Secunia - Stay Secure
Gartner
Home Corporate Website Jobs Updated Mailing Lists RSS Blog  Online Shop Advertise
Software Inspectors
  Scan Online
  Personal (PSI)
  Network (NSI 2.0)

Solutions For
  Security Professionals
  Security Vendors

Free Solutions For
  Open Communities
  Journalists & Media

Secunia Advisories
  Search
  Historic Advisories
  Listed By Product
  Listed By Vendor
  Statistics / Graphs
  Secunia Research
  Report Vulnerability
  About Advisories

Virus Information
  Chronological List
  Last 10 Virus Alerts
  About Virus Information

Secunia Customers
  Customer Area


SUSE update for MozillaFirefox Advisory Available in Danish  Advisory Available in German 

Secunia Advisory: SA27944  
Release Date: 2007-12-06

Critical:
Highly critical
Impact: Cross Site Scripting
DoS
System access
Where: From remote
Solution Status: Vendor Patch

OS:openSUSE 10.2
openSUSE 10.3
SUSE Linux 10
SUSE Linux 10.1
SUSE Linux Enterprise Server 10


CVE reference:CVE-2007-5947 (Secunia mirror)
CVE-2007-5959 (Secunia mirror)
CVE-2007-5960 (Secunia mirror)

Want to know the next time vulnerabilities are fixed in this product?
- Companies can be alerted via email and SMS!


Description:
SUSE has issued an update for MozillaFirefox. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site request forgery and cross-site scripting attacks or potentially compromise a user's system.

For more information:
SA27605
SA27725

Solution:
Apply updated packages.

x86 Platform:

openSUSE 10.3:

http://download.opensuse.org/pub/open.../MozillaFirefox-2.0.0.10-0.1.i586.rpm
d0f7fd357a6de8c6a590b42dda9c7702

http://download.opensuse.org/pub/open...ox-translations-2.0.0.10-0.1.i586.rpm
1aaf5db8a1297805e8e9e176b238ef8c

openSUSE 10.2:

ftp://ftp.suse.com/pub/suse/update/10.../MozillaFirefox-2.0.0.10-0.1.i586.rpm
1f2516d822f8ca87b3f3f25c145e4a38

ftp://ftp.suse.com/pub/suse/update/10...ox-translations-2.0.0.10-0.1.i586.rpm
574823f229420156208b5f45bff5ca6d

SUSE LINUX 10.1:

ftp://ftp.suse.com/pub/suse/update/10.../MozillaFirefox-2.0.0.10-0.2.i586.rpm
cf1b3c80ffdfd1f3e4f340e0d9a8c07f

ftp://ftp.suse.com/pub/suse/update/10...ox-translations-2.0.0.10-0.2.i586.rpm
fd13fa44b75a2e6317103f265d77f702

SUSE LINUX 10.0:

ftp://ftp.suse.com/pub/suse/i386/upda.../MozillaFirefox-2.0.0.10-0.1.i586.rpm
6f5985e8b52cd2fd82f935eb1bdcef75

ftp://ftp.suse.com/pub/suse/i386/upda...ox-translations-2.0.0.10-0.1.i586.rpm
5713f8749a674285d4de104729466231

Power PC Platform:

openSUSE 10.3:

http://download.opensuse.org/pub/open...c/MozillaFirefox-2.0.0.10-0.1.ppc.rpm
d94b360b96f78415486e590ba2ebc56f

http://download.opensuse.org/pub/open...fox-translations-2.0.0.10-0.1.ppc.rpm
e22b1e054000aa0d53c41fe6ac39372a

openSUSE 10.2:

ftp://ftp.suse.com/pub/suse/update/10...c/MozillaFirefox-2.0.0.10-0.1.ppc.rpm
530f6740fee6d2fb643afa4b9f0c49ef

ftp://ftp.suse.com/pub/suse/update/10...fox-translations-2.0.0.10-0.1.ppc.rpm
6db2f0cb850b212cec62de5ad94d0069

