| PROBLEM: | Mozilla Firefox, a popular open source Web browser, has released an update that fixes several security vulnerabilities. |
| SOFTWARE: | Mozilla Firefox 0.x, Mozilla Firefox 1.x |
| PLATFORM: | Red Hat Desktop (v. 3) & (v. 4) Red Hat Enterprise Linux AS (v. 2.1, 3, 4) Red Hat Enterprise Linux ES (v. 2.1, 3, 4) Red Hat Enterprise Linux WS (v. 2.1, 3, 4) Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor SGI ProPack 3 Service Pack 5 for SGI Altix family of systems HP-UX B.11.00, B.11.11, B.11.22, B.11.23 running Mozilla versions prior to 1.7.8.00 |
| DAMAGE: | The effects of exploiting the ten security flaws that were fixed with this update include: cross-site scripting attacks, bypassing security restrictions, and possible system compromise. |
| SOLUTION: | Apply available security updates. |
| VULNERABILITY ASSESSMENT: |
The risk is MEDIUM. Exploiting the vulnerabilities may result in cross-site scripting attacks, bypassing security restrictions, and possible system compromise. |
REVISION HISTORY:
04/29/2005 - revised to add a link to Red Hat Security Advisory
RHSA-2005:384-11.
05/09/2005 - revised to add a link to SGI Security Advisory 20050501-01-U.
07/22/2005 - revised to add a link to Red Hat RHSA-2005:601-07 for Red Had
Desktop (v. 4) & Red Hat Enterprise Linux AS, ES, WS (v. 4).
08/10/2005 - revised to add a link to Hewlett-Packard HPSBUX01133 SSRT5940
rev. 1 for HP-UX B.11.00, B.11.11, B.11.22, B.11.23 running
Mozilla versions prior to 1.7.8.00.
08/24/2005 - revised to add a link to Debian Security Advisory DSA-781-1 mozilla-
thunderbird -- several vulnerabilities
[***** Start Red Hat Security Advisory RHSA-2005:383-07 *****]
Important: firefox security update
DetailsUpdated firefox packages that fix various security bugs are now available. Mozilla Firefox is an open source Web browser. SolutionBefore applying this update, make sure that all previously-released
errata relevant to your system have been applied. Use Red Hat Network to download and update your packages. To launch the Red Hat Update Agent, use the following command: up2date For information on how to install packages manually, refer to the following Web page for the System Administration or Customization guide specific to your system: http://www.redhat.com/docs/manuals/enterprise/ Updated packages
Bugs fixed (see bugzilla for more information)155114 - CAN-2005-0752 Multiple firefox issues. (CAN-2005-0989) References
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0752
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0989 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-1153 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-1154 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-1155 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-1156 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-1157 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-1158 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-1159 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-1160 http://www.mozilla.org/projects/security/known-vulnerabilities.html These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from: https://www.redhat.com/security/team/key/#package The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/ |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Voice: +1 925-422-8193 (7 x 24)
FAX: +1 925-423-8002
STU-III: +1 925-423-2604
E-mail: ciac@ciac.org
World Wide Web: http://www.ciac.org/
Anonymous FTP: ftp.ciac.org