| From: |
| updates@fedoraproject.org |
| To: |
| fedora-package-announce@redhat.com |
| Subject: |
| [SECURITY] Fedora 11 Update: epiphany-2.26.3-7.fc11 |
| Date: |
| Fri, 18 Dec 2009 04:32:41 +0000 |
| Message-ID: |
| <20091218043243.17B2B28EDDC@bastion3.fedora.phx2.redhat.com> |
| Archive-link: |
| Article, Thread
|
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2009-13333
2009-12-18 03:17:31
--------------------------------------------------------------------------------
Name : epiphany
Product : Fedora 11
Version : 2.26.3
Release : 7.fc11
URL : http://www.gnome.org/projects/epiphany/
Summary : Web browser for GNOME
Description :
Epiphany is the web browser for the GNOME desktop. Its goal is to be
simple and easy to use. Epiphany ties together many GNOME components
in order to let you focus on the Web content, instead of the browser
application.
Epiphany is extensible through a plugin system. Existing plugins can be
found in the epiphany-extensions package.
--------------------------------------------------------------------------------
Update Information:
Update to new upstream Firefox version 3.5.6, fixing multiple security issues
detailed in the upstream advisories: http://www.mozilla.org/security/known-
vulnerabilities/firefox35.html#firefox3.5.6 Update also includes all packages
depending on gecko-libs rebuilt against new version of Firefox / XULRunner.
CVE-2009-3979 CVE-2009-3980 CVE-2009-3982 CVE-2009-3983 CVE-2009-3984
CVE-2009-3985 CVE-2009-3986 CVE-2009-3388 CVE-2009-3389
--------------------------------------------------------------------------------
ChangeLog:
* Wed Dec 16 2009 Jan Horak <jhorak@redhat.com> - 2.26.3-7
- Rebuild against newer gecko
* Thu Nov 5 2009 Jan Horak <jhorak@redhat.com> - 2.26.3-6
- Rebuild against newer gecko
* Tue Oct 27 2009 Jan Horak <jhorak@redhat.com> - 2.26.3-5
- Rebuild against newer gecko
* Wed Sep 9 2009 Jan Horak <jhorak@redhat.com> - 2.26.3-4
- Rebuild against newer gecko
* Mon Aug 3 2009 Christopher Aillon <caillon@redhat.com> - 2.26.3-3
- Rebuild against newer gecko
* Fri Jul 17 2009 Jan Horak <jhorak@redhat.com> - 2.26.3-2
- Rebuild against newer gecko
* Wed Jul 1 2009 Matthias Clasen <mclasen@redhat.com> - 2.26.3-1
- Update to 2.26.3
- See http://download.gnome.org/sources/epiphany/2.26/epiphany-...
* Tue Jun 30 2009 Christopher Aillon <caillon@redhat.com> - 2.26.2-2
- Rebuild against newer gecko
* Mon Jun 1 2009 Matthias Clasen <mclasen@redhat.com> - 2.26.2-1
- Update to 2.26.2
- See http://download.gnome.org/sources/epiphany/2.26/epiphany-...
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #546694 - CVE-2009-3979 Mozilla crash with evidence of memory corruption
https://bugzilla.redhat.com/show_bug.cgi?id=546694
[ 2 ] Bug #546720 - CVE-2009-3983 Mozilla NTLM reflection vulnerability
https://bugzilla.redhat.com/show_bug.cgi?id=546720
[ 3 ] Bug #546722 - CVE-2009-3984 Mozilla SSL spoofing with document.location and empty SSL
response page
https://bugzilla.redhat.com/show_bug.cgi?id=546722
[ 4 ] Bug #546726 - CVE-2009-3985 Mozilla URL spoofing via invalid document.location
https://bugzilla.redhat.com/show_bug.cgi?id=546726
[ 5 ] Bug #546724 - CVE-2009-3986 Mozilla Chrome privilege escalation via window.opener
https://bugzilla.redhat.com/show_bug.cgi?id=546724
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update epiphany' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
http://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
Fedora-package-announce mailing list
Fedora-package-announce@redhat.com
http://www.redhat.com/mailman/listinfo/fedora-package-ann...
(
Log in to post comments)