Secunia - Stay Secure
Home Corporate Website Jobs Updated Mailing Lists RSS Blog  Online Shop Advertise
Software Inspectors
  Scan Online
  Personal (PSI)
  Network (NSI 2.0)

Solutions For
  Security Professionals
  Security Vendors

Free Solutions For
  Open Communities
  Journalists & Media

Secunia Advisories
  Search
  Historic Advisories
  Listed By Product
  Listed By Vendor
  Statistics / Graphs
  Secunia Research
  Report Vulnerability
  About Advisories

Virus Information
  Chronological List
  Last 10 Virus Alerts
  About Virus Information

Secunia Customers
  Customer Area


SUSE update for MozillaFirefox and seamonkey Advisory Available in Danish  Advisory Available in German 

Secunia Advisory: SA24384  
Release Date: 2007-03-07

Critical:
Highly critical
Impact: Cross Site Scripting
Spoofing
Exposure of sensitive information
System access
Where: From remote
Solution Status: Vendor Patch

OS:openSUSE 10.2
SUSE Linux 10
SUSE Linux 10.1
SUSE Linux 9.3
SUSE Linux Enterprise Server 10


CVE reference:CVE-2006-6077 (Secunia mirror)
CVE-2007-0008 (Secunia mirror)
CVE-2007-0009 (Secunia mirror)
CVE-2007-0775 (Secunia mirror)
CVE-2007-0776 (Secunia mirror)
CVE-2007-0777 (Secunia mirror)
CVE-2007-0778 (Secunia mirror)
CVE-2007-0779 (Secunia mirror)
CVE-2007-0780 (Secunia mirror)
CVE-2007-0800 (Secunia mirror)
CVE-2007-0981 (Secunia mirror)
CVE-2007-0994 (Secunia mirror)
CVE-2007-0995 (Secunia mirror)
CVE-2007-0996 (Secunia mirror)
CVE-2007-1092 (Secunia mirror)

Want to know the next time vulnerabilities are fixed in this product?
- Companies can be alerted via email and SMS!


Description:
SUSE has issued an update for MozillaFirefox and seamonkey. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, conduct cross-site scripting and spoofing attacks, gain knowledge of sensitive information, and potentially compromise a user's system.

For more information:
SA24205
SA24238

Solution:
Apply updated packages.

x86 Platform:

openSUSE 10.2:
ftp://ftp.suse.com/pub/suse/update/10...6/MozillaFirefox-2.0.0.2-1.1.i586.rpm
02e3d51d0b3420cc9397760f0e86d191
ftp://ftp.suse.com/pub/suse/update/10...fox-translations-2.0.0.2-1.1.i586.rpm
7b0f32ecd094d7eef87733b3e3476673
ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/seamonkey-1.1.1-0.1.i586.rpm
84df0ff9847008b5db52b4c1ae934210
ftp://ftp.suse.com/pub/suse/update/10...nkey-dom-inspector-1.1.1-0.1.i586.rpm
f90f3afd0bff86b4da3dbb05a2c2335d
ftp://ftp.suse.com/pub/suse/update/10...i586/seamonkey-irc-1.1.1-0.1.i586.rpm
80ac7fdac2cc547c76b5eedd482bb082
ftp://ftp.suse.com/pub/suse/update/10...586/seamonkey-mail-1.1.1-0.1.i586.rpm
91992945df0728e4260ae2ddfb7d3281
ftp://ftp.suse.com/pub/suse/update/10...onkey-spellchecker-1.1.1-0.1.i586.rpm
a4c38e8b67b32883b7d2a8c43672e762
ftp://ftp.suse.com/pub/suse/update/10.../seamonkey-venkman-1.1.1-0.1.i586.rpm
907c12a9bb1662652126d643fe851fcc

