RHSA-2009:0397: Critical security update
61
This update has been rated as having critical security impact by the Red Hat Security Response
Team.
Mozilla Firefox is an open source Web browser. XULRunner provides the XUL Runtime environment
for Mozilla Firefox.
Several flaws were found in the processing of malformed web content. A web page containing
malicious content could cause Firefox to crash or, potentially, execute arbitrary code as the user
running Firefox. (
CVE-2009-1302
355
,
CVE-2009-1303
356
,
CVE-2009-1304
357
,
CVE-2009-1305
358
)
Several flaws were found in the way malformed web content was processed. A web page
containing malicious content could execute arbitrary JavaScript in the context of the site, possibly
presenting misleading data to a user, or stealing sensitive information such as login credentials.
(
CVE-2009-0652
359
,
CVE-2009-1306
360
,
CVE-2009-1307
361
,
CVE-2009-1308
362
,
CVE-2009-1309
363
,
CVE-2009-1310
364
,
CVE-2009-1312
365
)
A flaw was found in the way Firefox saved certain web pages to a local file. If a user saved the inner
frame of a web page containing POST data, the POST data could be revealed to the inner frame,
possibly surrendering sensitive information such as login credentials. (
CVE-2009-1311
366
)
For technical details regarding these flaws, refer to the Mozilla security advisories for Firefox 3.0.9.
You can find a link to the Mozilla advisories in the References section of this errata.
All Firefox users should upgrade to these updated packages, which contain Firefox version 3.0.9,
which corrects these issues. After installing the update, Firefox must be restarted for the changes to
take effect.
1.57.5. RHSA-2009:0397: Critical security update
Important
This update has already been released (prior to the GA of this release) as the security
errata
RHSA-2009:0397
367
Updated firefox packages that fix two security issues are now available for Red Hat Enterprise Linux 4
and 5.
This update has been rated as having critical security impact by the Red Hat Security Response
Team.
Mozilla Firefox is an open source Web browser. XULRunner provides the XUL Runtime environment
for Mozilla Firefox.
355
https://www.redhat.com/security/data/cve/CVE-2009-1302.html
356
https://www.redhat.com/security/data/cve/CVE-2009-1303.html
357
https://www.redhat.com/security/data/cve/CVE-2009-1304.html
358
https://www.redhat.com/security/data/cve/CVE-2009-1305.html
359
https://www.redhat.com/security/data/cve/CVE-2009-0652.html
360
https://www.redhat.com/security/data/cve/CVE-2009-1306.html
361
https://www.redhat.com/security/data/cve/CVE-2009-1307.html
362
https://www.redhat.com/security/data/cve/CVE-2009-1308.html
363
https://www.redhat.com/security/data/cve/CVE-2009-1309.html
364
https://www.redhat.com/security/data/cve/CVE-2009-1310.html
365
https://www.redhat.com/security/data/cve/CVE-2009-1312.html
366
https://www.redhat.com/security/data/cve/CVE-2009-1311.html
Summary of Contents for ENTERPRISE 5.4 RELEASE NOTES
Page 1: ...Red Hat Enterprise Linux 5 4 Technical Notes Every Change to Every Package ...
Page 18: ...xviii ...
Page 306: ...288 ...
Page 464: ...446 ...
Page 466: ...448 ...