Security Advisory Updated Mozilla packages fix security vulnerabilities

Advisory: RHSA-2002:192-13
Type: Security Advisory
Severity: N/A
Issued on: 2002-08-28
Last updated on: 2002-10-09
Affected Products: Red Hat Linux 7.2
Red Hat Linux 7.3
Red Hat Linux 8.0
OVAL: N/A
CVEs (cve.mitre.org): CVE-2002-0593
CVE-2002-0594
CVE-2002-1091
CVE-2002-1126

Details

Updated Mozilla packages are now available for Red Hat Linux. These new
packages fix vulnerabilities in previous versions of Mozilla.

Mozilla is an open source web browser. Versions of Mozilla previous to
version 1.0.1 contain various security vulnerabilities. These
vulnerabilities could be used by an attacker to read data off of the local
hard drive, to gain information that should normally be kept private, and
in some cases to execute arbitrary code. For more information on the
specific vulnerabilities fixed please see the references below.

All users of Mozilla should update to these errata packages containing
Mozilla version 1.0.1 which is not vulnerable to these issues.


Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

To update all RPMs for your particular architecture, run:

rpm -Fvh [filenames]

where [filenames] is a list of the RPMs you wish to upgrade. Only those
RPMs which are currently installed will be updated. Those RPMs which are
not installed but included in the list will not be updated. Note that you
can also use wildcards (*.rpm) if your current directory *only* contains the
desired RPMs.

Please note that this update is also available via Red Hat Network. Many
people find this an easier way to apply updates. To use Red Hat Network,
launch the Red Hat Update Agent with the following command:

up2date

This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system.

Updated packages

Red Hat Linux 7.2

SRPMS:
galeon-1.2.6-0.7.2.src.rpm
File outdated by:  RHSA-2003:162
    2c9290ece68000873e629ce86552a196
ftp://updates.redhat.com/7.2/en/os/SRPMS/gdk-pixbuf-0.14.0-0.7.2.src.rpm
Missing file
    45ac827625017ff0fbf6d5cef7435aeb
mozilla-1.0.1-2.7.2.src.rpm
File outdated by:  RHSA-2003:162
    f92260127e30ed4da890502653b0e029
ftp://updates.redhat.com/7.2/en/os/SRPMS/nautilus-1.0.4-48.src.rpm
Missing file
    edf75a33af3af645257bd16d35637664
 
IA-32:
galeon-1.2.6-0.7.2.i386.rpm
File outdated by:  RHSA-2003:162
    bce50acc0675f468a9b08d125d0f4be2
ftp://updates.redhat.com/7.2/en/os/i386/gdk-pixbuf-0.14.0-0.7.2.i386.rpm
Missing file
    bbaa3bf0948a2889644db081355ccfdf
ftp://updates.redhat.com/7.2/en/os/i386/gdk-pixbuf-devel-0.14.0-0.7.2.i386.rpm
Missing file
    35043786032f1399077cb42021e3b372
ftp://updates.redhat.com/7.2/en/os/i386/gdk-pixbuf-gnome-0.14.0-0.7.2.i386.rpm
Missing file
    37f9cf9f4fe3619c1d7e88a5a0f6ccca
mozilla-1.0.1-2.7.2.i386.rpm
File outdated by:  RHSA-2003:162
    55cae02cdb3588ecdb5c98162658dcf0
mozilla-chat-1.0.1-2.7.2.i386.rpm
File outdated by:  RHSA-2003:162
    f02f614a369d697f72d4668306b429a3
mozilla-devel-1.0.1-2.7.2.i386.rpm
File outdated by:  RHSA-2003:162
    c837cb4b7e86c203e3826e154bdd53bc
mozilla-dom-inspector-1.0.1-2.7.2.i386.rpm
File outdated by:  RHSA-2003:162
    eb96ae6280da1b4e9af11320e466d95a
mozilla-js-debugger-1.0.1-2.7.2.i386.rpm
File outdated by:  RHSA-2003:162
    9c3612262d14acf6453c6e12d2931cd8
mozilla-mail-1.0.1-2.7.2.i386.rpm
File outdated by:  RHSA-2003:162
    4049e74e502d396c6de586f23d1e6543
mozilla-nspr-1.0.1-2.7.2.i386.rpm
File outdated by:  RHSA-2003:162
    b7845d71694282593fab8d7e59761592
mozilla-nspr-devel-1.0.1-2.7.2.i386.rpm
File outdated by:  RHSA-2003:162
    caf0ad56986e6be4c7e2143c26729e09
mozilla-nss-1.0.1-2.7.2.i386.rpm
File outdated by:  RHSA-2003:162
    8fa96d2226a69d3e90042bd96ff755ef
mozilla-nss-devel-1.0.1-2.7.2.i386.rpm
File outdated by:  RHSA-2003:162
    4fbd4d48b9fed65d1d78790dd8f1df6c
mozilla-psm-1.0.1-2.7.2.i386.rpm
File outdated by:  RHSA-2003:162
    1153effb7a20ba940d84ccf4d2d1ba6d
ftp://updates.redhat.com/7.2/en/os/i386/nautilus-1.0.4-48.i386.rpm
Missing file
    e0719ff530dceeaf85c0b35a076ff248
ftp://updates.redhat.com/7.2/en/os/i386/nautilus-devel-1.0.4-48.i386.rpm
Missing file
    5733116ad2f47d7af6f28e96c2d96545
ftp://updates.redhat.com/7.2/en/os/i386/nautilus-mozilla-1.0.4-48.i386.rpm
Missing file
    a35343068ce221c7cae6c321b8999c6f
 
