSA-2009:111
RHSA-2009:0449
https://rhn.redhat.com/errata/RHSA-2009-0449.html
SSA:2009-118-01
http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.350967
USN-765-1
http://www.ubuntu.com/usn/USN-765-1
http://www.mozilla.org/security/announce/2009/mfsa2009-23.html
https://bugzilla.mozilla.org/show_bug.cgi?id=489647
https://bugzilla.mozilla.org/show_bug.cgi?id=489676
https://bugzilla.mozilla.org/show_bug.cgi?id=490233
https://bugzilla.redhat.com/show_bug.cgi?id=497447
oval:org.mitre.oval:def:10446
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10446
CopyrightCopyright (C) 2011 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.