[FEDORA-2008-2682] Fedora 8: Miro, yelp, epiphany, gtkmozembedmm, ruby-gnome2 & 11 more

Severity High
Affected Packages 16
CVEs 11

Mozilla Firefox is an open source Web browser. Several flaws were found in
the processing of some malformed web content. A web page containing such
malicious content could cause Firefox to crash or, potentially, execute
arbitrary code as the user running Firefox. (CVE-2008-1233, CVE-2008-1235,
CVE-2008-1236, CVE-2008-1237) Several flaws were found in the display of
malformed web content. A web page containing specially-crafted content could,
potentially, trick a Firefox user into surrendering sensitive information.
(CVE-2008-1234, CVE-2008-1238, CVE-2008-1241) All Firefox users should
upgrade to these updated packages, which correct these issues, and are rebuilt
against the update Firefox packages.

Source # ID Name URL
Bugzilla 438713 Bug #438713 - CVE-2008-1233 Mozilla products XPCNativeWrapper pollution https://bugzilla.redhat.com/show_bug.cgi?id=438713
Bugzilla 438715 Bug #438715 - CVE-2008-1234 universal XSS using event handlers https://bugzilla.redhat.com/show_bug.cgi?id=438715
Bugzilla 438730 Bug #438730 - CVE-2008-1241 XUL popup spoofing https://bugzilla.redhat.com/show_bug.cgi?id=438730
Bugzilla 438718 Bug #438718 - CVE-2008-1236 browser engine crashes https://bugzilla.redhat.com/show_bug.cgi?id=438718
Bugzilla 438724 Bug #438724 - CVE-2008-1238 Referrer spoofing bug https://bugzilla.redhat.com/show_bug.cgi?id=438724
Bugzilla 438717 Bug #438717 - CVE-2008-1235 chrome privilege via wrong principal https://bugzilla.redhat.com/show_bug.cgi?id=438717
Bugzilla 438721 Bug #438721 - CVE-2008-1237 javascript crashes https://bugzilla.redhat.com/show_bug.cgi?id=438721
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/fedora/yelp?distro=fedora-8 fedora yelp < fedora-8
Affected pkg:rpm/fedora/ruby-gnome2?distro=fedora-8 fedora ruby-gnome2 < fedora-8
Affected pkg:rpm/fedora/openvrml?distro=fedora-8 fedora openvrml < fedora-8
Affected pkg:rpm/fedora/Miro?distro=fedora-8 fedora Miro < fedora-8
Affected pkg:rpm/fedora/liferea?distro=fedora-8 fedora liferea < fedora-8
Affected pkg:rpm/fedora/kazehakase?distro=fedora-8 fedora kazehakase < fedora-8
Affected pkg:rpm/fedora/gtkmozembedmm?distro=fedora-8 fedora gtkmozembedmm < 1.4.2.cvs20060817.19.fc8 fedora-8
Affected pkg:rpm/fedora/gnome-web-photo?distro=fedora-8 fedora gnome-web-photo < 0.3.9.fc8 fedora-8
Affected pkg:rpm/fedora/gnome-python2-extras?distro=fedora-8 fedora gnome-python2-extras < fedora-8
Affected pkg:rpm/fedora/galeon?distro=fedora-8 fedora galeon < fedora-8
Affected pkg:rpm/fedora/firefox?distro=fedora-8 fedora firefox < fedora-8
Affected pkg:rpm/fedora/epiphany?distro=fedora-8 fedora epiphany < fedora-8
Affected pkg:rpm/fedora/epiphany-extensions?distro=fedora-8 fedora epiphany-extensions < fedora-8
Affected pkg:rpm/fedora/devhelp?distro=fedora-8 fedora devhelp < fedora-8
Affected pkg:rpm/fedora/chmsee?distro=fedora-8 fedora chmsee < fedora-8
Affected pkg:rpm/fedora/blam?distro=fedora-8 fedora blam < fedora-8
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date