Mozilla Firefox: Multiple vulnerabilities

Security Team  Contact Address

Updated July 15, 2005

1.  Gentoo Linux Security Advisory

Version Information

Advisory Reference GLSA 200507-14 / mozilla
Release Date July 15, 2005
Latest Revision July 15, 2005: 01
Impact normal
Exploitable remote
Package Vulnerable versions Unaffected versions Architecture(s)
www-client/mozilla-firefox < 1.0.5 >= 1.0.5 All supported architectures
www-client/mozilla-firefox-bin < 1.0.5 >= 1.0.5 All supported architectures

Related bugreports: #95199

Synopsis

Several vulnerabilities in Mozilla Firefox allow attacks ranging from execution of script code with elevated privileges to information leak.

2.  Impact Information

Background

Mozilla Firefox is the next-generation web browser from the Mozilla project.

Description

The following vulnerabilities were found and fixed in Mozilla Firefox:

Impact

A remote attacker could craft malicious web pages that would leverage these issues to inject and execute arbitrary script code with elevated privileges, steal cookies or other information from web pages, or spoof content.

3.  Resolution Information

Workaround

There are no known workarounds for all the issues at this time.

Resolution

All Mozilla Firefox users should upgrade to the latest version:

Code Listing 3.1: Resolution

# emerge --sync
# emerge --ask --oneshot --verbose ">=www-client/mozilla-firefox-1.0.5"

All Mozilla Firefox binary users should upgrade to the latest version:

Code Listing 3.2: Resolution

# emerge --sync
# emerge --ask --oneshot --verbose ">=www-client/mozilla-firefox-bin-1.0.5"

4.  References