Full Disclosure mailing list archives

rPSA-2007-0148-1 firefox thunderbird


From: rPath Update Announcements <announce-noreply () rpath com>
Date: Fri, 20 Jul 2007 08:39:57 -0400

rPath Security Advisory: 2007-0148-1
Published: 2007-07-20
Products: rPath Linux 1
Rating: Major
Exposure Level Classification:
    Indirect User Deterministic Unauthorized Access
Updated Versions:
    firefox=/conary.rpath.com@rpl:devel//1/1.5.0.12-0.2-1
    thunderbird=/conary.rpath.com@rpl:devel//1/1.5.0.12-0.2-1

References:
    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3089
    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3656
    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3734
    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3735
    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3736
    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3737
    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3738
    https://issues.rpath.com/browse/RPL-1561

Description:
    Previous versions of the firefox and thunderbird packages are
    vulnerable to several types of attacks, some of which are understood
    to allow compromised or malicious sites to run arbitrary code or
    commands as the user running the vulnerable application.

Copyright 2007 rPath, Inc.
This file is distributed under the terms of the MIT License.
A copy is available at http://www.rpath.com/permanent/mit-license.html

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Current thread: