French Security Incident Response Team

FrSIRT   

      

   français French  anglais English

 
Vulnerability Notification Service
FrSIRT Partner Program
14-Day Free Trial
Contact FrSIRT Sales Dept.
 

Security Advisories
Linux Security Advisories
Virus and Threats Advisories
Latest Security News
Latest Zero Day Threats
Advisories and vulnerabilities by Vendor
Advisories and vulnerabilities by Keyword
 

Report a security incident
Report a new vulnerability
Security Mailinglist
 

Our Company
FrSIRT in the News
Advertise on FrSIRT.COM
Security Researchers and Exploit Writers Jobs
Contact Us

Fedora Security Update Fixes Firefox Command Execution Vulnerabilities


Title : Fedora Security Update Fixes Firefox Command Execution Vulnerabilities
Advisory ID : FrSIRT/ADV-2007-3604
CVE ID : CVE-2007-1095 - CVE-2007-2292 - CVE-2007-3511 - CVE-2007-5334 - CVE-2007-5335 - CVE-2007-5337 - CVE-2007-5338 - CVE-2007-5339 - CVE-2007-5340
Rated as : Critical 
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2007-10-25

Advisory Details

 
  Description
  Affected Products
  Solution
  References
Technical Description    Receive FrSIRT alerts in a Text format  Receive FrSIRT alerts in a PDF format  Receive FrSIRT alerts in an XML format  Receive FrSIRT notifications by SMS 

Multiple vulnerabilities have been identified in Fedora, which could be exploited by attackers to bypass security restrictions, disclose sensitive information, cause a denial of service or take complete control of an affected system [...]

Solution

Upgrade the affected packages :

