FLEA-2007-0033-1: firefox thunderbird



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Foresight Linux Essential Advisory: 2007-0033-1
Published: 2007-07-24

Rating: Major

Updated Versions:
firefox=/foresight.rpath.org@fl:1-devel//1/2.0.0.5-1-1
thunderbird=/conary.rpath.com@rpl:devel//foresight.rpath.org@fl:1-devel//1/2.0.0.5-0.1-1
group-dist=/foresight.rpath.org@fl:1-devel//1/1.3.2-0.6-2

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3089
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3656
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3734
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3735
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3736
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3737
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3738
https://issues.rpath.com/browse/RPL-1561

Description:
Previous versions of the firefox and thunderbird packages are
vulnerable to several types of attacks, some of which are understood
to allow compromised or malicious sites to run arbitrary code or
commands as the user running the vulnerable application.

- ---

Copyright 2007 Foresight Linux Project
This file is distributed under the terms of the MIT License.
A copy is available at http://www.foresightlinux.org/permanent/mit-license.html
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.4 (GNU/Linux)

iQIVAwUBRqYu9tfwEn07iAtZAQLDlQ/8CxsUkYf1amtYqX4XGoXbG3Vt0V/M1TLn
xYRAy9tT7FtoMpppQBVoGrvR/Y3jnE1n7OptmO713LgjWuYvL88Krj3DAZMqXwZM
iv4gzZ61MMuZbNm5oYQ9r1uHjiDGrHJdAgVRyfqy5i3KXzT810oZ10Ckp1qinzJG
0Uh111gG/jYsG5tnk7gbipInJtaJoMmyR8seheB3LMgA40lNTJGEyZM8m83dwvVE
Pk5aYnWyAHyVLqX4oV8j2bB3qOKAHjuR4T4bKx4CzUZR/9B3wwTx1ovhEGtTOvWT
3jgGmA/74psloP9eh7S1F7G9nVk3mtfmH3ozaFGWQKzyPuy/PVxiExiPU5UpfSW2
WA29R1iUcjialQ4eDdyDWAAUls3FaqRKLYTsJLSGdlQAvqnTudHXXpi+TandpBWC
fjVt1d7AIUh+sUPvon6X+K8oemjPn0s7u4hc28iwHUASi+VtSSffY87ZvTW+/xmM
PDdCmFsRy4kWhZxxMIG3su73RSOFTzHFrEOgsGFUXvo22o0Qn3EzrSSfxg7W+CqZ
+QVOqlmJvI5HYGKM4vb/1+gof4MwV2592xXlbXSfhtp/HlFvCSsXAO6rqxO6beA6
YsG4jsb7hjAQrXxAFvwcc0gdLMNdYOeBneeMboAeyx9kcaPJKIl4tVq7i+H516CS
vfEOMgi0ofY=
=B1vH
-----END PGP SIGNATURE-----



Relevant Pages

  • FLEA-2007-0062-1 firefox
    ... Foresight Linux Essential Advisory: 2007-0062-1 ... Rating: Major ... or malicious sites to run arbitrary code as the user running firefox. ... Copyright 2007 Foresight Linux Project ...
    (Bugtraq)
  • [Full-disclosure] FLEA-2007-0023-1: firefox
    ... Rating: Major ... Previous versions of the firefox package are vulnerable to several types of ... Copyright 2007 Foresight Linux Project ... Portions Copyright 2007 rPath, Inc. ...
    (Full-Disclosure)
  • [Full-disclosure] FLEA-2007-0033-1: firefox thunderbird
    ... Rating: Major ... Previous versions of the firefox and thunderbird packages are ... Copyright 2007 Foresight Linux Project ...
    (Full-Disclosure)
  • [Full-disclosure] FLEA-2008-0006-1 tetex tetex-dvips tetex-fonts
    ... Foresight Linux Essential Advisory: 2008-0006-1 ... Rating: Minor ... Previous versions of the tetex package are vulnerable to multiple issues, ... Copyright 2008 Foresight Linux Project ...
    (Full-Disclosure)
  • FLEA-2007-0023-1: firefox
    ... Rating: Major ... Previous versions of the firefox package are vulnerable to several types of ... Copyright 2007 Foresight Linux Project ... Portions Copyright 2007 rPath, Inc. ...
    (Bugtraq)