Secunia - Stay Secure
Gartner
Home Corporate Website Jobs Updated Mailing Lists RSS Blog  Online Shop Advertise
Software Inspectors
  Scan Online
  Personal (PSI)
  Network (NSI 2.0)

Solutions For
  Security Professionals
  Security Vendors

Free Solutions For
  Open Communities
  Journalists & Media

Secunia Advisories
  Search
  Historic Advisories
  Listed By Product
  Listed By Vendor
  Statistics / Graphs
  Secunia Research
  Report Vulnerability
  About Advisories

Virus Information
  Chronological List
  Last 10 Virus Alerts
  About Virus Information

Secunia Customers
  Customer Area


Debian update for iceweasel Advisory Available in German 

Secunia Advisory: SA28864  
Release Date: 2008-02-11

Critical:
Highly critical
Impact: Security Bypass
Cross Site Scripting
Spoofing
Exposure of sensitive information
DoS
System access
Where: From remote
Solution Status: Vendor Patch

OS:Debian GNU/Linux 4.0


CVE reference:CVE-2008-0412 (Secunia mirror)
CVE-2008-0413 (Secunia mirror)
CVE-2008-0414 (Secunia mirror)
CVE-2008-0415 (Secunia mirror)
CVE-2008-0416 (Secunia mirror)
CVE-2008-0417 (Secunia mirror)
CVE-2008-0418 (Secunia mirror)
CVE-2008-0419 (Secunia mirror)
CVE-2008-0591 (Secunia mirror)
CVE-2008-0592 (Secunia mirror)
CVE-2008-0593 (Secunia mirror)
CVE-2008-0594 (Secunia mirror)

Want to know the next time vulnerabilities are fixed in this product?
- Companies can be alerted via email and SMS!


Description:
Debian has issued an update for iceweasel. This fixes some weaknesses and vulnerabilities, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, conduct spoofing attacks, or to compromise a user's system.

For more information:
SA28758
SA28815

Solution:
Apply updated packages.

-- Debian 4.0 (stable) --

Source archives:

http://security.debian.org/pool/updat...weasel/iceweasel_2.0.0.12.orig.tar.gz
Size/MD5 checksum: 43522779 34cb9e2038afa635dac9319a0f113be8
http://security.debian.org/pool/updat...eweasel/iceweasel_2.0.0.12-0etch1.dsc
Size/MD5 checksum: 1289 568c8d5661721888aa75724f4ec76cf9
http://security.debian.org/pool/updat...sel/iceweasel_2.0.0.12-0etch1.diff.gz
Size/MD5 checksum: 186174 96e7907d265cdf00b81785db4e2ab6c4

Architecture independent packages:

http://security.debian.org/pool/updat...easel/firefox_2.0.0.12-0etch1_all.deb
Size/MD5 checksum: 54290 97f40d39e73fba4b90c79a514ab89f18
http://security.debian.org/pool/updat...gnome-support_2.0.0.12-0etch1_all.deb
Size/MD5 checksum: 54146 ef3dbcc83837bc5c86ecdb3295716e23
http://security.debian.org/pool/updat...dom-inspector_2.0.0.12-0etch1_all.deb
Size/MD5 checksum: 54026 91815e0777f6249b4ba95bbeb38cee0c
http://security.debian.org/pool/updat...dom-inspector_2.0.0.12-0etch1_all.deb
Size/MD5 checksum: 54176 1b7640fa33604225b347b8fd368163a0
http://security.debian.org/pool/updat...zilla-firefox_2.0.0.12-0etch1_all.deb
Size/MD5 checksum: 54816 97db059f2fc4f52bd4d2389f724e8378
http://security.debian.org/pool/updat...gnome-support_2.0.0.12-0etch1_all.deb
Size/MD5 checksum: 54026 969ad8b6ed5b8b0dea8cd5d3414c1485
http://security.debian.org/pool/updat...dom-inspector_2.0.0.12-0etch1_all.deb
Size/MD5 checksum: 239356 4309e0a07163450b9d7ce65103b39b80

