[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SA:2009:023 -- SUSE MozillaFirefox remote code execution

ID: oval:org.secpod.oval:def:400069Date: (C)2012-01-31   (M)2024-02-15
Class: PATCHFamily: unix




The Mozilla Firefox Browser was refreshed to the current MOZILLA_1_8 branch state around fix level 2.0.0.22, backporting various security fixes from the Firefox 3.0.8 browser version. Security issues identified as being fixed are: CVE-2009-0353: Mozilla developers identified and fixed several stability bugs in the browser engine used in Firefox and other Mozilla-based products. Some of these crashes showed evidence of memory corruption under certain circumstances and we presume that with enough effort at least some of these could be exploited to run arbitrary code. CVE-2009-0774: Mozilla developers identified and fixed several stability bugs in the browser engine used in Firefox and other Mozilla-based products. Some of these crashes showed evidence of memory corruption under certain circumstances and we presume that with enough effort at least some of these could be exploited to run arbitrary code. CVE-2009-0776: Mozilla security researcher Georgi Guninski reported that a website could use nsIRDFService and a cross-domain redirect to steal arbitrary XML data from another domain, a violation of the same-origin policy. This vulnerability could be used by a malicious website to steal private data from users authenticated to the redirected website. CVE-2009-0040: Google security researcher Tavis Ormandy reported several memory safety hazards to the libpng project, an external library used by Mozilla to render PNG images. These vulnerabilities could be used by a malicious website to crash a victim"s browser and potentially execute arbitrary code on their computer. libpng was upgraded to version 1.2.35 which contains fixes for these flaws. CVE-2009-1169: Security researcher Guido Landi discovered that a XSL stylesheet could be used to crash the browser during a XSL transformation. An attacker could potentially use this crash to run arbitrary code on a victim"s computer. This vulnerability was also previously reported as a stability problem by Ubuntu community member, Andre. Ubuntu community member Michael Rooney reported Andre"s findings to Mozilla, and Mozilla community member Martin helped reduce Andre"s original test case and contributed a patch to fix the vulnerability.

Platform:
openSUSE 10.3
Product:
MozillaFirefox
Reference:
SUSE-SA:2009:023
CVE-2009-0040
CVE-2009-0352
CVE-2009-0353
CVE-2009-0772
CVE-2009-0774
CVE-2009-0776
CVE-2009-1169
CVE    7
CVE-2009-0352
CVE-2009-1169
CVE-2009-0353
CVE-2009-0040
...
CPE    1
cpe:/o:opensuse:opensuse:10.3

© SecPod Technologies