1bbc7b83d27d95ec77d665b99d256f04329ab5d9 firefox-2.0.0.8-1.fc7.ppc64.rpm
57d2065b0223d485231a208000b6162f08de6fa6 firefox-devel-2.0.0.8-1.fc7.ppc64.rpm
a3a89afb6dfbba3079e6f13a8839d08977aa529f firefox-debuginfo-2.0.0.8-1.fc7.ppc64.rpm
6665baabb62fbc18b39bc732b84162300477dc1f firefox-debuginfo-2.0.0.8-1.fc7.i386.rpm
2e08c7cfa646b091c3707927571f056da19fb477 firefox-devel-2.0.0.8-1.fc7.i386.rpm
b1e205773b567ca096add51a64974a2674940b51 firefox-2.0.0.8-1.fc7.i386.rpm
b5459a7fbf2a662e62f7bf89f7ba61fb36b93d55 firefox-2.0.0.8-1.fc7.x86_64.rpm
0a1f12f771f1351b00e0b7af74479e1ceefd7c40 firefox-debuginfo-2.0.0.8-1.fc7.x86_64.rpm
9d4ae526f2f4281caf8b4fcbca5b440463942572 firefox-devel-2.0.0.8-1.fc7.x86_64.rpm
15f505d67a4d2bb231aa9d64a3edb00cbd10bffc firefox-2.0.0.8-1.fc7.ppc.rpm
0345954dbf90f7f7907a1c79728cefaeefc097a7 firefox-debuginfo-2.0.0.8-1.fc7.ppc.rpm
8af4bccd1acfbbd4bead83098bed48c759fb53e1 firefox-devel-2.0.0.8-1.fc7.ppc.rpm
ee7856d134b948c98a439a3fa23b306c49349f07 firefox-2.0.0.8-1.fc7.src.rpm
1174e49539962975aec0b809b7156259b936bc55 epiphany-extensions-debuginfo-2.18.3-4.ppc64.rpm
6dcd9722650050ddd48d7390ea2eb657c0aac56a epiphany-extensions-2.18.3-4.ppc64.rpm
24e79112ac00e186e3252fa2e346d25131929c78 epiphany-extensions-debuginfo-2.18.3-4.i386.rpm
47534f98eac4aab3377486d27efed705181d6ae2 epiphany-extensions-2.18.3-4.i386.rpm
299756e351a678ac825a815bd5ce6c3e3ffb8077 epiphany-extensions-2.18.3-4.x86_64.rpm
6a8ef5d759386c762a85c617b4c917b0e5e9c450 epiphany-extensions-debuginfo-2.18.3-4.x86_64.rpm
186de278d3b1a0bd094a8a8e384564b246477ea7 epiphany-extensions-2.18.3-4.ppc.rpm
987757848c23fdce032026f841f6fd9e673d2a68 epiphany-extensions-debuginfo-2.18.3-4.ppc.rpm
0c4667c1c05f1d4cfdb3670e3bbfafcffd9d87cb epiphany-extensions-2.18.3-4.src.rpm
dae9d3d304156279c4c13f55ec5bb7be57678a09 blam-1.8.3-7.fc7.i386.rpm
6fbc063d1bbc6e7b91b3b8822e062718f0774f15 blam-debuginfo-1.8.3-7.fc7.i386.rpm
c91e3d209dc285eb42e3eb333450b6e103a5ee38 blam-1.8.3-7.fc7.x86_64.rpm
50d74e32ecd6c6a0fbd1a144032967f68a7b51d4 blam-debuginfo-1.8.3-7.fc7.x86_64.rpm
b1c75f5655f48ffcf6aec6606a1301fd3d7f3f56 blam-debuginfo-1.8.3-7.fc7.ppc.rpm
9e03a392b85e63336157c4b6c9258eedff4eda0f blam-1.8.3-7.fc7.ppc.rpm
87620d7f9e9bcb881a4ec879a148e44bf5dd3a14 blam-1.8.3-7.fc7.src.rpm
fd68ddee007946c1dfc75bdef967fe7d95667079 chmsee-debuginfo-1.0.0-1.25.fc7.ppc64.rpm
b38bfd71318aa9ef7f4009880376736205bb5a80 chmsee-1.0.0-1.25.fc7.ppc64.rpm
a69bb40b4fe709e18027551954c2c983e3312273 chmsee-1.0.0-1.25.fc7.i386.rpm
b49c1727578fc8eabbb11de1d3b5482e7b9cb4b7 chmsee-debuginfo-1.0.0-1.25.fc7.i386.rpm
b6f2693963ebdae67c7efe604c50fbcd4d0e0a19 chmsee-debuginfo-1.0.0-1.25.fc7.x86_64.rpm
e7c5062bf5119f255a894e3a64b17d1ad4b8f01f chmsee-1.0.0-1.25.fc7.x86_64.rpm
1e6456b103081927d80aabfcb548a9c3e2499024 chmsee-1.0.0-1.25.fc7.ppc.rpm
607b21434bf04a9b7df1a20d1777e0da25e86f34 chmsee-debuginfo-1.0.0-1.25.fc7.ppc.rpm
04cd2ddf8717e8375c8f23a5edc71efccee571ab chmsee-1.0.0-1.25.fc7.src.rpm
7e37d82968e514aa76437e1769cbf5a0ae6124cd galeon-debuginfo-2.0.3-12.fc7.ppc64.rpm
df1fbb131f023818e89258424f06a0d1732b5f68 galeon-2.0.3-12.fc7.ppc64.rpm
6262f13982048f6135ef71d913f94f87bf8f54a3 galeon-2.0.3-12.fc7.i386.rpm
f66cd663ca0d4074dbb155c139249c120c04f83d galeon-debuginfo-2.0.3-12.fc7.i386.rpm
01bd6c5adfc381988708935b36122458cbc00810 galeon-debuginfo-2.0.3-12.fc7.x86_64.rpm
ed452d62facf245c5c2b3277a8627012bc7a488e galeon-2.0.3-12.fc7.x86_64.rpm
393d99913f850df9659a738ad800475aa4116995 galeon-debuginfo-2.0.3-12.fc7.ppc.rpm
d022724595d67132b2d24a6326120f683b29a865 galeon-2.0.3-12.fc7.ppc.rpm
2a520b06b32091bbf963e56a5b344aee9ba2bf97 galeon-2.0.3-12.fc7.src.rpm
d5b76b9329d102b75b7c502882f0b2dace2a089e Miro-debuginfo-0.9.8.1-4.fc7.ppc64.rpm
53060aa170d6c97e4880760c5e5e74b25a162105 Miro-0.9.8.1-4.fc7.ppc64.rpm
