Описание
ELSA-2009-0449: firefox security update (CRITICAL)
firefox:
[3.0.10-1.0.1.el5]
- Update firstrun and homepage URLs
- Added firefox-oracle-default-prefs.js/firefox-oracle-default-bookmarks.html and removed the corresponding Red Hat ones
- Added patch oracle-firefox-branding.patch
[3.0.10-1]
- Update to 3.0.10
xulrunner:
[1.9.0.10-1.0.1.el5]
- Added xulrunner-oracle-default-prefs.js and removed the corresponding RedHat one
[1.9.0.10-1]
- Update to 1.9.0.10
Обновленные пакеты
Oracle Linux 5
Oracle Linux x86_64
firefox
3.0.10-1.0.1.el5
xulrunner
1.9.0.10-1.0.1.el5
xulrunner-devel
1.9.0.10-1.0.1.el5
xulrunner-devel-unstable
1.9.0.10-1.0.1.el5
Oracle Linux i386
firefox
3.0.10-1.0.1.el5
xulrunner
1.9.0.10-1.0.1.el5
xulrunner-devel
1.9.0.10-1.0.1.el5
xulrunner-devel-unstable
1.9.0.10-1.0.1.el5
Связанные CVE
Связанные уязвимости
The nsTextFrame::ClearTextRun function in layout/generic/nsTextFrameThebes.cpp in Mozilla Firefox 3.0.9 allows remote attackers to cause a denial of service (memory corruption) and probably execute arbitrary code via unspecified vectors. NOTE: this vulnerability reportedly exists because of an incorrect fix for CVE-2009-1302.
The nsTextFrame::ClearTextRun function in layout/generic/nsTextFrameThebes.cpp in Mozilla Firefox 3.0.9 allows remote attackers to cause a denial of service (memory corruption) and probably execute arbitrary code via unspecified vectors. NOTE: this vulnerability reportedly exists because of an incorrect fix for CVE-2009-1302.
The nsTextFrame::ClearTextRun function in layout/generic/nsTextFrameThebes.cpp in Mozilla Firefox 3.0.9 allows remote attackers to cause a denial of service (memory corruption) and probably execute arbitrary code via unspecified vectors. NOTE: this vulnerability reportedly exists because of an incorrect fix for CVE-2009-1302.
The nsTextFrame::ClearTextRun function in layout/generic/nsTextFrameTh ...
The nsTextFrame::ClearTextRun function in layout/generic/nsTextFrameThebes.cpp in Mozilla Firefox 3.0.9 allows remote attackers to cause a denial of service (memory corruption) and probably execute arbitrary code via unspecified vectors. NOTE: this vulnerability reportedly exists because of an incorrect fix for CVE-2009-1302.