Family: Mandrake Local Security Checks --> Category: infos
MDKSA-2005:173: mozilla-firefox Vulnerability Scan
Vulnerability Scan Summary
Check for the version of the mozilla-firefox package
Detailed Explanation for this Vulnerability Test
The remote host is missing the patch for the advisory MDKSA-2005:173 (mozilla-firefox).
New updates are available for Mozilla Firefox:
A regression in the LE2005 Firefox package caused problems with cursor movement
that has been fixed.
The run-mozilla.sh script, with debugging enabled, would allow local users to
create or overwrite arbitrary files via a symlink attack on temporary files
nsScriptSecurityManager::GetBaseURIScheme didn't handle jar:view-source:...
correctly because the jar: and view-source: cases didn't use recursion as they
were supposed to. This was corrected in Firefox 1.0.4 and only affects the
The updated packages have been patched to correct these issues.
Solution : http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2005:173
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.