IA-64:
ftp://updates.redhat.com/7.2/en/os/ia64/gdk-pixbuf-0.14.0-0.7.2.ia64.rpm
Missing file
    a214992d302e65c74547cb4f76754037
ftp://updates.redhat.com/7.2/en/os/ia64/gdk-pixbuf-devel-0.14.0-0.7.2.ia64.rpm
Missing file
    ee37c010271bdef5d716cb9893ce86a2
ftp://updates.redhat.com/7.2/en/os/ia64/gdk-pixbuf-gnome-0.14.0-0.7.2.ia64.rpm
Missing file
    ba5982cf9c1ab63b92206bd9b599504c
ftp://updates.redhat.com/7.2/en/os/ia64/nautilus-1.0.4-48.ia64.rpm
Missing file
    dc7707c2e2e580801ef4e56628a73abb
ftp://updates.redhat.com/7.2/en/os/ia64/nautilus-devel-1.0.4-48.ia64.rpm
Missing file
    4e7d0a6909c132733dc9e9d935155626
 
Red Hat Linux 7.3

SRPMS:
galeon-1.2.6-0.7.3.src.rpm
File outdated by:  RHSA-2003:162
    fb77474103240a26f072c20a7fd882aa
mozilla-1.0.1-2.7.3.src.rpm
File outdated by:  RHSA-2003:162
    413fdcc522366c152052a45c04cbd514
ftp://updates.redhat.com/7.3/en/os/SRPMS/nautilus-1.0.6-16.src.rpm
Missing file
    96f43ccc321db5a6c94aa8918bd67276
 
