Oval Definition:oval:com.redhat.rhsa:def:20100556
Revision Date:2010-07-24Version:638
Title:RHSA-2010:0556: firefox security update (Critical)
Description:Mozilla Firefox is an open source web browser. XULRunner provides the XUL Runtime environment for Mozilla Firefox.

An invalid free flaw was found in Firefox's plugin handler. Malicious web content could result in an invalid memory pointer being freed, causing Firefox to crash or, potentially, execute arbitrary code with the privileges of the user running the Firefox application. (CVE-2010-2755)

All Firefox users should upgrade to these updated packages, which contain a backported patch that corrects this issue. After installing the update, Firefox must be restarted for the changes to take effect.
Family:unixClass:patch
Status:Reference(s):CVE-2010-2755
RHSA-2010:0556
RHSA-2010:0556-01
RHSA-2010:0556-01
Platform(s):Red Hat Enterprise Linux 5
Product(s):
Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • xulrunner is earlier than 0:1.9.2.7-3.el5
  • AND xulrunner is signed with Red Hat redhatrelease2 key
  • xulrunner-devel is earlier than 0:1.9.2.7-3.el5
  • AND xulrunner-devel is signed with Red Hat redhatrelease2 key
  • firefox is earlier than 0:3.6.7-3.el5
  • AND firefox is signed with Red Hat redhatrelease2 key
  • BACK