|
Mozilla Browser Refresh Security Property Spoofing Vulnerability
Solution: Conectiva has released an advisory (CLA-2004:877) to address various issues including this issue in Mozilla. This advisory contains updated Mozilla packages (1.7.3) for Conectiva Linux 9 and 10. Please see the referenced advisory for more information. SCO has released an advisory SCOSA-2005.25 including updated packages to address this issue. Please see the referenced advisory for more information. Avaya has released an advisory that acknowledges this vulnerability for Avaya products. Fixes are not currently available; customers are advised to contact the vendor for further details regarding fix availability. Please see the referenced Avaya advisory at the following location for further details: http://support.avaya.com/japple/css/japple?temp.groupID=128450&temp.selectedFamily=128451&temp.selectedProduct=154235&temp.selectedBucket=126655&temp.feedbackState=askForFeedback&temp.documentID=198527&PAGE=avaya.css.CSSLvl1Detail&executeTransaction=avaya.css.UsageUpdate() RedHat has released advisory RHSA-2004:421-17 and fixes dealing with this issue for RedHat Enterprise Linux platforms. Please see the referenced advisory for further information. Mozilla has released upgrades for their Browser, Firefox and Thunderbird packages. Please see the referenced web advisory for more information. Slackware has released an advisory (SSA:2004-223-01) to address this issue. Please see the referenced advisory for more information. Mandrake Linux has released advisory MDKSA-2004:082 along with fixes addressing this issue. Please see the referenced advisory for further information. SGI has made available Patch 10095, correcting this vulnerability for systems running SGI Advanced Linux Environment 3: Patch 10095 is available from http://support.sgi.com/ and ftp://patches.sgi.com/support/free/security/patches/ProPack/3/ The individual RPMs from Patch 10095 are available from: ftp://oss.sgi.com/projects/sgi_propack/download/3/updates/RPMS ftp://oss.sgi.com/projects/sgi_propack/download/3/updates/SRPMS Gentoo has released advisory GLSA 200408-22 dealing with this issue. Users are advised to upgrade to the latest available version using the following sequence of commands: # emerge sync # emerge -pv your-version # emerge your-version Please see the referenced Gentoo advisory for more information. HP has released advisory "HPSBTU01063 SSRT4778 - rev.2 Mozilla Application Suite for HP Tru64 UNIX - Potential Overflows - Denial of Service - Unauthorized access" to address this and other issues. Please see the attached advisory for fix information. SuSE Linux has released advisory SUSE-SA:2004:036 along with fixes dealing with this issue. Please see the referenced advisory for more information. The Fedora Legacy project has released advisory FLSA-2004:2089 along with fixes to address multiple issues in RedHat Fedora Core 1, and RedHat Linux 7.3 and 9.0. Please see the referenced advisory for further information. Mozilla Thunderbird 0.7
Mozilla Thunderbird 0.7.1
Mozilla Thunderbird 0.7.2
Mozilla Firefox 0.8
Mozilla Firefox 0.9
Mozilla Firefox 0.9 rc
Mozilla Firefox 0.9.1
Mozilla Firefox 0.9.2
Mozilla Browser 0.9.9
Mozilla Browser 1.0
Mozilla Browser 1.0 RC1
Mozilla Browser 1.0 RC2
Mozilla Browser 1.0.1
Mozilla Browser 1.0.2
Mozilla Browser 1.1
Mozilla Browser 1.1 Alpha
Mozilla Browser 1.1 Beta
Mozilla Browser 1.2 Alpha
Mozilla Browser 1.2
Mozilla Browser 1.2 Beta
Mozilla Browser 1.2.1
Mozilla Browser 1.3
Mozilla Browser 1.3.1
Mozilla Browser 1.4
Mozilla Browser 1.4 a
Mozilla Browser 1.4 b
Mozilla Browser 1.4.1
Mozilla Browser 1.4.2
Mozilla Browser 1.5
Mozilla Browser 1.6
Mozilla Browser 1.7
Mozilla Browser 1.7 rc3
Mozilla Browser 1.7.1
|
|
|
Privacy Statement |