SUSE LINUX 10.1:

ftp://ftp.suse.com/pub/suse/update/10...c/MozillaFirefox-2.0.0.10-0.2.ppc.rpm
ed1d282e433ce48f63ed14e836c18d52

ftp://ftp.suse.com/pub/suse/update/10...fox-translations-2.0.0.10-0.2.ppc.rpm
740adaa059e9898be2e0a1a2bea8bfd0

SUSE LINUX 10.0:

ftp://ftp.suse.com/pub/suse/i386/upda...c/MozillaFirefox-2.0.0.10-0.1.ppc.rpm
0c7fc24e3f284c4f2f4fbe4da05500bc

ftp://ftp.suse.com/pub/suse/i386/upda...fox-translations-2.0.0.10-0.1.ppc.rpm
58404d548715285c5899e36a7ce28b6c

x86-64 Platform:

openSUSE 10.3:

http://download.opensuse.org/pub/open...ozillaFirefox-2.0.0.10-0.1.x86_64.rpm
084e0ea783cb2b1069de863276b65b67

http://download.opensuse.org/pub/open...-translations-2.0.0.10-0.1.x86_64.rpm
ab398376912b59c1b29326771336b4d7

openSUSE 10.2:

ftp://ftp.suse.com/pub/suse/update/10...ozillaFirefox-2.0.0.10-0.1.x86_64.rpm
173749354f0641198f0c6100ae190564

ftp://ftp.suse.com/pub/suse/update/10...-translations-2.0.0.10-0.1.x86_64.rpm
c7d56938e6ebc0bbaac89965eedcf475

Sources:

openSUSE 10.3:

http://download.opensuse.org/pub/open...c/MozillaFirefox-2.0.0.10-0.1.src.rpm
beb5c6009fc75627e1305e05aafdd808

openSUSE 10.2:

ftp://ftp.suse.com/pub/suse/update/10...c/MozillaFirefox-2.0.0.10-0.1.src.rpm
1fa1299403a46b21f0fe505405250fc7

SUSE LINUX 10.1:

ftp://ftp.suse.com/pub/suse/update/10...c/MozillaFirefox-2.0.0.10-0.2.src.rpm
5c8cb8c56778911746b6851de11446fe

SUSE LINUX 10.0:

ftp://ftp.suse.com/pub/suse/i386/upda...c/MozillaFirefox-2.0.0.10-0.1.src.rpm
4f10c8fdacab3bc3e05dec6100be2d6b

SUSE Linux Enterprise Server 10 SP1

http://support.novell.com/techcenter/psdb/a1909a9a9f705e973cf0feed1743484e.html

SUSE Linux Enterprise Desktop 10 SP1

http://support.novell.com/techcenter/psdb/a1909a9a9f705e973cf0feed1743484e.html

Original Advisory:
http://lists.opensuse.org/opensuse-security-announce/2007-12/msg00004.html

Other References:
SA27605:
http://secunia.com/advisories/27605/

SA27725:
http://secunia.com/advisories/27725/



Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.

257 Related Secunia Security Advisories, displaying 10

1. SUSE Update for Multiple Packages
2. SUSE update for MozillaFirefox
3. SUSE update for bind
4. SUSE update for MozillaFirefox
5. SUSE update for kernel
6. SUSE Update for Multiple Packages
7. SUSE update for kernel
8. SUSE update for kernel
9. SUSE Update for Multiple Packages
10. SUSE update for evolution

Show all related advisories


Send Feedback to Secunia

If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.








Secunia PSI
Scan | Patch | Track
Free Download

Secunia Poll

Do you think it's important to read Setup/User Guides for applications for use within your network?


See Results   


Most Popular Advisories

1.
Red Hat update for vsftpd
2.
Red Hat update for rdesktop
3.
Red Hat update for rdesktop
4.
Red Hat update for coreutils
5.
Red Hat update for nss_ldap
6.
Red Hat update for kernel
7.
Red Hat update for mysql
8.
OpenBSD BIND Query Port DNS Cache Poisoning
9.
Atom PhotoBlog "photoId" SQL Injection Vulnerability
10.
Debian update for clamav





Vulnerability Management - Terms & Conditions - Copyright 2002-2008 Secunia - Compliance - Contact Secunia