| From: |
| Mageia Updates <buildsystem-daemon@mageia.org> |
| To: |
| updates-announce@ml.mageia.org |
| Subject: |
| [updates-announce] MGASA-2013-0287: Updated firefox and thunderbird packages fix security vulnerabilities |
| Date: |
| Thu, 19 Sep 2013 11:50:02 +0200 |
| Message-ID: |
| <20130919095002.B43A95B0C8@valstar.mageia.org> |
| Archive-link: |
| Article, Thread
|
MGASA-2013-0287 - Updated firefox and thunderbird packages fix security vulnerabilities
Publication date: 19 Sep 2013
URL: http://advisories.mageia.org/MGASA-2013-0287.html
Type: security
Affected Mageia releases: 2, 3
CVE: CVE-2013-1718,
CVE-2013-1722,
CVE-2013-1725,
CVE-2013-1730,
CVE-2013-1732,
CVE-2013-1735,
CVE-2013-1736,
CVE-2013-1737
Description:
Several flaws were found in the processing of malformed web content. A
web page containing malicious content could cause Firefox or Thunderbird
to crash or, potentially, execute arbitrary code with the privileges of
the user running Firefox or Thunderbird (CVE-2013-1718, CVE-2013-1722,
CVE-2013-1725, CVE-2013-1730, CVE-2013-1732, CVE-2013-1735,
CVE-2013-1736).
A flaw was found in the way Firefox and Thunderbird handled certain DOM
JavaScript objects. An attacker could use this flaw to make JavaScript
client or add-on code make incorrect, security sensitive decisions
(CVE-2013-1737).
References:
- https://bugs.mageia.org/show_bug.cgi?id=11250
- http://www.mozilla.org/security/announce/2013/mfsa2013-76...
- http://www.mozilla.org/security/announce/2013/mfsa2013-79...
- http://www.mozilla.org/security/announce/2013/mfsa2013-82...
- http://www.mozilla.org/security/announce/2013/mfsa2013-83...
- http://www.mozilla.org/security/announce/2013/mfsa2013-88...
- http://www.mozilla.org/security/announce/2013/mfsa2013-89...
- http://www.mozilla.org/security/announce/2013/mfsa2013-90...
- http://www.mozilla.org/security/announce/2013/mfsa2013-91...
- http://www.mozilla.org/security/known-vulnerabilities/fir...
- https://rhn.redhat.com/errata/RHSA-2013-1268.html
- https://rhn.redhat.com/errata/RHSA-2013-1269.html
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1718
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1722
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1725
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1730
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1732
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1735
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1736
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1737
SRPMS:
- 3/core/firefox-17.0.9-1.mga3
- 3/core/firefox-17.0.9-1.mga3
- 3/core/thunderbird-17.0.9-1.mga3
- 3/core/thunderbird-l10n-17.0.9-1.mga3
- 2/core/firefox-17.0.9-1.mga2
- 2/core/firefox-l10n-17.0.9-1.mga2
- 2/core/thunderbird-17.0.9-1.mga2
- 2/core/thunderbird-l10n-17.0.9-1.mga2
(
Log in to post comments)