MozillaFirefoxMozillaFirefox: Update to 2.0.0.17MozillaFirefox: Update auf 2.0.0.17This update brings MozillaFirefox to version 2.0.0.17 to
fix bugs and security issues:
MFSA 2008-45 / CVE-2008-4069: XBM image uninitialized
memory reading
MFSA 2008-44 / CVE-2008-4067 / CVE-2008-4068: resource:
traversal vulnerabilities
MFSA 2008-43: BOM characters stripped from JavaScript
before execution CVE-2008-4065: Stripped BOM characters bug
CVE-2008-4066: HTML escaped low surrogates bug
MFSA 2008-42 Crashes with evidence of memory corruption
(rv:1.9.0.2/1.8.1.17): CVE-2008-4061: Jesse Ruderman
reported a crash in the layout engine. CVE-2008-4062: Igor
Bukanov, Philip Taylor, Georgi Guninski, and Antoine Labour
reported crashes in the JavaScript engine. CVE-2008-4063:
Jesse Ruderman, Bob Clary, and Martijn Wargers reported
crashes in the layout engine which only affected Firefox 3.
CVE-2008-4064: David Maciejak and Drew Yao reported crashes
in graphics rendering which only affected Firefox 3.
MFSA 2008-41 Privilege escalation via XPCnativeWrapper
pollution CVE-2008-4058: XPCnativeWrapper pollution bugs
CVE-2008-4059: XPCnativeWrapper pollution (Firefox 2)
CVE-2008-4060: Documents without script handling objects
MFSA 2008-40 / CVE-2008-3837: Forced mouse drag
MFSA 2008-39 / CVE-2008-3836: Privilege escalation using
feed preview page and XSS flaw
MFSA 2008-38 / CVE-2008-3835:
nsXMLDocument::OnChannelRedirect() same-origin violation
MFSA 2008-37 / CVE-2008-0016: UTF-8 URL stack buffer
overflow
For more details:
http://www.mozilla.org/security/known-vulnerabilities/firefo
x20.html
Dieses Update bringt MozillaFirefox auf 2.0.0.17 und behebt
Sicherheitsprobleme und andere Fehler:
MFSA 2008-45 / CVE-2008-4069: XBM image uninitialized
memory reading
MFSA 2008-44 / CVE-2008-4067 / CVE-2008-4068: resource:
traversal vulnerabilities
MFSA 2008-43: BOM characters stripped from JavaScript
before execution CVE-2008-4065: Stripped BOM characters bug
CVE-2008-4066: HTML escaped low surrogates bug
MFSA 2008-42 Crashes with evidence of memory corruption
(rv:1.9.0.2/1.8.1.17): CVE-2008-4061: Jesse Ruderman
reported a crash in the layout engine. CVE-2008-4062: Igor
Bukanov, Philip Taylor, Georgi Guninski, and Antoine Labour
reported crashes in the JavaScript engine. CVE-2008-4063:
Jesse Ruderman, Bob Clary, and Martijn Wargers reported
crashes in the layout engine which only affected Firefox 3.
CVE-2008-4064: David Maciejak and Drew Yao reported crashes
in graphics rendering which only affected Firefox 3.
MFSA 2008-41 Privilege escalation via XPCnativeWrapper
pollution CVE-2008-4058: XPCnativeWrapper pollution bugs
CVE-2008-4059: XPCnativeWrapper pollution (Firefox 2)
CVE-2008-4060: Documents without script handling objects
MFSA 2008-40 / CVE-2008-3837: Forced mouse drag
MFSA 2008-39 / CVE-2008-3836: Privilege escalation using
feed preview page and XSS flaw
MFSA 2008-38 / CVE-2008-3835:
nsXMLDocument::OnChannelRedirect() same-origin violation
MFSA 2008-37 / CVE-2008-0016: UTF-8 URL stack buffer
overflow
For more details:
http://www.mozilla.org/security/known-vulnerabilities/firefo
x20.html
securityMozillaFirefoxi586580b75f904682971f4b07a0a28e113f2b213e081af98e54dcc85713b9a3dd3a7f0f2ebda98063e6eebb6d0e92b6b556af2a3bc99fb16d7b67312c473MozillaFirefoxppc33ae878eb83fe92d55b00341cb51303a7528ea66ba6c8527c1fbad5814ac6ed77804283de7e0aa379ffd6e9eaab39da6c8c93318c01591896c217b50MozillaFirefoxx86_647886d892f4cac3401a43cd1eb0d6e45d55672d096fe9240fb752bb7a17568c972be983fd273ea5866136c0c22d9aaf9ebab165c7ef863e97b2f8a6c6MozillaFirefox-translationsi5866d3baa62ae26f1978b51922f2b1165cc9217644d0672d6d7d53c6eb8fdc1b13e0e1559969bc66c5fe787eebfdb6badae1694abd8746c60f908baf7c8MozillaFirefox-translationsppc8be6e421cc4d0264787067b553caa66a8ab5d4e963e8a2b2637ad98d7cb9d9bb0beb36949c6622c2fcc9571673a56e3ef8bb334c4a9f56aeee198e13MozillaFirefox-translationsx86_64e26db79aeb1c433115a10968991124bc38c5b81c0f18233ed72b4a0924401efa840f241c45e5a619cad619d00cc2a53d68ed16d316c9d96ebbdf1f34