Updated packages are available which fix a security issue in Mozilla.
One component of the XML Extras package in Mozilla 0.9.9 and
earlier allows remote attackers to read arbitrary files and list
directories on a client system. This exploit is performed by opening a
URL
that redirects the browser to the file on the client and reading the
results using the responseText property.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2002-0354 to this issue.
Users of Mozilla are advised to upgrade to these errata packages which
have
been patched and are not vulnerable to this issue.
| Red Hat Linux 7.2 |
|
| SRPMS: |
galeon-1.2.0-4.src.rpm
File outdated by: RHSA-2003:162 |
74205204260a219baa7115040502a6ad |
mozilla-0.9.9-12.7.2.src.rpm
File outdated by: RHSA-2003:162 |
61dc6fb50d42ad468fa0dc6461204d52 |
nautilus-1.0.4-47.src.rpm
File outdated by: RHSA-2002:192 |
6761d7591dd2c2ea4381d9b2a72f113e |
| |
| IA-32: |
galeon-1.2.0-4.i386.rpm
File outdated by: RHSA-2003:162 |
7fd91be26bd046c90e9dab7ae1dd97e8 |
mozilla-0.9.9-12.7.2.i386.rpm
File outdated by: RHSA-2003:162 |
c8cb0b5b5149caf9c7304c58303e1521 |
mozilla-chat-0.9.9-12.7.2.i386.rpm
File outdated by: RHSA-2003:162 |
25a89877b688f4ff2a486fe3fad0653f |
mozilla-devel-0.9.9-12.7.2.i386.rpm
File outdated by: RHSA-2003:162 |
5d7a8ab180050c7903fa6a960b391800 |
mozilla-dom-inspector-0.9.9-12.7.2.i386.rpm
File outdated by: RHSA-2003:162 |
af5c2c218d4261b0d0026735e2f0bf2c |
mozilla-js-debugger-0.9.9-12.7.2.i386.rpm
File outdated by: RHSA-2003:162 |
4908abfa35ab6dfbdf57b1a4517ae9a4 |
mozilla-mail-0.9.9-12.7.2.i386.rpm
File outdated by: RHSA-2003:162 |
edf9cefd2bc44f84be2ba8eb5f0ce628 |
mozilla-nspr-0.9.9-12.7.2.i386.rpm
File outdated by: RHSA-2003:162 |
a4a8d9448735517017c411267ef988e7 |
mozilla-nspr-devel-0.9.9-12.7.2.i386.rpm
File outdated by: RHSA-2003:162 |
7255b6906b29468a450871f93183d30f |
mozilla-nss-0.9.9-12.7.2.i386.rpm
File outdated by: RHSA-2003:162 |
64c6694e8491d7168044f8c7ce72fb94 |
mozilla-nss-devel-0.9.9-12.7.2.i386.rpm
File outdated by: RHSA-2003:162 |
e98076dfac69a134d1df3eb164895fe9 |
mozilla-psm-0.9.9-12.7.2.i386.rpm
File outdated by: RHSA-2003:162 |
87f75c3bf3e643fc10540cc9da16e782 |
nautilus-1.0.4-47.i386.rpm
File outdated by: RHSA-2002:192 |
1355d06e20ddf248348ac30065a5fcf3 |
nautilus-devel-1.0.4-47.i386.rpm
File outdated by: RHSA-2002:192 |
c006cbd6ebd1d6cde75c85644b9532cd |
nautilus-mozilla-1.0.4-47.i386.rpm
File outdated by: RHSA-2002:192 |
6459a5f406537ac5846c933bb2c6581e |
| |
| Red Hat Linux 7.3 |
|
| SRPMS: |
mozilla-0.9.9-12.7.3.src.rpm
File outdated by: RHSA-2003:162 |
34414eebf6f9b36a537ab298e2e1b807 |
| |
| IA-32: |
mozilla-0.9.9-12.7.3.i386.rpm
File outdated by: RHSA-2003:162 |
5a83b956e389a2f92b1eab349a930ff2 |
mozilla-chat-0.9.9-12.7.3.i386.rpm
File outdated by: RHSA-2003:162 |
db2d0e25dc4eb85b60ecb6c6646f013a |
mozilla-devel-0.9.9-12.7.3.i386.rpm
File outdated by: RHSA-2003:162 |
297737da7d306e7b313a287f5f23ad94 |
mozilla-dom-inspector-0.9.9-12.7.3.i386.rpm
File outdated by: RHSA-2003:162 |
9c93d5fa132870012ef048c0f7ae3728 |
mozilla-js-debugger-0.9.9-12.7.3.i386.rpm
File outdated by: RHSA-2003:162 |
a2f5d75373d37ffbf3b22eae9a9ce958 |
mozilla-mail-0.9.9-12.7.3.i386.rpm
File outdated by: RHSA-2003:162 |
81163adb654a741f18b2acfa428b6c22 |
mozilla-nspr-0.9.9-12.7.3.i386.rpm
File outdated by: RHSA-2003:162 |
010608fa44c7ab497680b31692be0423 |
mozilla-nspr-devel-0.9.9-12.7.3.i386.rpm
File outdated by: RHSA-2003:162 |
b68e64e165261fd50b27aecc51d6999c |
mozilla-nss-0.9.9-12.7.3.i386.rpm
File outdated by: RHSA-2003:162 |
21983fac067201f30d477bb05bce2b2f |
mozilla-nss-devel-0.9.9-12.7.3.i386.rpm
File outdated by: RHSA-2003:162 |
f82fa92ac1df7434a98763f47c54fb64 |
mozilla-psm-0.9.9-12.7.3.i386.rpm
File outdated by: RHSA-2003:162 |
5fcda91f151690b32fa77f3eefe4f492 |
| |
64283 - XMLHttpRequest allows reading of local files