Gentoo Archives: gentoo-announce

From: Sune Kloppenborg Jeppesen <jaervosz@g.o>
To: gentoo-announce@l.g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××.com, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] UPDATE: [ GLSA 200408-22 ] Mozilla, Firefox, Thunderbird, Galeon, Epiphany: New releases fix vulnerabilities
Date: Fri, 03 Sep 2004 09:46:16
Message-Id: 200409031139.19204.jaervosz@gentoo.org
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
5 Gentoo Linux Security Advisory GLSA 200408-22
6 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
7 http://security.gentoo.org/
8 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
9
10 Severity: Normal
11 Title: Mozilla, Firefox, Thunderbird, Galeon, Epiphany: New
12 releases fix vulnerabilities
13 Date: August 23, 2004
14 Bugs: #57380, #59419
15 ID: 200408-22
16
17 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
18
19 Synopsis
20 ========
21
22 New releases of Mozilla, Epiphany, Galeon, Mozilla Thunderbird, and
23 Mozilla Firefox fix several vulnerabilities, including remote DoS and
24 buffer overflows.
25
26 Background
27 ==========
28
29 Mozilla is a popular web browser that includes a mail and newsreader.
30 Galeon and Epiphany are both web browsers that use gecko, the Mozilla
31 rendering engine. Mozilla Firefox is the next-generation browser from
32 the Mozilla project that incorporates advanced features that are yet to
33 be incorporated into Mozilla. Mozilla Thunderbird is the
34 next-generation mail client from the Mozilla project.
35
36 Affected packages
37 =================
38
39 -------------------------------------------------------------------
40 Package / Vulnerable / Unaffected
41 -------------------------------------------------------------------
42 1 mozilla < 1.7.2 >= 1.7.2
43 2 mozilla-firefox < 0.9.3 >= 0.9.3
44 3 mozilla-thunderbird < 0.7.3 >= 0.7.3
45 4 mozilla-bin < 1.7.2 >= 1.7.2
46 5 mozilla-firefox-bin < 0.9.3 >= 0.9.3
47 6 mozilla-thunderbird-bin < 0.7.3 >= 0.7.3
48 7 epiphany < 1.2.7-r1 >= 1.2.7-r1
49 8 galeon < 1.3.17 >= 1.3.17
50 -------------------------------------------------------------------
51 8 affected packages on all of their supported architectures.
52 -------------------------------------------------------------------
53
54 Description
55 ===========
56
57 Mozilla, Galeon, Epiphany, Mozilla Firefox and Mozilla Thunderbird
58 contain the following vulnerabilities:
59
60 * All Mozilla tools use libpng for graphics. This library contains a
61 buffer overflow which may lead to arbitrary code execution.
62
63 * If a user imports a forged Certificate Authority (CA) certificate,
64 it may overwrite and corrupt the valid CA already installed on the
65 machine.
66
67 Mozilla, Mozilla Firefox, and other gecko-based browsers also contain a
68 bug in their caching which may allow the SSL icon to remain visible,
69 even when the site in question is an insecure site.
70
71 Impact
72 ======
73
74 Users of Mozilla, Mozilla Firefox, and other gecko-based browsers are
75 susceptible to SSL certificate spoofing, a Denial of Service against
76 legitimate SSL sites, crashes, and arbitrary code execution. Users of
77 Mozilla Thunderbird are susceptible to crashes and arbitrary code
78 execution via malicious e-mails.
79
80 Workaround
81 ==========
82
83 There is no known workaround for most of these vulnerabilities. All
84 users are advised to upgrade to the latest available version.
85
86 Resolution
87 ==========
88
89 All users should upgrade to the latest stable version:
90
91 # emerge sync
92
93 # emerge -pv your-version
94 # emerge your-version
95
96 References
97 ==========
98
99 [ 1 ] CAN-2004-0763
100 http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0763
101 [ 2 ] CAN-2004-0758
102 http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0758
103 [ 3 ] CAN-2004-0597
104 http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0597
105 [ 4 ] CAN-2004-0598
106 http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0598
107 [ 5 ] CAN-2004-0599
108 http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0599
109
110 Availability
111 ============
112
113 This GLSA and any updates to it are available for viewing at
114 the Gentoo Security Website:
115
116 http://security.gentoo.org/glsa/glsa-200408-22.xml
117
118 Concerns?
119 =========
120
121 Security is a primary focus of Gentoo Linux and ensuring the
122 confidentiality and security of our users machines is of utmost
123 importance to us. Any security concerns should be addressed to
124 security@g.o or alternatively, you may file a bug at
125 http://bugs.gentoo.org.
126
127 License
128 =======
129
130 Copyright 2004 Gentoo Foundation, Inc; referenced text
131 belongs to its owner(s).
132
133 The contents of this document are licensed under the
134 Creative Commons - Attribution / Share Alike license.
135
136 http://creativecommons.org/licenses/by-sa/1.0
137 -----BEGIN PGP SIGNATURE-----
138 Version: GnuPG v1.2.4 (GNU/Linux)
139
140 iD8DBQFBODukzKC5hMHO6rkRAhL8AJ4/Sv7xDRUIUyb/vJWqoAJK0Ft2QQCdHo3z
141 ybxN9FXECqEJjWceB6uLR9M=
142 =YKBA
143 -----END PGP SIGNATURE-----