Oval Definition:oval:com.redhat.rhsa:def:20060329
Revision Date:2006-04-25Version:646
Title:RHSA-2006:0329: mozilla security update (Critical)
Description:Mozilla is an open source Web browser, advanced email and newsgroup client, IRC chat client, and HTML editor.

  • Several bugs were found in the way Mozilla processes malformed javascript. A malicious web page could modify the content of a different open web page, possibly stealing sensitive information or conducting a cross-site scripting attack. (CVE-2006-1731, CVE-2006-1732, CVE-2006-1741)

  • Several bugs were found in the way Mozilla processes certain javascript actions. A malicious web page could execute arbitrary javascript instructions with the permissions of "chrome", allowing the page to steal sensitive information or install browser malware. (CVE-2006-1727, CVE-2006-1728, CVE-2006-1733, CVE-2006-1734, CVE-2006-1735, CVE-2006-1742)

  • Several bugs were found in the way Mozilla processes malformed web pages. A carefully crafted malicious web page could cause the execution of arbitrary code as the user running Mozilla. (CVE-2006-0748, CVE-2006-0749, CVE-2006-1730, CVE-2006-1737, CVE-2006-1738, CVE-2006-1739, CVE-2006-1790)

  • A bug was found in the way Mozilla displays the secure site icon. If a browser is configured to display the non-default secure site modal warning dialog, it may be possible to trick a user into believing they are viewing a secure site. (CVE-2006-1740)

  • A bug was found in the way Mozilla allows javascript mutation events on "input" form elements. A malicious web page could be created in such a way that when a user submits a form, an arbitrary file could be uploaded to the attacker. (CVE-2006-1729)

  • A bug was found in the way Mozilla executes in-line mail forwarding. If a user can be tricked into forwarding a maliciously crafted mail message as in-line content, it is possible for the message to execute javascript with the permissions of "chrome". (CVE-2006-0884)

    Users of Mozilla are advised to upgrade to these updated packages containing Mozilla version 1.7.13 which corrects these issues.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2006-0748
    CVE-2006-0749
    CVE-2006-0884
    CVE-2006-1724
    CVE-2006-1727
    CVE-2006-1728
    CVE-2006-1729
    CVE-2006-1730
    CVE-2006-1731
    CVE-2006-1732
    CVE-2006-1733
    CVE-2006-1734
    CVE-2006-1735
    CVE-2006-1737
    CVE-2006-1738
    CVE-2006-1739
    CVE-2006-1740
    CVE-2006-1741
    CVE-2006-1742
    CVE-2006-1790
    RHSA-2006:0329
    RHSA-2006:0329-02
    RHSA-2006:0329-02
    Platform(s):Red Hat Enterprise Linux 3
    Red Hat Enterprise Linux 4
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • devhelp-devel is earlier than 0:0.9.2-2.4.8
  • AND devhelp-devel is signed with Red Hat master key
  • devhelp is earlier than 0:0.9.2-2.4.8
  • AND devhelp is signed with Red Hat master key
  • Definition Synopsis
  • Release Information
  • Red Hat Enterprise Linux 3 is installed
  • AND
  • mozilla is earlier than 37:1.7.13-1.1.3.1
  • AND mozilla is signed with Red Hat master key
  • mozilla-chat is earlier than 37:1.7.13-1.1.3.1
  • AND mozilla-chat is signed with Red Hat master key
  • mozilla-devel is earlier than 37:1.7.13-1.1.3.1
  • AND mozilla-devel is signed with Red Hat master key
  • mozilla-dom-inspector is earlier than 37:1.7.13-1.1.3.1
  • AND mozilla-dom-inspector is signed with Red Hat master key
  • mozilla-js-debugger is earlier than 37:1.7.13-1.1.3.1
  • AND mozilla-js-debugger is signed with Red Hat master key
  • mozilla-mail is earlier than 37:1.7.13-1.1.3.1
  • AND mozilla-mail is signed with Red Hat master key
  • mozilla-nspr is earlier than 37:1.7.13-1.1.3.1
  • AND mozilla-nspr is signed with Red Hat master key
  • mozilla-nspr-devel is earlier than 37:1.7.13-1.1.3.1
  • AND mozilla-nspr-devel is signed with Red Hat master key
  • mozilla-nss is earlier than 37:1.7.13-1.1.3.1
  • AND mozilla-nss is signed with Red Hat master key
  • mozilla-nss-devel is earlier than 37:1.7.13-1.1.3.1
  • AND mozilla-nss-devel is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • devhelp is earlier than 0:0.9.2-2.4.8
  • AND devhelp is signed with Red Hat master key
  • devhelp-devel is earlier than 0:0.9.2-2.4.8
  • AND devhelp-devel is signed with Red Hat master key
  • mozilla is earlier than 37:1.7.13-1.4.1
  • AND mozilla is signed with Red Hat master key
  • mozilla-chat is earlier than 37:1.7.13-1.4.1
  • AND mozilla-chat is signed with Red Hat master key
  • mozilla-devel is earlier than 37:1.7.13-1.4.1
  • AND mozilla-devel is signed with Red Hat master key
  • mozilla-dom-inspector is earlier than 37:1.7.13-1.4.1
  • AND mozilla-dom-inspector is signed with Red Hat master key
  • mozilla-js-debugger is earlier than 37:1.7.13-1.4.1
  • AND mozilla-js-debugger is signed with Red Hat master key
  • mozilla-mail is earlier than 37:1.7.13-1.4.1
  • AND mozilla-mail is signed with Red Hat master key
  • mozilla-nspr is earlier than 37:1.7.13-1.4.1
  • AND mozilla-nspr is signed with Red Hat master key
  • mozilla-nspr-devel is earlier than 37:1.7.13-1.4.1
  • AND mozilla-nspr-devel is signed with Red Hat master key
  • mozilla-nss is earlier than 37:1.7.13-1.4.1
  • AND mozilla-nss is signed with Red Hat master key
  • mozilla-nss-devel is earlier than 37:1.7.13-1.4.1
  • AND mozilla-nss-devel is signed with Red Hat master key
  • Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • devhelp is earlier than 0:0.9.2-2.4.8
  • AND devhelp is signed with Red Hat redhatrelease2 key
  • devhelp-devel is earlier than 0:0.9.2-2.4.8
  • AND devhelp-devel is signed with Red Hat redhatrelease2 key
  • BACK