Oval Definition:oval:com.redhat.rhsa:def:20050277
Revision Date:2005-03-04Version:502
Title:RHSA-2005:277: mozilla security update (Critical)
Description:Mozilla is an open source Web browser, advanced email and newsgroup client, IRC chat client, and HTML editor.

A bug was found in the Mozilla string handling functions. If a malicious website is able to exhaust a system's memory, it becomes possible to execute arbitrary code. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2005-0255 to this issue.

Please note that other security issues have been found that affect Mozilla. These other issues have a lower severity, and are therefore planned to be released as additional security updates in the future.

Users of Mozilla should upgrade to these updated packages, which contain a backported patch and are not vulnerable to these issues.
Family:unixClass:patch
Status:Reference(s):CVE-2005-0255
RHSA-2005:277-01
Platform(s):Red Hat Enterprise Linux 4
Product(s):
Definition Synopsis
  • Red Hat Enterprise Linux 4 is installed
  • AND Package Information
  • mozilla-js-debugger is earlier than 37:1.7.3-19.EL4
  • AND mozilla-js-debugger is signed with Red Hat master key
  • OR
  • mozilla-mail is earlier than 37:1.7.3-19.EL4
  • AND mozilla-mail is signed with Red Hat master key
  • OR
  • mozilla-chat is earlier than 37:1.7.3-19.EL4
  • AND mozilla-chat is signed with Red Hat master key
  • OR
  • mozilla-nss-devel is earlier than 37:1.7.3-19.EL4
  • AND mozilla-nss-devel is signed with Red Hat master key
  • OR
  • mozilla is earlier than 37:1.7.3-19.EL4
  • AND mozilla is signed with Red Hat master key
  • OR
  • mozilla-nspr-devel is earlier than 37:1.7.3-19.EL4
  • AND mozilla-nspr-devel is signed with Red Hat master key
  • OR
  • mozilla-nspr is earlier than 37:1.7.3-19.EL4
  • AND mozilla-nspr is signed with Red Hat master key
  • OR
  • mozilla-dom-inspector is earlier than 37:1.7.3-19.EL4
  • AND mozilla-dom-inspector is signed with Red Hat master key
  • OR
  • mozilla-devel is earlier than 37:1.7.3-19.EL4
  • AND mozilla-devel is signed with Red Hat master key
  • OR
  • mozilla-nss is earlier than 37:1.7.3-19.EL4
  • AND mozilla-nss is signed with Red Hat master key
  • BACK