Oval Definition:oval:com.redhat.rhsa:def:20050038
Revision Date:2005-01-13Version:504
Title:RHSA-2005:038: mozilla security update (Low)
Description:Mozilla is an open source Web browser, advanced email and newsgroup client, IRC chat client, and HTML editor.

iSEC Security Research has discovered a buffer overflow bug in the way Mozilla handles NNTP URLs. If a user visits a malicious web page or is convinced to click on a malicious link, it may be possible for an attacker to execute arbitrary code on the victim's machine. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-1316 to this issue.

Users of Mozilla should upgrade to these updated packages, which contain backported patches and are not vulnerable to these issues.
Family:unixClass:patch
Status:Reference(s):CVE-2004-1316
RHSA-2005:038-03
Platform(s):Red Hat Enterprise Linux 3
Product(s):
Definition Synopsis
  • Red Hat Enterprise Linux 3 is installed
  • AND Package Information
  • mozilla-js-debugger is earlier than 37:1.4.3-3.0.7
  • AND mozilla-js-debugger is signed with Red Hat master key
  • OR
  • mozilla-mail is earlier than 37:1.4.3-3.0.7
  • AND mozilla-mail is signed with Red Hat master key
  • OR
  • mozilla-chat is earlier than 37:1.4.3-3.0.7
  • AND mozilla-chat is signed with Red Hat master key
  • OR
  • mozilla-nss-devel is earlier than 37:1.4.3-3.0.7
  • AND mozilla-nss-devel is signed with Red Hat master key
  • OR
  • mozilla is earlier than 37:1.4.3-3.0.7
  • AND mozilla is signed with Red Hat master key
  • OR
  • mozilla-dom-inspector is earlier than 37:1.4.3-3.0.7
  • AND mozilla-dom-inspector is signed with Red Hat master key
  • OR
  • mozilla-nspr-devel is earlier than 37:1.4.3-3.0.7
  • AND mozilla-nspr-devel is signed with Red Hat master key
  • OR
  • mozilla-nspr is earlier than 37:1.4.3-3.0.7
  • AND mozilla-nspr is signed with Red Hat master key
  • OR
  • mozilla-devel is earlier than 37:1.4.3-3.0.7
  • AND mozilla-devel is signed with Red Hat master key
  • OR
  • mozilla-nss is earlier than 37:1.4.3-3.0.7
  • AND mozilla-nss is signed with Red Hat master key
  • BACK