Описание
ELSA-2011-1164: firefox security update (CRITICAL)
firefox:
[3.6.20-2.0.1.el6_1]
- Add firefox-oracle-default-prefs.js and remove the corresponding Red Hat ones
[3.6.20-2]
- Update to 3.6.20
xulrunner:
[1.9.2.20-2.0.1.el6_1]
- Replace xulrunner-redhat-default-prefs.js with xulrunner-oracle-default-prefs.js
[1.9.2.20-2]
- Update to 1.9.2.20
Обновленные пакеты
Oracle Linux 5
Oracle Linux ia64
firefox
3.6.20-2.0.1.el5
xulrunner
1.9.2.20-2.0.1.el5
xulrunner-devel
1.9.2.20-2.0.1.el5
Oracle Linux x86_64
firefox
3.6.20-2.0.1.el5
xulrunner
1.9.2.20-2.0.1.el5
xulrunner-devel
1.9.2.20-2.0.1.el5
Oracle Linux i386
firefox
3.6.20-2.0.1.el5
xulrunner
1.9.2.20-2.0.1.el5
xulrunner-devel
1.9.2.20-2.0.1.el5
Oracle Linux 6
Oracle Linux x86_64
firefox
3.6.20-2.0.1.el6_1
xulrunner
1.9.2.20-2.0.1.el6_1
xulrunner-devel
1.9.2.20-2.0.1.el6_1
Oracle Linux i686
firefox
3.6.20-2.0.1.el6_1
xulrunner
1.9.2.20-2.0.1.el6_1
xulrunner-devel
1.9.2.20-2.0.1.el6_1
Ссылки на источники
Связанные уязвимости
The SVGTextElement.getCharNumAtPosition function in Mozilla Firefox before 3.6.20, and 4.x through 5; Thunderbird 3.x before 3.1.12 and other versions before 6; SeaMonkey 2.x before 2.3; and possibly other products does not properly handle SVG text, which allows remote attackers to execute arbitrary code via unspecified vectors that lead to a "dangling pointer."
The SVGTextElement.getCharNumAtPosition function in Mozilla Firefox before 3.6.20, and 4.x through 5; Thunderbird 3.x before 3.1.12 and other versions before 6; SeaMonkey 2.x before 2.3; and possibly other products does not properly handle SVG text, which allows remote attackers to execute arbitrary code via unspecified vectors that lead to a "dangling pointer."
The SVGTextElement.getCharNumAtPosition function in Mozilla Firefox before 3.6.20, and 4.x through 5; Thunderbird 3.x before 3.1.12 and other versions before 6; SeaMonkey 2.x before 2.3; and possibly other products does not properly handle SVG text, which allows remote attackers to execute arbitrary code via unspecified vectors that lead to a "dangling pointer."
The SVGTextElement.getCharNumAtPosition function in Mozilla Firefox be ...