SUSE LINUX 10.1:
ftp://ftp.suse.com/pub/suse/update/10.../MozillaFirefox-1.5.0.10-0.2.i586.rpm
6e55236e3b80b3894969c655f9ebf2a4
ftp://ftp.suse.com/pub/suse/update/10...ox-translations-1.5.0.10-0.2.i586.rpm
6d61e4d6e1d6dbc9445cc3f6b6ed30e3

SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/upda.../MozillaFirefox-1.5.0.10-0.2.i586.rpm
d94fa79fb7f0de31f8d9f90baa617ca1
ftp://ftp.suse.com/pub/suse/i386/upda...ox-translations-1.5.0.10-0.2.i586.rpm
1d3fddf5349977a9caead4b47878e51d

SUSE LINUX 9.3:
ftp://ftp.suse.com/pub/suse/i386/upda.../MozillaFirefox-1.5.0.10-0.2.i586.rpm
f6e7cc76afc0fef155553f735fe653b7
ftp://ftp.suse.com/pub/suse/i386/upda...ox-translations-1.5.0.10-0.2.i586.rpm
9e7435497cd97dcd1f38105a6b080d8c

Power PC Platform:

openSUSE 10.2:
ftp://ftp.suse.com/pub/suse/update/10...pc/MozillaFirefox-2.0.0.2-1.1.ppc.rpm
5c6b5efd358c074106dcef14acb89f23
ftp://ftp.suse.com/pub/suse/update/10...efox-translations-2.0.0.2-1.1.ppc.rpm
1a6991caad9a490822710e4fcf838c9c
ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/seamonkey-1.1.1-0.1.ppc.rpm
c0dc8bbb08a3d06b656258a86710bc45
ftp://ftp.suse.com/pub/suse/update/10...onkey-dom-inspector-1.1.1-0.1.ppc.rpm
c834417d2d1db92f284a12c9f88f71d0
ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/seamonkey-irc-1.1.1-0.1.ppc.rpm
469a2f5b1968979582291477e83260dd
ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/seamonkey-mail-1.1.1-0.1.ppc.rpm
21d9f56ac5b93d70f47eba112505e209
ftp://ftp.suse.com/pub/suse/update/10...monkey-spellchecker-1.1.1-0.1.ppc.rpm
c550ce638db6e7f8d7fb3f3e037de53a
ftp://ftp.suse.com/pub/suse/update/10...c/seamonkey-venkman-1.1.1-0.1.ppc.rpm
58c4aced409456293248113d32a00dbf

SUSE LINUX 10.1:
ftp://ftp.suse.com/pub/suse/update/10...c/MozillaFirefox-1.5.0.10-0.2.ppc.rpm
4140a6709fabce8a52a9ccaeaeb7bb1a
ftp://ftp.suse.com/pub/suse/update/10...fox-translations-1.5.0.10-0.2.ppc.rpm
ac0d3d387e2f1930f331fee0800e462b

SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/upda...c/MozillaFirefox-1.5.0.10-0.2.ppc.rpm
76e3f52dd691ca5b652edce6c697070f
ftp://ftp.suse.com/pub/suse/i386/upda...fox-translations-1.5.0.10-0.2.ppc.rpm
3652ee25f11e32a518294ad8b4314b23

x86-64 Platform:

openSUSE 10.2:
ftp://ftp.suse.com/pub/suse/update/10...MozillaFirefox-2.0.0.2-1.1.x86_64.rpm
ae21afdc3451c6517c228b7cb012bbc7
ftp://ftp.suse.com/pub/suse/update/10...x-translations-2.0.0.2-1.1.x86_64.rpm
9ec91717a80c8ad5947d6d6e2fc99d01
ftp://ftp.suse.com/pub/suse/update/10...x86_64/seamonkey-1.1.1-0.1.x86_64.rpm
aa9b1d5d7cf62fcc990aabcae84e7c39
ftp://ftp.suse.com/pub/suse/update/10...ey-dom-inspector-1.1.1-0.1.x86_64.rpm
d8ac0deb3f11edc0439ce11153a04fbe
ftp://ftp.suse.com/pub/suse/update/10...64/seamonkey-irc-1.1.1-0.1.x86_64.rpm
1554c4a8c75564ae02c720455f29775b
ftp://ftp.suse.com/pub/suse/update/10...4/seamonkey-mail-1.1.1-0.1.x86_64.rpm
779e371deec7bf589bda6b3d6fdd4069
ftp://ftp.suse.com/pub/suse/update/10...key-spellchecker-1.1.1-0.1.x86_64.rpm
2ffba2b0ea7bbaf5806e03c7ffe58ac4
ftp://ftp.suse.com/pub/suse/update/10...eamonkey-venkman-1.1.1-0.1.x86_64.rpm
3761ab7b9fc06cc114a609c322d18803

