[FEDORA-2007-3962] Fedora 8: galeon, epiphany-extensions, blam, ruby-gnome2, devhelp & 11 more

Severity High
Affected Packages 16
CVEs 4

Updated firefox packages that fix several security issues are now available for Fedora 8.

This update has been rated as having critical security impact by the Fedora Security Response Team.

Mozilla Firefox is an open source Web browser.

A cross-site scripting flaw was found in the way Firefox handled the jar: URI scheme. It was possible for a malicious website to leverage this flaw and conduct a cross-site scripting attack against a user running Firefox. (CVE-2007-5947)

Several flaws were found in the way Firefox processed certain malformed web content. A webpage containing malicious content could cause Firefox to crash, or potentially execute arbitrary code as the user running Firefox. (CVE-2007-5959)

A race condition existed when Firefox set the "window.location" property for a webpage. This flaw could allow a webpage to set an arbitrary Referer header, which may lead to a Cross-site Request Forgery (CSRF) attack against websites that rely only on the Referer header for protection. (CVE-2007-5960)

Users of Firefox are advised to upgrade to these updated packages, which contain backported patches to resolve these issues.

Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/fedora/yelp?distro=fedora-8 fedora yelp < 2.20.0.6.fc8 fedora-8
Affected pkg:rpm/fedora/ruby-gnome2?distro=fedora-8 fedora ruby-gnome2 < 0.16.0.17.fc8 fedora-8
Affected pkg:rpm/fedora/openvrml?distro=fedora-8 fedora openvrml < 0.16.7.2.fc8 fedora-8
Affected pkg:rpm/fedora/Miro?distro=fedora-8 fedora Miro < 1.0.2.fc8 fedora-8
Affected pkg:rpm/fedora/liferea?distro=fedora-8 fedora liferea < 1.4.8.2.fc8 fedora-8
Affected pkg:rpm/fedora/kazehakase?distro=fedora-8 fedora kazehakase < 0.5.0.1.fc8.2 fedora-8
Affected pkg:rpm/fedora/gtkmozembedmm?distro=fedora-8 fedora gtkmozembedmm < 1.4.2.cvs20060817.17.fc8 fedora-8
Affected pkg:rpm/fedora/gnome-web-photo?distro=fedora-8 fedora gnome-web-photo < 0.3.7.fc8 fedora-8
Affected pkg:rpm/fedora/gnome-python2-extras?distro=fedora-8 fedora gnome-python2-extras < 2.19.1.11.fc8 fedora-8
Affected pkg:rpm/fedora/galeon?distro=fedora-8 fedora galeon < 2.0.3.16.fc8 fedora-8
Affected pkg:rpm/fedora/firefox?distro=fedora-8 fedora firefox < 2.0.0.10.1.fc8 fedora-8
Affected pkg:rpm/fedora/epiphany?distro=fedora-8 fedora epiphany < 2.20.1.6.fc8 fedora-8
Affected pkg:rpm/fedora/epiphany-extensions?distro=fedora-8 fedora epiphany-extensions < 2.20.1.4.fc8 fedora-8
Affected pkg:rpm/fedora/devhelp?distro=fedora-8 fedora devhelp < 0.16.1.4.fc8 fedora-8
Affected pkg:rpm/fedora/chmsee?distro=fedora-8 fedora chmsee < 1.0.0.1.27.fc8 fedora-8
Affected pkg:rpm/fedora/blam?distro=fedora-8 fedora blam < 1.8.3.12.fc8 fedora-8
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...