Oval Definition:oval:com.redhat.rhsa:def:20100681
Revision Date:2010-09-08Version:648
Title:RHSA-2010:0681: firefox security update (Critical)
Description:Mozilla Firefox is an open source web browser. XULRunner provides the XUL Runtime environment for Mozilla Firefox.

  • Several flaws were found in the processing of malformed web content. A web page containing malicious content could cause Firefox to crash or, potentially, execute arbitrary code with the privileges of the user running Firefox. (CVE-2010-3169, CVE-2010-2762)

  • Several use-after-free and dangling pointer flaws were found in Firefox. A web page containing malicious content could cause Firefox to crash or, potentially, execute arbitrary code with the privileges of the user running Firefox. (CVE-2010-2760, CVE-2010-2766, CVE-2010-2767, CVE-2010-3167, CVE-2010-3168)

  • Multiple buffer overflow flaws were found in Firefox. A web page containing malicious content could cause Firefox to crash or, potentially, execute arbitrary code with the privileges of the user running Firefox. (CVE-2010-2765, CVE-2010-3166)

  • Multiple cross-site scripting (XSS) flaws were found in Firefox. A web page containing malicious content could cause Firefox to run JavaScript code with the permissions of a different website. (CVE-2010-2768, CVE-2010-2769)

  • A flaw was found in the Firefox XMLHttpRequest object. A remote site could use this flaw to gather information about servers on an internal private network. (CVE-2010-2764)

    For technical details regarding these flaws, refer to the Mozilla security advisories for Firefox 3.6.9. You can find a link to the Mozilla advisories in the References section of this erratum.

    Note: After installing this update, Firefox will fail to connect (with HTTPS) to a server using the SSL DHE (Diffie-Hellman Ephemeral) key exchange if the server's ephemeral key is too small. Connecting to such servers is a security risk as an ephemeral key that is too small makes the SSL connection vulnerable to attack. Refer to the Solution section for further information.

    All Firefox users should upgrade to these updated packages, which contain Firefox version 3.6.9, which corrects these issues. After installing the update, Firefox must be restarted for the changes to take effect.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2010-2760
    CVE-2010-2762
    CVE-2010-2764
    CVE-2010-2765
    CVE-2010-2766
    CVE-2010-2767
    CVE-2010-2768
    CVE-2010-2769
    CVE-2010-3166
    CVE-2010-3167
    CVE-2010-3168
    CVE-2010-3169
    RHSA-2010:0681
    RHSA-2010:0681-01
    RHSA-2010:0681-01
    Platform(s):Red Hat Enterprise Linux 4
    Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • firefox is earlier than 0:3.6.9-1.el4
  • AND firefox is signed with Red Hat redhatrelease2 key
  • nspr is earlier than 0:4.8.6-1.el4
  • AND nspr is signed with Red Hat redhatrelease2 key
  • nspr-devel is earlier than 0:4.8.6-1.el4
  • AND nspr-devel is signed with Red Hat redhatrelease2 key
  • nss is earlier than 0:3.12.7-1.el4
  • AND nss is signed with Red Hat redhatrelease2 key
  • nss-devel is earlier than 0:3.12.7-1.el4
  • AND nss-devel is signed with Red Hat redhatrelease2 key
  • nss-tools is earlier than 0:3.12.7-1.el4
  • AND nss-tools is signed with Red Hat redhatrelease2 key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • xulrunner is earlier than 0:1.9.2.9-1.el5
  • AND xulrunner is signed with Red Hat redhatrelease2 key
  • xulrunner-devel is earlier than 0:1.9.2.9-1.el5
  • AND xulrunner-devel is signed with Red Hat redhatrelease2 key
  • firefox is earlier than 0:3.6.9-2.el5
  • AND firefox is signed with Red Hat redhatrelease2 key
  • nspr is earlier than 0:4.8.6-1.el5
  • AND nspr is signed with Red Hat redhatrelease2 key
  • nspr-devel is earlier than 0:4.8.6-1.el5
  • AND nspr-devel is signed with Red Hat redhatrelease2 key
  • nss is earlier than 0:3.12.7-2.el5
  • AND nss is signed with Red Hat redhatrelease2 key
  • nss-devel is earlier than 0:3.12.7-2.el5
  • AND nss-devel is signed with Red Hat redhatrelease2 key
  • nss-pkcs11-devel is earlier than 0:3.12.7-2.el5
  • AND nss-pkcs11-devel is signed with Red Hat redhatrelease2 key
  • nss-tools is earlier than 0:3.12.7-2.el5
  • AND nss-tools is signed with Red Hat redhatrelease2 key
  • BACK