Описание
ELSA-2010-0501: firefox security, bug fix, and enhancement update (CRITICAL)
devhelp:
[0.12-21]
- Rebuild against xulrunner
esc:
[1.1.0-12]
- Rebuild for xulrunner update
firefox:
[3.6.4-8.0.1.el5]
- Add firefox-oracle-default-prefs.js and firefox-oracle-default-bookmarks.html and remove the corresponding Red Hat ones
[3.6.4-8]
- Fixing NVR
[3.6.4-7]
- Update to 3.6.4 build7
- Disable checking for updates since they can't be applied
[3.6.4-6]
- Update to 3.6.4 build6
[3.6.4-5]
- Update to 3.6.4 build5
[3.6.4-4]
- Update to 3.6.4 build4
[3.6.4-3]
- Update to 3.6.4 build 3
[3.6.4-2]
- Update to 3.6.4 build 2
[3.6.4-1]
- Update to 3.6.4
[3.6.3-3]
- Fixed language packs (#581392)
[3.6.3-2]
- Fixed multilib conflict
[3.6.3-1]
- Rebase to 3.6.3
gnome-python2-extras:
[2.14.2-7]
- rebuild agains xulrunner
totem:
[2.16.7-7]
- rebuild against new xulrunner
xulrunner:
[1.9.2.4-9.0.1]
- Added xulrunner-oracle-default-prefs.js and removed the corresponding RedHat one.
[1.9.2.4-9]
- Update to 1.9.2.4 build 7
[1.9.2.4-8]
- Update to 1.9.2.4 build 6
[1.9.2.4-7]
- Update to 1.9.2.4 build 5
[1.9.2.4-6]
- Update to 1.9.2.4 build 4
- Fixed mozbz#546270 patch
[1.9.2.4-5]
- Update to 1.9.2.4 build 3
[1.9.2.4-4]
- Update to 1.9.2.4 build 2
- Enabled oopp
[1.9.2.4-3]
- Disabled libnotify
[1.9.2.4-2]
- Disabled oopp, causes TEXTREL
[1.9.2.4-1]
- Update to 1.9.2.4
[1.9.2.3-3]
- fixed js-config.h multilib conflict
- fixed file list
[1.9.2.3-2]
- Added fix for rhbz#555760 - Firefox Javascript anomily, landscape print orientation reverts to portrait (mozbz#546270)
[1.9.2.3-1]
- Update to 1.9.2.3
[1.9.2.2-1]
- Rebase to 1.9.2.2
yelp:
[2.16.0-26]
- rebuild against xulrunner
[2.16.0-25]
- rebuild against xulrunner
- added xulrunner fix
- added -fno-strict-aliasing to build flags
Обновленные пакеты
Oracle Linux 5
Oracle Linux ia64
devhelp
0.12-21.el5
devhelp-devel
0.12-21.el5
esc
1.1.0-12.el5
firefox
3.6.4-8.0.1.el5
gnome-python2-extras
2.14.2-7.el5
gnome-python2-gtkhtml2
2.14.2-7.el5
gnome-python2-gtkmozembed
2.14.2-7.el5
gnome-python2-gtkspell
2.14.2-7.el5
gnome-python2-libegg
2.14.2-7.el5
totem
2.16.7-7.el5
totem-devel
2.16.7-7.el5
totem-mozplugin
2.16.7-7.el5
xulrunner
1.9.2.4-9.0.1.el5
xulrunner-devel
1.9.2.4-9.0.1.el5
yelp
2.16.0-26.el5
Oracle Linux x86_64
devhelp
0.12-21.el5
devhelp-devel
0.12-21.el5
esc
1.1.0-12.el5
firefox
3.6.4-8.0.1.el5
gnome-python2-extras
2.14.2-7.el5
gnome-python2-gtkhtml2
2.14.2-7.el5
gnome-python2-gtkmozembed
2.14.2-7.el5
gnome-python2-gtkspell
2.14.2-7.el5
gnome-python2-libegg
2.14.2-7.el5
totem
2.16.7-7.el5
totem-devel
2.16.7-7.el5
totem-mozplugin
2.16.7-7.el5
xulrunner
1.9.2.4-9.0.1.el5
xulrunner-devel
1.9.2.4-9.0.1.el5
yelp
2.16.0-26.el5
Oracle Linux i386
devhelp
0.12-21.el5
devhelp-devel
0.12-21.el5
esc
1.1.0-12.el5
firefox
3.6.4-8.0.1.el5
gnome-python2-extras
2.14.2-7.el5
gnome-python2-gtkhtml2
2.14.2-7.el5
gnome-python2-gtkmozembed
2.14.2-7.el5
gnome-python2-gtkspell
2.14.2-7.el5
gnome-python2-libegg
2.14.2-7.el5
totem
2.16.7-7.el5
totem-devel
2.16.7-7.el5
totem-mozplugin
2.16.7-7.el5
xulrunner
1.9.2.4-9.0.1.el5
xulrunner-devel
1.9.2.4-9.0.1.el5
yelp
2.16.0-26.el5
Ссылки на источники
Связанные уязвимости
Mozilla Firefox before 3.6 Beta 3 does not properly handle overlong UTF-8 encoding, which makes it easier for remote attackers to bypass cross-site scripting (XSS) protection mechanisms via a crafted string, a different vulnerability than CVE-2010-1210.
Mozilla Firefox before 3.6 Beta 3 does not properly handle overlong UTF-8 encoding, which makes it easier for remote attackers to bypass cross-site scripting (XSS) protection mechanisms via a crafted string, a different vulnerability than CVE-2010-1210.
Mozilla Firefox before 3.6 Beta 3 does not properly handle overlong UTF-8 encoding, which makes it easier for remote attackers to bypass cross-site scripting (XSS) protection mechanisms via a crafted string, a different vulnerability than CVE-2010-1210.
Mozilla Firefox before 3.6 Beta 3 does not properly handle overlong UT ...
Mozilla Firefox before 3.6 Beta 3 does not properly handle overlong UTF-8 encoding, which makes it easier for remote attackers to bypass cross-site scripting (XSS) protection mechanisms via a crafted string, a different vulnerability than CVE-2010-1210.