|
Family: SuSE Local Security Checks --> Category: infos
SUSE-SA:2006:054: MozillaFirefox,MozillaThunderbird,seamonkey Vulnerability Scan
Vulnerability Scan Summary Check for the version of the MozillaFirefox,MozillaThunderbird,seamonkey package
Detailed Explanation for this Vulnerability Test
The remote host is missing the patch for the advisory SUSE-SA:2006:054 (MozillaFirefox,MozillaThunderbird,seamonkey).
Security updates have been released that bring Mozilla Firefox to
version 1.5.0.7, Mozilla Thunderbird to version 1.5.0.7 and Mozilla
Seamonkey to 1.0.5.
Seamonkey and Thunderbird were released early this week, Firefox was
released today.
Please also see
http://www.mozilla.org/projects/security/known-vulnerabilities.html
for more details.
The updates fix the following security problems:
MFSA 2006-64/CVE-2006-4571: Crashes with evidence of memory corruption
MFSA 2006-63/CVE-2006-4570: Executing JavaScript within E-Mail using XBL
MFSA 2006-62/CVE-2006-4569: Pop up-blocker cross-site scripting (XSS)
MFSA 2006-61/CVE-2006-4568: Frame spoofing using document.open()
MFSA 2006-60/CVE-2006-4340/CERT VU#845620: RSA Signature Forgery
MFSA 2006-59/CVE-2006-4253: Concurrency-related vulnerability
MFSA 2006-58/CVE-2006-4567: Auto-Update compromise through DNS and SSL spoofing
MFSA 2006-57/CVE-2006-4565/CVE-2006-4566: JavaScript Regular Expression Heap Corruption
Solution : http://www.suse.de/security/http://www.novell.com/linux/security/advisories/2006_54_mozilla.html
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.
|