French Security Incident Response Team

FrSIRT   

      

   français French  anglais English

 
Vulnerability Notification Service
FrSIRT Private Exploit & PoC Codes Service
FrSIRT Partner Program
14-Day Free Trial
Contact FrSIRT Sales Dept.
 

Security Advisories
Linux Security Advisories
Virus and Threats Advisories
Latest Security News
Latest Zero Day Threats
Security Vulnerabilities and Advisories Search Engine
 

Report a security incident
Report a new vulnerability
Security Mailinglist
 

Our Company
FrSIRT in the News
Advertise on FrSIRT.COM
Security Researchers and Exploit Writers Jobs
Contact Us

Fedora Security Update Fixes Mozilla Firefox Multiple Command Execution Vulnerabilities


Title : Fedora Security Update Fixes Mozilla Firefox Multiple Command Execution Vulnerabilities
Advisory ID : FrSIRT/ADV-2006-5122
CVE ID : CVE-2006-6497 - CVE-2006-6498 - CVE-2006-6501 - CVE-2006-6502 - CVE-2006-6503 - CVE-2006-6504
Rated as : Critical 
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2006-12-22

Advisory Details

 
  Description
  Affected Products
  Solution
  References
Technical Description    Receive FrSIRT alerts in a Text format  Receive FrSIRT alerts in a PDF format  Receive FrSIRT alerts in an XML format  Receive FrSIRT notifications by SMS 

Fedora has released security updates to address multiple vulnerabilities identified in Mozilla Firefox [...]

Solution

Upgrade the affected packages :

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/6/

e1fe5ef2c1156a06026b08a9023c05c0f43fd375 SRPMS/firefox-1.5.0.9-1.fc6.src.rpm
e1fe5ef2c1156a06026b08a9023c05c0f43fd375 noarch/firefox-1.5.0.9-1.fc6.src.rpm
0e1d89ab8417844327bf5a503e44eabed4b2989d ppc/debug/firefox-debuginfo-1.5.0.9-1.fc6.ppc.rpm
4d7214e03d8db9f236073bed272f584f70217c05 ppc/firefox-devel-1.5.0.9-1.fc6.ppc.rpm
212166e344557d93cd340a52f246d7f17e28ac93 ppc/firefox-1.5.0.9-1.fc6.ppc.rpm
ca2fb6249c633971b319363b5940702a4049fe71 x86_64/firefox-devel-1.5.0.9-1.fc6.x86_64.rpm
da7254f374f59aba18d466f025c7145181ba6c9b x86_64/debug/firefox-debuginfo-1.5.0.9-1.fc6.x86_64.rpm
cfd3064e23d4c97c8bf0167c323b5163d2df97a0 x86_64/firefox-1.5.0.9-1.fc6.x86_64.rpm
03cc7fcdd387fa443b7d2e2b2e199c5af1e98ffd i386/firefox-devel-1.5.0.9-1.fc6.i386.rpm
1b01573757dfddb260ce4a6f3e3e4e7e2e261f79 i386/debug/firefox-debuginfo-1.5.0.9-1.fc6.i386.rpm
156f9deca5f95a0dbd6770a11ddab7ecb88b6c29 i386/firefox-1.5.0.9-1.fc6.i386.rpm

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/

7adb054fa9d328c994da34b00c1e39ab3861ec3d SRPMS/firefox-1.5.0.9-1.fc5.src.rpm
7adb054fa9d328c994da34b00c1e39ab3861ec3d noarch/firefox-1.5.0.9-1.fc5.src.rpm
6ef57784517cccd2b6107a72ac25ddaf2ddedd2c ppc/debug/firefox-debuginfo-1.5.0.9-1.fc5.ppc.rpm
cd587d1449885a232e7255d7147baf2497817cda ppc/firefox-1.5.0.9-1.fc5.ppc.rpm
5b7346c702bc999c0a4300ad6dc30dd04d5e212c x86_64/debug/firefox-debuginfo-1.5.0.9-1.fc5.x86_64.rpm
9b82c1c8df42ce68bb9301fa422262a8ed893985 x86_64/firefox-1.5.0.9-1.fc5.x86_64.rpm
a274f39e5fadc562eca0ad747c670bba6bc20c9d i386/debug/firefox-debuginfo-1.5.0.9-1.fc5.i386.rpm
f4deed8b6f417d2003216070088362ff666b5206 i386/firefox-1.5.0.9-1.fc5.i386.rpm

ChangeLog

2006-12-22 : Initial release

Vulnerability Management

Subscribe to FrSIRT VNS and receive real-time e-mail and SMS alerts when new vulnerabilities, exploits, or patches relevant to your systems and network configurations are available.

Feedback

If you have additional information or corrections for this security advisory please submit them via our contact form or by email to updates@frsirt.com.


 
 

Search

      

Mailinglist

    
 

Mozilla Products Code Execution and Security Bypass Vulnerabilities

Mozilla Firefox Shortcut Handlingg Information Disclosure Vulnerability

Mozilla Products Code Execution and Security Bypass Vulnerabilities

Mozilla Firefox for Mac OS X GIF Rendering Code Execution Vulnerability

Mozilla Products Remote Code Execution and Security Bypass Issues

Mozilla Products Code Execution and Injection Vulnerabilities

Mozilla JavaScript Garbage Collector Code Execution Vulnerability

Microsoft XML Core Services Multiple Remote Vulnerabilities (MS08-069)

Microsoft Windows SMB Credential Reflection Vulnerability (MS08-068)

Microsoft Windows Server Service Vulnerability (MS08-067)

Microsoft Windows "afd.sys" Privilege Escalation Vulnerability (MS08-066)

Microsoft Windows MSMQ Code Execution Vulnerability (MS08-065)

Microsoft Windows VADs Privilege Escalation Vulnerability (MS08-064)

Microsoft Windows SMB Code Execution Vulnerability (MS08-063)

Apple iPhone and iPod touch Multiple Code Execution Vulnerabilities

Apple Safari Code Execution and Security Bypass Vulnerabilities

Apple iLife and Aperture Image Handling Code Execution Vulnerabilities

Apple Mac OS X Code Execution and Security Bypass Vulnerabilities

Apple TV Multiple File Processing Code Execution Vulnerabilities

Apple Mac OS X Code Execution and Security Bypass Vulnerabilities

Apple iPhone Code Execution and Security Bypass Vulnerabilities

Copyright 2003-2008 © FrSIRT.COM - Privacy Policy