Mozilla Firefox: Various vulnerabilities

Security Team  Contact Address

Updated March 04, 2005

1.  Gentoo Linux Security Advisory

Version Information

Advisory Reference GLSA 200503-10 / Firefox
Release Date March 04, 2005
Latest Revision March 04, 2005: 01
Impact normal
Exploitable remote and local
Package Vulnerable versions Unaffected versions Architecture(s)
www-client/mozilla-firefox < 1.0.1 >= 1.0.1 All supported architectures
www-client/mozilla-firefox-bin < 1.0.1 >= 1.0.1 All supported architectures

Related bugreports: #83267

Synopsis

Mozilla Firefox is vulnerable to a local file deletion issue and to various issues allowing to trick the user into trusting fake web sites or interacting with privileged content.

2.  Impact Information

Background

Mozilla Firefox is the popular next-generation browser from the Mozilla project.

Description

The following vulnerabilities were found and fixed in Mozilla Firefox:

Impact

3.  Resolution Information

Workaround

There is no known workaround at this time.

Resolution

All Firefox users should upgrade to the latest version:

Code Listing 3.1: Resolution

# emerge --sync
# emerge --ask --oneshot --verbose ">=www-client/mozilla-firefox-1.0.1"

All Firefox binary users should upgrade to the latest version:

Code Listing 3.2: Resolution

# emerge --sync
# emerge --ask --oneshot --verbose ">=www-client/mozilla-firefox-bin-1.0.1"

4.  References