IA-32:
galeon-1.2.6-0.7.3.i386.rpm
File outdated by:  RHSA-2003:162
    9e6581d0c1130fe9c5b586fef8b801fd
mozilla-1.0.1-2.7.3.i386.rpm
File outdated by:  RHSA-2003:162
    3b7cbffce1e495fa0e7ab35524b6d8a7
mozilla-chat-1.0.1-2.7.3.i386.rpm
File outdated by:  RHSA-2003:162
    c904e415dd240afd88858fc190e434f1
mozilla-devel-1.0.1-2.7.3.i386.rpm
File outdated by:  RHSA-2003:162
    bc8b506c8ba8ef533cb7aee51463d1fc
mozilla-dom-inspector-1.0.1-2.7.3.i386.rpm
File outdated by:  RHSA-2003:162
    23e6364b844beda678b47d4eec6fd7c7
mozilla-js-debugger-1.0.1-2.7.3.i386.rpm
File outdated by:  RHSA-2003:162
    d9d5da9c42bb40629be4e2f569a535f8
mozilla-mail-1.0.1-2.7.3.i386.rpm
File outdated by:  RHSA-2003:162
    1002a1657091994e2b6c641efccd3084
mozilla-nspr-1.0.1-2.7.3.i386.rpm
File outdated by:  RHSA-2003:162
    e5088a329b5b370f99d1bcdc91fd1da5
mozilla-nspr-devel-1.0.1-2.7.3.i386.rpm
File outdated by:  RHSA-2003:162
    4d91282c418fd138d463a4f597fbe0c8
mozilla-nss-1.0.1-2.7.3.i386.rpm
File outdated by:  RHSA-2003:162
    5cc1495b12fcb7aa2c5bd12cc8f3cb00
mozilla-nss-devel-1.0.1-2.7.3.i386.rpm
File outdated by:  RHSA-2003:162
    6bece76a0b4c597a2e421c9dff5abf37
mozilla-psm-1.0.1-2.7.3.i386.rpm
File outdated by:  RHSA-2003:162
    e14c15e957472c4e1258df02821c9a42
ftp://updates.redhat.com/7.3/en/os/i386/nautilus-1.0.6-16.i386.rpm
Missing file
    d35b4a163ae71d132a1f54abb04c6dfc
ftp://updates.redhat.com/7.3/en/os/i386/nautilus-devel-1.0.6-16.i386.rpm
Missing file
    379c05ad14b9a8154a9afe1259fe9435
ftp://updates.redhat.com/7.3/en/os/i386/nautilus-mozilla-1.0.6-16.i386.rpm
Missing file
    bfea3b16bf8ef7a706c796a26ea4afdb
 
Red Hat Linux 8.0

SRPMS:
galeon-1.2.6-0.8.0.src.rpm
File outdated by:  RHSA-2003:162
    ad145735d93c8ab0e1a6ae067ce8087d
mozilla-1.0.1-26.src.rpm
File outdated by:  RHSA-2003:162
    a72e5a350f3d8060510cbae91ac0f7a2
 
IA-32:
galeon-1.2.6-0.8.0.i386.rpm
File outdated by:  RHSA-2003:162
    d8d8b5eb226c715b6f2caadd891f3589
mozilla-1.0.1-26.i386.rpm
File outdated by:  RHSA-2003:162
    8970dd4ed15dc723b69981a759dc276d
mozilla-chat-1.0.1-26.i386.rpm
File outdated by:  RHSA-2003:162
    c937a851972b2dc0b5fc3fcb1102b271
mozilla-devel-1.0.1-26.i386.rpm
File outdated by:  RHSA-2003:162
    dea17caeaecf5409b109c159c103b79f
mozilla-dom-inspector-1.0.1-26.i386.rpm
File outdated by:  RHSA-2003:162
    e076a16d042773e89e12b28b7881b0d3
mozilla-js-debugger-1.0.1-26.i386.rpm
File outdated by:  RHSA-2003:162
    4e598807c3deb705bb1acaf49d27bdc1
mozilla-mail-1.0.1-26.i386.rpm
File outdated by:  RHSA-2003:162
    738ab97dc4b45cdfc2f2183b34094b0e
mozilla-nspr-1.0.1-26.i386.rpm
File outdated by:  RHSA-2003:162
    dafdc4e139a1b472facce214480de017
mozilla-nspr-devel-1.0.1-26.i386.rpm
File outdated by:  RHSA-2003:162
    1f5436dcc047c4957235abde0c7d635f
mozilla-nss-1.0.1-26.i386.rpm
File outdated by:  RHSA-2003:162
    8e9bdb03a9ddd07a48fa1dac1268a89d
mozilla-nss-devel-1.0.1-26.i386.rpm
File outdated by:  RHSA-2003:162
    8c943caa6cfb3f885ecaed505682fdba
mozilla-psm-1.0.1-26.i386.rpm
File outdated by:  RHSA-2003:162
    e626196daf83519788f137637c9599d1
 

References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/