It is currently Sat May 25, 2013 4:34 am

All times are UTC




Post new topic Reply to topic  [ 7 posts ] 
Author Message
 Post subject: [Fixed]iceweasel 3 < 3.0.5, multiple vulnerabilities
PostPosted: Wed Dec 17, 2008 4:29 am 
Master of the known universe
Master of the known universe
User avatar

Joined: Thu Mar 29, 2007 2:34 am
Posts: 1253
Location: Taiwan
SANS internet storm center wrote:
FireFox 3.0.5 has been released with several security fixes.

Fixed in Firefox 3.0.5
MFSA 2008-69 XSS vulnerabilities in SessionStore
MFSA 2008-68 XSS and JavaScript privilege escalation
MFSA 2008-67 Escaped null characters ignored by CSS parser
MFSA 2008-66 Errors parsing URLs with leading whitespace and control characters
MFSA 2008-65 Cross-domain data theft via script redirect error message
MFSA 2008-64 XMLHttpRequest 302 response disclosure
MFSA 2008-63 User tracking via XUL persist attribute
MFSA 2008-60 Crashes with evidence of memory corruption (rv:1.9.0.5/1.8.1.19)

Thanks to John and Roseman for bringing this to our attention.


For more info please check:
http://www.mozilla.org/security/known-v ... refox3.0.5

!8! !8! !8!


Last edited by infwonder on Thu Dec 25, 2008 1:20 am, edited 1 time in total.

 Profile Send private message  
 
 Post subject: Re: iceweasel 3 < 3.0.5, multiple vulnerabilities
PostPosted: Wed Dec 17, 2008 9:33 am 
Global Moderator
Global Moderator
User avatar

Joined: Mon Apr 10, 2006 12:43 pm
Posts: 4727
Location: Ath (Belgium)
The package is not yet in the repo l!!!
So it is maybe better to stay in 3.0.4


Bip


 Profile Send private message  
 
 Post subject: Re: iceweasel 3 < 3.0.5, multiple vulnerabilities
PostPosted: Wed Dec 17, 2008 10:23 am 
Master of the known universe
Master of the known universe
User avatar

Joined: Thu Mar 29, 2007 2:34 am
Posts: 1253
Location: Taiwan
As always, all mozilla replated products need to be updated ...

Thunderbird (icedove): 2.0.0.19
SeaMonkey: 1.1.4


bipbip:
I am not sure what you meant to tell. :-\


 Profile Send private message  
 
 Post subject: Re: iceweasel 3 < 3.0.5, multiple vulnerabilities
PostPosted: Wed Dec 17, 2008 10:39 am 
Global Moderator
Global Moderator
User avatar

Joined: Mon Apr 10, 2006 12:43 pm
Posts: 4727
Location: Ath (Belgium)
oups sorry forget my answer :-[


 Profile Send private message  
 
 Post subject: Re: iceweasel 3 < 3.0.5, multiple vulnerabilities
PostPosted: Wed Dec 17, 2008 10:24 pm 

Seamonkey 1.1.14 is in FIFO.


  
 
 Post subject: Re: iceweasel 3 < 3.0.5, multiple vulnerabilities
PostPosted: Sat Dec 20, 2008 7:59 am 
Master of the known universe
Master of the known universe
User avatar

Joined: Thu Mar 29, 2007 2:34 am
Posts: 1253
Location: Taiwan
Oh! I forgot to mention that these vulnerabilities also affect xulrunner, which should be updated to 1.9.0.5.


 Profile Send private message  
 
 Post subject: Re: iceweasel 3 < 3.0.5, multiple vulnerabilities
PostPosted: Wed Dec 31, 2008 5:12 am 
Master of the known universe
Master of the known universe
User avatar

Joined: Thu Mar 29, 2007 2:34 am
Posts: 1253
Location: Taiwan
infwonder wrote:
As always, all mozilla replated products need to be updated ...

Thunderbird (icedove): 2.0.0.19
...



It's (finally) released today! :)


 Profile Send private message  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 7 posts ] 

All times are UTC


 Who is online

Users browsing this forum: No registered users and 3 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to: