96 lines
4 KiB
XML
96 lines
4 KiB
XML
|
<?xml version="1.0" encoding="utf-8"?>
|
||
|
<?xml-stylesheet href="/xsl/glsa.xsl" type="text/xsl"?>
|
||
|
<?xml-stylesheet href="/xsl/guide.xsl" type="text/xsl"?>
|
||
|
<!DOCTYPE glsa SYSTEM "http://www.gentoo.org/dtd/glsa.dtd">
|
||
|
|
||
|
<glsa id="200606-12">
|
||
|
<title>Mozilla Firefox: Multiple vulnerabilities</title>
|
||
|
<synopsis>
|
||
|
Vulnerabilities in Mozilla Firefox allow privilege escalations for
|
||
|
JavaScript code, cross site scripting attacks, HTTP response smuggling and
|
||
|
possibly the execution of arbitrary code.
|
||
|
</synopsis>
|
||
|
<product type="ebuild">mozilla-firefox</product>
|
||
|
<announced>June 11, 2006</announced>
|
||
|
<revised>June 11, 2006: 01</revised>
|
||
|
<bug>135254</bug>
|
||
|
<access>remote</access>
|
||
|
<affected>
|
||
|
<package name="www-client/mozilla-firefox" auto="yes" arch="*">
|
||
|
<unaffected range="ge">1.5.0.4</unaffected>
|
||
|
<vulnerable range="lt">1.5.0.4</vulnerable>
|
||
|
</package>
|
||
|
<package name="www-client/mozilla-firefox-bin" auto="yes" arch="*">
|
||
|
<unaffected range="ge">1.5.0.4</unaffected>
|
||
|
<vulnerable range="lt">1.5.0.4</vulnerable>
|
||
|
</package>
|
||
|
</affected>
|
||
|
<background>
|
||
|
<p>
|
||
|
Mozilla Firefox is the next-generation web browser from the
|
||
|
Mozilla project.
|
||
|
</p>
|
||
|
</background>
|
||
|
<description>
|
||
|
<p>
|
||
|
A number of vulnerabilities were found and fixed in Mozilla
|
||
|
Firefox. For details please consult the references below.
|
||
|
</p>
|
||
|
</description>
|
||
|
<impact type="normal">
|
||
|
<p>
|
||
|
By enticing the user to visit a malicious website, a remote
|
||
|
attacker can inject arbitrary HTML and JavaScript Code into the user's
|
||
|
browser, execute JavaScript code with elevated privileges and possibly
|
||
|
execute arbitrary code with the permissions of the user running the
|
||
|
application.
|
||
|
</p>
|
||
|
</impact>
|
||
|
<workaround>
|
||
|
<p>
|
||
|
There is no known workaround at this time.
|
||
|
</p>
|
||
|
</workaround>
|
||
|
<resolution>
|
||
|
<p>
|
||
|
All Mozilla Firefox users should upgrade to the latest version:
|
||
|
</p>
|
||
|
<code>
|
||
|
# emerge --sync
|
||
|
# emerge --ask --oneshot --verbose ">=www-client/mozilla-firefox-1.5.0.4"</code>
|
||
|
<p>
|
||
|
All Mozilla Firefox binary users should upgrade to the latest
|
||
|
version:
|
||
|
</p>
|
||
|
<code>
|
||
|
# emerge --sync
|
||
|
# emerge --ask --oneshot --verbose ">=www-client/mozilla-firefox-bin-1.5.0.4"</code>
|
||
|
<p>
|
||
|
Note: There is no stable fixed version for the Alpha
|
||
|
architecture yet. Users of Mozilla Firefox on Alpha should consider
|
||
|
unmerging it until such a version is available.
|
||
|
</p>
|
||
|
</resolution>
|
||
|
<references>
|
||
|
<uri link="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2775">CVE-2006-2775</uri>
|
||
|
<uri link="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2776">CVE-2006-2776</uri>
|
||
|
<uri link="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2777">CVE-2006-2777</uri>
|
||
|
<uri link="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2778">CVE-2006-2778</uri>
|
||
|
<uri link="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2779">CVE-2006-2779</uri>
|
||
|
<uri link="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2780">CVE-2006-2780</uri>
|
||
|
<uri link="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2782">CVE-2006-2782</uri>
|
||
|
<uri link="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2783">CVE-2006-2783</uri>
|
||
|
<uri link="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2784">CVE-2006-2784</uri>
|
||
|
<uri link="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2785">CVE-2006-2785</uri>
|
||
|
<uri link="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2786">CVE-2006-2786</uri>
|
||
|
<uri link="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2787">CVE-2006-2787</uri>
|
||
|
<uri link="http://www.mozilla.org/projects/security/known-vulnerabilities.html#Firefox">Mozilla Foundation Security Advisories</uri>
|
||
|
</references>
|
||
|
<metadata tag="submitter" timestamp="Wed, 07 Jun 2006 17:33:16 +0000">
|
||
|
frilled
|
||
|
</metadata>
|
||
|
<metadata tag="bugReady" timestamp="Thu, 08 Jun 2006 10:36:32 +0000">
|
||
|
falco
|
||
|
</metadata>
|
||
|
</glsa>
|