7ff3e927d4c9ae4c2ca08151c4135874d4ea9cb0 Miro-debuginfo-0.9.8.1-4.fc7.i386.rpm
e1dd21a54e9e2fb44ad749baffbb86f85e8ab464 Miro-0.9.8.1-4.fc7.i386.rpm
c3d1f2a8122f8eefe608c281fc88f1d495ed3191 Miro-debuginfo-0.9.8.1-4.fc7.x86_64.rpm
f2e640140ba1ea48f508155bb92e21a5674dad8d Miro-0.9.8.1-4.fc7.x86_64.rpm
ed34560ad3fae35f8f94edf0ad102a4508cc5abb Miro-0.9.8.1-4.fc7.ppc.rpm
61daeed029346f47d2ace83e4263740e8a1907f6 Miro-debuginfo-0.9.8.1-4.fc7.ppc.rpm
2586b3b71c4bae2f8b9d8d471ff889235aecb038 Miro-0.9.8.1-4.fc7.src.rpm
7889c45eeedc1963b6c7e9b86535e6ade2388f3d openvrml-0.16.6-3.fc7.ppc64.rpm
58a39052737a774a65c310a8bc3b6c193cd1e642 openvrml-player-0.16.6-3.fc7.ppc64.rpm
1af6060587b4cad36119262b9a70e95696e276b4 openvrml-devel-0.16.6-3.fc7.ppc64.rpm
48557753db6adb723bd1a43fc6be48c2d53383dc openvrml-gl-0.16.6-3.fc7.ppc64.rpm
61bd639ce0a0a96d87de46c893c206f82c8dc8fe openvrml-debuginfo-0.16.6-3.fc7.ppc64.rpm
27c0ed19d902712bce0ec59db95abfe5bb255779 openvrml-xembed-0.16.6-3.fc7.ppc64.rpm
7aa9091e4effe87531ef998a4f7c57b825cac6d8 openvrml-mozilla-plugin-0.16.6-3.fc7.ppc64.rpm
d27114e638b51ca6ad2f814bf266efc571e0cc49 openvrml-gl-devel-0.16.6-3.fc7.ppc64.rpm
9290cd735ad8122020d8182a95dc47b37deb0801 openvrml-gl-0.16.6-3.fc7.i386.rpm
c64f304c226d49ee7db382b956f69d176c11b4df openvrml-mozilla-plugin-0.16.6-3.fc7.i386.rpm
a9059b0781e7cac3f00db9fe71f4144b95fe8ec6 openvrml-0.16.6-3.fc7.i386.rpm
94b2e29dd252ab5ce38cf61262f6f1c342be12a5 openvrml-player-0.16.6-3.fc7.i386.rpm
5f3da0a38c1790bec608a4075dd06be1ee8d6aca openvrml-xembed-0.16.6-3.fc7.i386.rpm
f71494bbd6e7fdb91ad0cb8bacb4e86ae186e32c openvrml-debuginfo-0.16.6-3.fc7.i386.rpm
8201b7953d85d44219ec64d0a9e6ca0081c17cfa openvrml-gl-devel-0.16.6-3.fc7.i386.rpm
cf4c72d18777a4e2d9674b0fbda223d473469b06 openvrml-devel-0.16.6-3.fc7.i386.rpm
71f96756215f01fb52110626d0bca3e1d805ec50 openvrml-player-0.16.6-3.fc7.x86_64.rpm
60f4fa89c5b681b7c0c2e85fe968ab2fed07d771 openvrml-gl-devel-0.16.6-3.fc7.x86_64.rpm
c591034a544b8b9d7550b0fcc664ad97ace0d62a openvrml-devel-0.16.6-3.fc7.x86_64.rpm
d5488f94d3a93fb5fe0393d9a79c799eeb01995b openvrml-mozilla-plugin-0.16.6-3.fc7.x86_64.rpm
ed8c990b9eac741d0dadb58ac265d5e1b497f5ce openvrml-gl-0.16.6-3.fc7.x86_64.rpm
7a59d8832261bf18aac6bf1179107351c2866449 openvrml-debuginfo-0.16.6-3.fc7.x86_64.rpm
5050bf473b05521bf1f14c64f867671bacb788a5 openvrml-xembed-0.16.6-3.fc7.x86_64.rpm
f01ca41845e851fc595f57c74ad597d600d6a43a openvrml-0.16.6-3.fc7.x86_64.rpm
acf20e41a6e6c4472564bd9d6e05d16ec5d6ce2a openvrml-xembed-0.16.6-3.fc7.ppc.rpm
59ce7a91b23401eb74ca7dd87c8eb2ed23aabf9b openvrml-player-0.16.6-3.fc7.ppc.rpm
e39b0f453e73b1882a8659044f247f303631f04e openvrml-debuginfo-0.16.6-3.fc7.ppc.rpm
1ec1f2032784aecd51ee8029529919a6762b48d0 openvrml-devel-0.16.6-3.fc7.ppc.rpm
27389d80a8619dbd1928103ff9531460be78dccb openvrml-mozilla-plugin-0.16.6-3.fc7.ppc.rpm
c7e4f123777b2e35922f00c54a357cdc4f79cab8 openvrml-gl-devel-0.16.6-3.fc7.ppc.rpm
87bdaefec011518fd4491ef857bb666f6929fc9e openvrml-gl-0.16.6-3.fc7.ppc.rpm
ae8eb0a42d9222f3ade8acf84d2f62164d8551fc openvrml-0.16.6-3.fc7.ppc.rpm
465130d39c868c932e201cefac9225912ca5fef7 openvrml-0.16.6-3.fc7.src.rpm
e58434388cdfee4caecc020e8f271b2248f600d7 chmsee-debuginfo-1.0.0-1.26.fc8.ppc64.rpm
0ce374bdc67ae945de9be9d926ae9ab953831c1b chmsee-1.0.0-1.26.fc8.ppc64.rpm
4cdc13b24aebc99539a3fd424a70fafcb78d987c chmsee-1.0.0-1.26.fc8.i386.rpm
6aba8a234bcff78bab72c8d8bb1548011464175b chmsee-debuginfo-1.0.0-1.26.fc8.i386.rpm
c28bf8134f0cbd073f92b74da0fd626faaca1643 chmsee-1.0.0-1.26.fc8.x86_64.rpm
ca55853acc39614d4d1ef17b1ce3fdd8bcba5aba chmsee-debuginfo-1.0.0-1.26.fc8.x86_64.rpm
f79d196d706ed37d2c2b7160b67d1a912b502733 chmsee-debuginfo-1.0.0-1.26.fc8.ppc.rpm
1d240e4bafce23a422624be5ff901187bb895872 chmsee-1.0.0-1.26.fc8.ppc.rpm
31f48e8836e1b3bae1a26df2e1b711949cabafe6 chmsee-1.0.0-1.26.fc8.src.rpm

