Gentoo Archives: gentoo-announce

From: Matthias Geerdsen <vorlon@g.o>
To: gentoo-announce@g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××××.uk, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200609-19 ] Mozilla Firefox: Multiple vulnerabilities
Date: Thu, 28 Sep 2006 19:46:19
Message-Id: 451C2089.5010506@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200609-19
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: Mozilla Firefox: Multiple vulnerabilities
9 Date: September 28, 2006
10 Bugs: #147652
11 ID: 200609-19
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 The Mozilla Foundation has reported numerous vulnerabilities in Mozilla
19 Firefox, including one that may allow execution of arbitrary code.
20
21 Background
22 ==========
23
24 Mozilla Firefox is a redesign of the Mozilla Navigator component. The
25 goal is to produce a cross-platform, stand-alone browser application.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 www-client/mozilla-firefox < 1.5.0.7 >= 1.5.0.7
34 2 www-client/mozilla-firefox-bin < 1.5.0.7 >= 1.5.0.7
35 -------------------------------------------------------------------
36 2 affected packages on all of their supported architectures.
37 -------------------------------------------------------------------
38
39 Description
40 ===========
41
42 A number of vulnerabilities were found and fixed in Mozilla Firefox.
43 For details please consult the references below.
44
45 Impact
46 ======
47
48 The most severe vulnerability involves enticing a user to visit a
49 malicious website, crashing the browser and executing arbitrary code
50 with the rights of the user running the application.
51
52 Workaround
53 ==========
54
55 There is no known workaround at this time.
56
57 Resolution
58 ==========
59
60 All Mozilla Firefox users should upgrade to the latest version:
61
62 # emerge --sync
63 # emerge --ask --oneshot --verbose
64 ">=www-client/mozilla-firefox-1.5.0.7"
65
66 Users of the binary package should upgrade as well:
67
68 # emerge --sync
69 # emerge --ask --oneshot --verbose
70 ">=www-client/mozilla-firefox-bin-1.5.0.7"
71
72 References
73 ==========
74
75 [ 1 ] CVE-2006-4253
76 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4253
77 [ 2 ] CVE-2006-4340
78 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4340
79 [ 3 ] CVE-2006-4565
80 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4565
81 [ 4 ] CVE-2006-4566
82 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4566
83 [ 5 ] CVE-2006-4567
84 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4567
85 [ 6 ] CVE-2006-4568
86 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4568
87 [ 7 ] CVE-2006-4569
88 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4569
89 [ 8 ] CVE-2006-4571
90 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4571
91
92 Availability
93 ============
94
95 This GLSA and any updates to it are available for viewing at
96 the Gentoo Security Website:
97
98 http://security.gentoo.org/glsa/glsa-200609-19.xml
99
100 Concerns?
101 =========
102
103 Security is a primary focus of Gentoo Linux and ensuring the
104 confidentiality and security of our users machines is of utmost
105 importance to us. Any security concerns should be addressed to
106 security@g.o or alternatively, you may file a bug at
107 http://bugs.gentoo.org.
108
109 License
110 =======
111
112 Copyright 2006 Gentoo Foundation, Inc; referenced text
113 belongs to its owner(s).
114
115 The contents of this document are licensed under the
116 Creative Commons - Attribution / Share Alike license.
117
118 http://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature