SCIENTIFIC-LINUX-ERRATA Archives

January 2013

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Pat Riehecky <[log in to unmask]>
Reply To:
Pat Riehecky <[log in to unmask]>
Date:
Thu, 10 Jan 2013 10:02:22 -0600
Content-Type:
text/plain
Parts/Attachments:
text/plain (81 lines)
Synopsis:          Critical: firefox security update
Issue Date:        2013-01-08
CVE Numbers:       CVE-2013-0769
                    CVE-2013-0762
                    CVE-2013-0766
                    CVE-2013-0767
                    CVE-2013-0759
                    CVE-2013-0744
                    CVE-2013-0746
                    CVE-2013-0748
                    CVE-2013-0750
                    CVE-2013-0758
                    CVE-2013-0753
                    CVE-2013-0754
--

Several flaws were found in the processing of malformed web content. A 
web page
containing malicious content could cause Firefox to crash or, potentially,
execute arbitrary code with the privileges of the user running Firefox.
(CVE-2013-0744, CVE-2013-0746, CVE-2013-0750, CVE-2013-0753, CVE-2013-0754,
CVE-2013-0762, CVE-2013-0766, CVE-2013-0767, CVE-2013-0769)

A flaw was found in the way Chrome Object Wrappers were implemented. 
Malicious
content could be used to cause Firefox to execute arbitrary code via 
plug-ins
installed in Firefox. (CVE-2013-0758)

A flaw in the way Firefox displayed URL values in the address bar could 
allow a
malicious site or user to perform a phishing attack. (CVE-2013-0759)

An information disclosure flaw was found in the way certain JavaScript
functions were implemented in Firefox. An attacker could use this flaw to
bypass Address Space Layout Randomization (ASLR) and other security
restrictions. (CVE-2013-0748)

After installing the update, Firefox must be restarted for the changes to
take effect.
--

SL5
   x86_64
     firefox-10.0.12-1.el5_9.i386.rpm
     firefox-10.0.12-1.el5_9.x86_64.rpm
     firefox-debuginfo-10.0.12-1.el5_9.i386.rpm
     firefox-debuginfo-10.0.12-1.el5_9.x86_64.rpm
     xulrunner-10.0.12-1.el5_9.i386.rpm
     xulrunner-10.0.12-1.el5_9.x86_64.rpm
     xulrunner-debuginfo-10.0.12-1.el5_9.i386.rpm
     xulrunner-debuginfo-10.0.12-1.el5_9.x86_64.rpm
     xulrunner-devel-10.0.12-1.el5_9.i386.rpm
     xulrunner-devel-10.0.12-1.el5_9.x86_64.rpm
   i386
     firefox-10.0.12-1.el5_9.i386.rpm
     firefox-debuginfo-10.0.12-1.el5_9.i386.rpm
     xulrunner-10.0.12-1.el5_9.i386.rpm
     xulrunner-debuginfo-10.0.12-1.el5_9.i386.rpm
     xulrunner-devel-10.0.12-1.el5_9.i386.rpm
SL6
   x86_64
     firefox-10.0.12-1.el6_3.i686.rpm
     firefox-10.0.12-1.el6_3.x86_64.rpm
     firefox-debuginfo-10.0.12-1.el6_3.i686.rpm
     firefox-debuginfo-10.0.12-1.el6_3.x86_64.rpm
     xulrunner-10.0.12-1.el6_3.i686.rpm
     xulrunner-10.0.12-1.el6_3.x86_64.rpm
     xulrunner-debuginfo-10.0.12-1.el6_3.i686.rpm
     xulrunner-debuginfo-10.0.12-1.el6_3.x86_64.rpm
     xulrunner-devel-10.0.12-1.el6_3.i686.rpm
     xulrunner-devel-10.0.12-1.el6_3.x86_64.rpm
   i386
     firefox-10.0.12-1.el6_3.i686.rpm
     firefox-debuginfo-10.0.12-1.el6_3.i686.rpm
     xulrunner-10.0.12-1.el6_3.i686.rpm
     xulrunner-debuginfo-10.0.12-1.el6_3.i686.rpm
     xulrunner-devel-10.0.12-1.el6_3.i686.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2