alpha architecture (DEC Alpha)

http://security.debian.org/pool/updat...ome-support_2.0.0.12-0etch1_alpha.deb
Size/MD5 checksum: 90934 5e1bdb44f0484fd2111a1541276b99dd
http://security.debian.org/pool/updat...eweasel-dbg_2.0.0.12-0etch1_alpha.deb
Size/MD5 checksum: 51062530 72e80dbe1969eae96b4d9ed57aa89122
http://security.debian.org/pool/updat...l/iceweasel_2.0.0.12-0etch1_alpha.deb
Size/MD5 checksum: 11553820 0cea194c903903bb98b53cc349b89dbf

amd64 architecture (AMD x86_64 (AMD64))

http://security.debian.org/pool/updat...eweasel-dbg_2.0.0.12-0etch1_amd64.deb
Size/MD5 checksum: 50060784 8639ed04300fac0705c47c27338fdfbb
http://security.debian.org/pool/updat...ome-support_2.0.0.12-0etch1_amd64.deb
Size/MD5 checksum: 87564 79c23f813fc543121275f4a974833c82
http://security.debian.org/pool/updat...l/iceweasel_2.0.0.12-0etch1_amd64.deb
Size/MD5 checksum: 10182710 bb8bbff82040dc0c04e98ac477a5a691

hppa architecture (HP PA RISC)

http://security.debian.org/pool/updat...nome-support_2.0.0.12-0etch1_hppa.deb
Size/MD5 checksum: 89302 2867a60e5385e94188bf66f38f992a29
http://security.debian.org/pool/updat...el/iceweasel_2.0.0.12-0etch1_hppa.deb
Size/MD5 checksum: 11031094 f5926d349e00706a548fdb4f6c02dbac
http://security.debian.org/pool/updat...ceweasel-dbg_2.0.0.12-0etch1_hppa.deb
Size/MD5 checksum: 50426978 4228e87f68b21f2627069a320603263d

i386 architecture (Intel ia32)

http://security.debian.org/pool/updat...el/iceweasel_2.0.0.12-0etch1_i386.deb
Size/MD5 checksum: 9096292 1c535164988178a3d6b889f9d44f31e8
http://security.debian.org/pool/updat...nome-support_2.0.0.12-0etch1_i386.deb
Size/MD5 checksum: 81706 a7ca2818a1d14730077724e3acaf615f
http://security.debian.org/pool/updat...ceweasel-dbg_2.0.0.12-0etch1_i386.deb
Size/MD5 checksum: 49451404 3525c3b01dd1142815513cc0d390493f

ia64 architecture (Intel ia64)

http://security.debian.org/pool/updat...el/iceweasel_2.0.0.12-0etch1_ia64.deb
Size/MD5 checksum: 14120046 8d6c6253c001988251523976eee216a1
http://security.debian.org/pool/updat...nome-support_2.0.0.12-0etch1_ia64.deb
Size/MD5 checksum: 99914 3a4bd7bd5ab87d20bbf5a962411ae4fa
http://security.debian.org/pool/updat...ceweasel-dbg_2.0.0.12-0etch1_ia64.deb
Size/MD5 checksum: 50400330 dfa48b54a479b7f305c899bc3f395f92

mips architecture (MIPS (Big Endian))

http://security.debian.org/pool/updat...ceweasel-dbg_2.0.0.12-0etch1_mips.deb
Size/MD5 checksum: 53844792 613a7bc03c43510bcb09e09d33bce694
http://security.debian.org/pool/updat...nome-support_2.0.0.12-0etch1_mips.deb
Size/MD5 checksum: 82810 e673433c89d7a74e95b86ed1a264fa5b
http://security.debian.org/pool/updat...el/iceweasel_2.0.0.12-0etch1_mips.deb
Size/MD5 checksum: 11038906 5f60ab9a24ad69a5b8c17ef69f31ef83

mipsel architecture (MIPS (Little Endian))