ChangeLog

2007-10-25 : Initial release
2007-10-30 : Updated Solution
2007-11-15 : Updated Solution

Vulnerability Management

Subscribe to FrSIRT VNS and receive real-time e-mail and SMS alerts when new vulnerabilities, exploits, or patches relevant to your systems and network configurations are available.

Feedback

If you have additional information or corrections for this security advisory please submit them via our contact form or by email to updates@frsirt.com.


 
 

Search

      

Mailinglist

    
 

Mozilla Products Code Execution and Security Bypass Vulnerabilities

Mozilla Firefox for Mac OS X GIF Rendering Code Execution Vulnerability

Mozilla Products Remote Code Execution and Security Bypass Issues

Mozilla Products Code Execution and Injection Vulnerabilities

Mozilla JavaScript Garbage Collector Code Execution Vulnerability

Mozilla Thunderbird Code Execution and Cross Site Scripting Issues

Mozilla Firefox and SeaMonkey Multiple Remote Code Execution Issues

Apple Mac OS X Code Execution and Security Bypass Vulnerabilities

Apple TV Multiple File Processing Code Execution Vulnerabilities

Apple Mac OS X Code Execution and Security Bypass Vulnerabilities

Apple iPhone Code Execution and Security Bypass Vulnerabilities

Apple QuickTime Multiple Remote Code Execution Vulnerabilities

Apple iTunes Driver Integer Overflow Privilege Escalation Vulnerability

Apple iPod touch Code Execution and Security Bypass Vulnerabilities

Cisco Unity Security Bypass and Denial of Service

Cisco UCM SIP Remote Denial of Service

Cisco IOS Denial of Service and Security Bypass Vulnerabilities

Cisco PIX and ASA Information Disclosure and DoS Vulnerabilities

Cisco Secure ACS EAP Remote Denial Of Service Vulnerability

Cisco Products Remote DNS Cache Poisoning Vulnerability

Cisco Wide Area Application Services CUPS Remote Vulnerability

Copyright 2003-2008 © FrSIRT.COM - Privacy Policy