Sources:

openSUSE 10.2:
ftp://ftp.suse.com/pub/suse/update/10...rc/MozillaFirefox-2.0.0.2-1.1.src.rpm
f77b9222e0a60e6638a3e0f343fea209
ftp://ftp.suse.com/pub/suse/update/10.2/rpm/src/seamonkey-1.1.1-0.1.src.rpm
ae42228f39110de8d0699694458ff88e

SUSE LINUX 10.1:
ftp://ftp.suse.com/pub/suse/update/10...c/MozillaFirefox-1.5.0.10-0.2.src.rpm
8f80ec015760d1fd3d25f30be2d5ef01

SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/upda...c/MozillaFirefox-1.5.0.10-0.2.src.rpm
748849a36a1990fea5bdb75b3bd0bcf3

SUSE LINUX 9.3:
ftp://ftp.suse.com/pub/suse/i386/upda...c/MozillaFirefox-1.5.0.10-0.2.src.rpm
f7d79ad15eeed3798e91a31cace3022d

Novell Linux Desktop 9
http://support.novell.com/techcenter/psdb/66969064f4a01b40dabf533d22cb76ee.html

Novell Linux Desktop 9 for x86
http://support.novell.com/techcenter/psdb/66969064f4a01b40dabf533d22cb76ee.html

SUSE SLES 10
http://support.novell.com/techcenter/psdb/1cbeadd626068e3518e641d88f149a11.html

SUSE SLED 10
http://support.novell.com/techcenter/psdb/1cbeadd626068e3518e641d88f149a11.html

Original Advisory:
http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html

Other References:
SA24205:
http://secunia.com/advisories/24205/

SA24238:
http://secunia.com/advisories/24238/



Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.

318 Related Secunia Security Advisories, displaying 10

1. SUSE update for python
2. SUSE update for postfix
3. SUSE Update for Multiple Packages
4. SUSE update for net-snmp
5. SUSE update for MozillaFirefox
6. SUSE Update for Multiple Packages
7. SUSE update for MozillaFirefox
8. SUSE update for bind
9. SUSE update for MozillaFirefox
10. SUSE update for kernel

Show all related advisories


Send Feedback to Secunia

If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.








Secunia PSI
Scan | Patch | Track
Free Download

Secunia Poll

Do you think it's important to read Setup/User Guides for applications for use within your network?


See Results   


Most Popular Advisories

1.
Opera Multiple Vulnerabilities
2.
Folder Lock Weak Password Encryption Security Issue
3.
vBulletin Private Message Subject Script Insertion
4.
Anzio Web Print Object (WePO) ActiveX Component "mainurl" Buffer Overflow
5.
neon "parse_domain() " Denial of Service Vulnerability
6.
SunShop Shopping Cart class.ajax.php SQL Injection Vulnerabilities
7.
URL Rotator Script "id" SQL Injection Vulnerability
8.
Programs Rating "id" SQL Injection Vulnerability
9.
Short Url & Url Tracker Script "id" SQL Injection Vulnerability
10.
PHP Live Helper Multiple Vulnerabilities





Vulnerability Management - Terms & Conditions - Copyright 2002-2008 Secunia - Compliance - Contact Secunia