http://security.debian.org/pool/updat...me-support_2.0.0.12-0etch1_mipsel.deb
Size/MD5 checksum: 82872 e9fcd10390f6241f8ddc9c996807afe0
http://security.debian.org/pool/updat.../iceweasel_2.0.0.12-0etch1_mipsel.deb
Size/MD5 checksum: 10735706 dcc381a4d6a0d26a0d69afb0696955db
http://security.debian.org/pool/updat...weasel-dbg_2.0.0.12-0etch1_mipsel.deb
Size/MD5 checksum: 52399756 ffa41f602d079d778355e5a4a7cbde18

powerpc architecture (PowerPC)

http://security.debian.org/pool/updat...iceweasel_2.0.0.12-0etch1_powerpc.deb
Size/MD5 checksum: 9913630 75da2ef9f6915fc6961cc56755f6b8fb
http://security.debian.org/pool/updat...e-support_2.0.0.12-0etch1_powerpc.deb
Size/MD5 checksum: 83434 0b65d7b061d42bfb5ae48c9fb2f65e05
http://security.debian.org/pool/updat...easel-dbg_2.0.0.12-0etch1_powerpc.deb
Size/MD5 checksum: 51852988 59f76c278e30b86d7e3caaab603d774e

s390 architecture (IBM S/390)

http://security.debian.org/pool/updat...nome-support_2.0.0.12-0etch1_s390.deb
Size/MD5 checksum: 87788 6cc1b69d90583e765b1f54bdd8ec88a4
http://security.debian.org/pool/updat...el/iceweasel_2.0.0.12-0etch1_s390.deb
Size/MD5 checksum: 10339140 dd605f3c893a9fd281ee68c940faaea7
http://security.debian.org/pool/updat...ceweasel-dbg_2.0.0.12-0etch1_s390.deb
Size/MD5 checksum: 50726238 fdc527fd80bb0383ea8ef02dca684f16

sparc architecture (Sun SPARC/UltraSPARC)

http://security.debian.org/pool/updat...ome-support_2.0.0.12-0etch1_sparc.deb
Size/MD5 checksum: 81548 f4e489f39594fda6a3a3498aea9bd986
http://security.debian.org/pool/updat...l/iceweasel_2.0.0.12-0etch1_sparc.deb
Size/MD5 checksum: 9122208 28632988671ede31388d9caa46a5cfe9
http://security.debian.org/pool/updat...eweasel-dbg_2.0.0.12-0etch1_sparc.deb
Size/MD5 checksum: 49060394 1008a6ee3a9f8a3b6e46b766e62af10a

Original Advisory:
http://lists.debian.org/debian-securi...-security-announce-2008/msg00051.html

Other References:
SA28758:
http://secunia.com/advisories/28758/

SA28815:
http://secunia.com/advisories/28815/



Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.

303 Related Secunia Security Advisories, displaying 10

1. Debian update for sympa
2. Debian update for dbus
3. Debian update for libtk-img
4. Debian update for imlib2
5. Debian update for xorg-server
6. Debian update for mt-daapd
7. Debian update for typo3
8. Debian update for xorg-server
9. Debian update for tomcat5.5
10. Debian update for libvorbis

Show all related advisories


Send Feedback to Secunia

If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.








Secunia PSI
Scan | Patch | Track
Free Download

Secunia Poll

Do you think it's important to read Setup/User Guides for applications for use within your network?


See Results   


Most Popular Advisories

1.
Mozilla Firefox Multiple Vulnerabilities
2.
Opera for Windows Unspecified Code Execution
3.
Fedora update for glib2
4.
VLC Media Player WAV Processing Integer Overflow
5.
Mozilla Thunderbird Multiple Vulnerabilities
6.
GNOME Glib PCRE pcre_compile.c Buffer Overflow Vulnerability
7.
Opera Canvas Functions Information Disclosure
8.
PCRE pcre_compile.c Buffer Overflow Vulnerability
9.
UnixWare ReliantHA Privilege Escalation Vulnerabilities
10.
Drupal Organic groups Information Disclosure and Script Insertion





Vulnerability Management - Terms & Conditions - Copyright 2002-2008 Secunia - Compliance - Contact Secunia