SciLinux: CVE-2007-3089 firefox SL5.x, SL4.x, SL3,x i386/x86_64
Summary
Date: Thu, 19 Jul 2007 16:05:27 -0500Reply-To: Troy DawsonSender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA for firefox on SL5.x, SL4.x, SL3,x i386/x86_64Comments: To: scientific-linux-errata@fnal.govSynopsis: Critical: firefox security updateIssue date: 2007-07-18CVE Names: CVE-2007-3089 CVE-2007-3656 CVE-2007-3734 CVE-2007-3735 CVE-2007-3736 CVE-2007-3737 CVE-2007-3738Several flaws were found in the way Firefox processed certain malformedJavaScript code. A web page containing malicious JavaScript code couldcause Firefox to crash or potentially execute arbitrary code as the userrunning Firefox. (CVE-2007-3734, CVE-2007-3735, CVE-2007-3737,CVE-2007-3738)Several content injection flaws were found in the way Firefox handledcertain JavaScript code. A web page containing malicious JavaScript codecould inject arbitrary content into other web pages. (CVE-2007-3736,CVE-2007-3089)A flaw was found in the way Firefox cached web pages on the local disk.A malicious web page may be able to inject arbitrary HTML into abrowsing session if the user reloads a targeted site. (CVE-2007-3656)SL 3.0.x SRPMS: firefox-1.5.0.12-0.3.SL3.src.rpm i386: firefox-1.5.0.12-0.3.SL3.i386.rpm x86_64: firefox-1.5.0.12-0.3.SL3.i386.rpm firefox-1.5.0.12-0.3.SL3.x86_64.rpmSL 4.x SRPMS: firefox-1.5.0.12-0.3.el4.src.rpm i386: firefox-1.5.0.12-0.3.el4.i386.rpm x86_64: firefox-1.5.0.12-0.3.el4.i386.rpm firefox-1.5.0.12-0.3.el4.x86_64.rpmSL 5.x SRPMS: firefox-1.5.0.12-3.el5.src.rpm i386: firefox-1.5.0.12-3.el5.i386.rpm firefox-devel-1.5.0.12-3.el5.i386.rpm x86_64: firefox-1.5.0.12-3.el5.i386.rpm firefox-1.5.0.12-3.el5.x86_64.rpm firefox-devel-1.5.0.12-3.el5.i386.rpm firefox-devel-1.5.0.12-3.el5.x86_64.rpm-Connie Sieh-Troy Dawson