[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CESA-2015:1982 -- centos 5 firefox

ID: oval:org.secpod.oval:def:203764Date: (C)2015-11-13   (M)2024-01-29
Class: PATCHFamily: unix




Mozilla Firefox is an open source web browser. XULRunner provides the XUL Runtime environment for Mozilla Firefox. Several flaws were found in the processing of malformed web content. A web page containing malicious content could cause Firefox to crash or, potentially, execute arbitrary code with the privileges of the user running Firefox. A same-origin policy bypass flaw was found in the way Firefox handled certain cross-origin resource sharing requests. A web page containing malicious content could cause Firefox to disclose sensitive information. A same-origin policy bypass flaw was found in the way Firefox handled URLs containing IP addresses with white-space characters. This could lead to cross-site scripting attacks. Red Hat would like to thank the Mozilla project for reporting these issues. Upstream acknowledges Christian Holler, David Major, Jesse Ruderman, Tyson Smith, Boris Zbarsky, Randell Jesup, Olli Pettay, Karl Tomlinson, Jeff Walden, and Gary Kwong, Micha Bentkowski, Looben Yang, Shinto K Anto, Gustavo Grieco, Vytautas Staraitis, Ronald Crane, and Ehsan Akhgari as the original reporters of these issues. All Firefox users should upgrade to these updated packages, which contain Firefox version 38.4.0 ESR, which corrects these issues. After installing the update, Firefox must be restarted for the changes to take effect.

Platform:
CentOS 5
Product:
firefox
Reference:
CESA-2015:1982
CVE-2015-7200
CVE-2015-7199
CVE-2015-7197
CVE-2015-7193
CVE-2015-7188
CVE-2015-4513
CVE-2015-7194
CVE-2015-7196
CVE-2015-7198
CVE-2015-7189
CVE    10
CVE-2015-4513
CVE-2015-7194
CVE-2015-7193
CVE-2015-7196
...
CPE    3
cpe:/a:mozilla:firefox:41.0.2
cpe:/o:centos:centos:5
cpe:/a:mozilla:firefox

© SecPod Technologies