Skip to navigation

Security Advisory Critical: firefox security update

Advisory: RHSA-2009:1162-1
Type: Security Advisory
Severity: Critical
Issued on: 2009-07-21
Last updated on: 2009-07-21
Affected Products: RHEL Desktop Workstation (v. 5 client)
Red Hat Desktop (v. 4)
Red Hat Enterprise Linux (v. 5 server)
Red Hat Enterprise Linux AS (v. 4)
Red Hat Enterprise Linux AS (v. 4.8.z)
Red Hat Enterprise Linux Desktop (v. 5 client)
Red Hat Enterprise Linux ES (v. 4)
Red Hat Enterprise Linux ES (v. 4.8.z)
Red Hat Enterprise Linux EUS (v. 5.3.z server)
Red Hat Enterprise Linux Long Life (v. 5.3 server)
Red Hat Enterprise Linux WS (v. 4)
CVEs (cve.mitre.org): CVE-2009-2462
CVE-2009-2463
CVE-2009-2464
CVE-2009-2465
CVE-2009-2466
CVE-2009-2467
CVE-2009-2469
CVE-2009-2470
CVE-2009-2471
CVE-2009-2472
CVE-2009-2664

Details

Updated firefox packages that fix several security issues are now available
for Red Hat Enterprise Linux 4 and 5.

This update has been rated as having critical security impact by the Red
Hat Security Response Team.

Mozilla Firefox is an open source Web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code as the user running Firefox.
(CVE-2009-2462, CVE-2009-2463, CVE-2009-2464, CVE-2009-2465, CVE-2009-2466,
CVE-2009-2467, CVE-2009-2469, CVE-2009-2471)

Several flaws were found in the way Firefox handles malformed JavaScript
code. A website containing malicious content could launch a cross-site
scripting (XSS) attack or execute arbitrary JavaScript with the permissions
of another website. (CVE-2009-2472)

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 3.0.12. You can find a link to the Mozilla
advisories in the References section of this errata.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 3.0.12, which corrects these issues. After installing the
update, Firefox must be restarted for the changes to take effect.


Solution

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied.

This update is available via Red Hat Network. Details on how to use
the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/docs/DOC-11259

Updated packages

RHEL Desktop Workstation (v. 5 client)

IA-32:
xulrunner-devel-1.9.0.12-1.el5_3.i386.rpm
File outdated by:  RHSA-2013:1476
    MD5: 930c76da9a362adb70b4304ca3cbc639
xulrunner-devel-unstable-1.9.0.12-1.el5_3.i386.rpm
File outdated by:  RHSA-2010:0332
    MD5: 62602e39714f4c523d2c7ad3ad1fa32a
 
x86_64:
xulrunner-devel-1.9.0.12-1.el5_3.i386.rpm
File outdated by:  RHSA-2013:1476
    MD5: 930c76da9a362adb70b4304ca3cbc639
xulrunner-devel-1.9.0.12-1.el5_3.x86_64.rpm
File outdated by:  RHSA-2013:1476
    MD5: bc6cd1fcc7e6e4e33d581e752f59744f
xulrunner-devel-unstable-1.9.0.12-1.el5_3.x86_64.rpm
File outdated by:  RHSA-2010:0332
    MD5: acd783b32be7c72679a81b53cc0a6def
 
Red Hat Desktop (v. 4)

SRPMS:
firefox-3.0.12-1.el4.src.rpm
File outdated by:  RHSA-2012:0142
    MD5: 1e4b2e2d928d6f594a57a8b51b3f946b
 
IA-32:
firefox-3.0.12-1.el4.i386.rpm
File outdated by:  RHSA-2012:0142
    MD5: 26bd18dd8b9fd6823638e7e9cabb120f
 
x86_64:
firefox-3.0.12-1.el4.x86_64.rpm
File outdated by:  RHSA-2012:0142
    MD5: 221ef62cdfa2832d433d8aee3d3af649
 
Red Hat Enterprise Linux (v. 5 server)

SRPMS:
firefox-3.0.12-1.el5_3.src.rpm
File outdated by:  RHSA-2014:0310
    MD5: 56860319f5b5846b21290d6d4257ac8c
 
IA-32:
firefox-3.0.12-1.el5_3.i386.rpm
File outdated by:  RHSA-2014:0310
    MD5: aa263e19f45a51fc0bf815dca97a4760
xulrunner-1.9.0.12-1.el5_3.i386.rpm
File outdated by:  RHSA-2013:1476
    MD5: a592f92f2e24422127503f5a08fd4dff
xulrunner-devel-1.9.0.12-1.el5_3.i386.rpm
File outdated by:  RHSA-2013:1476
    MD5: 930c76da9a362adb70b4304ca3cbc639
xulrunner-devel-unstable-1.9.0.12-1.el5_3.i386.rpm
File outdated by:  RHSA-2010:0332
    MD5: 62602e39714f4c523d2c7ad3ad1fa32a
 
IA-64:
firefox-3.0.12-1.el5_3.ia64.rpm
File outdated by:  RHSA-2014:0310
    MD5: a458da59f18260217d7a730b079c195e
xulrunner-1.9.0.12-1.el5_3.ia64.rpm
File outdated by:  RHSA-2013:1476
    MD5: 82a3213662110c1f8f6d9b2c9d3b41e3
xulrunner-devel-1.9.0.12-1.el5_3.ia64.rpm
File outdated by:  RHSA-2013:1476
    MD5: 4d5c830be4a3f76ba5a0061d51e284a4
xulrunner-devel-unstable-1.9.0.12-1.el5_3.ia64.rpm
File outdated by:  RHSA-2010:0332
    MD5: 1a72571c79e096c94297202b5cc7b35c
 
PPC:
firefox-3.0.12-1.el5_3.ppc.rpm
File outdated by:  RHSA-2014:0310
    MD5: f88ab9abed6ebafb7c27a6c35a318d0b
xulrunner-1.9.0.12-1.el5_3.ppc.rpm
File outdated by:  RHSA-2013:1476
    MD5: ae7417febcb4110c8400592de76a1463
xulrunner-1.9.0.12-1.el5_3.ppc64.rpm
File outdated by:  RHSA-2013:1476
    MD5: 1ac88d2f5b9da0cfd3bb1f7b2498a3c4
xulrunner-devel-1.9.0.12-1.el5_3.ppc.rpm
File outdated by:  RHSA-2013:1476
    MD5: 7a1514e7d10c9a44b0acd6dad61c69da
xulrunner-devel-1.9.0.12-1.el5_3.ppc64.rpm
File outdated by:  RHSA-2013:1476
    MD5: b3b0b04d3abd962f4de3754684876aaa
xulrunner-devel-unstable-1.9.0.12-1.el5_3.ppc.rpm
File outdated by:  RHSA-2010:0332
    MD5: c36f63437247579ab70751f9100e8ec8
 
s390x:
firefox-3.0.12-1.el5_3.s390.rpm
File outdated by:  RHSA-2014:0310
    MD5: 8c7770f2d484cd79555993a5876274e7
firefox-3.0.12-1.el5_3.s390x.rpm
File outdated by:  RHSA-2014:0310
    MD5: 4a8a68a019df6f7436a45d62aea3d355
xulrunner-1.9.0.12-1.el5_3.s390.rpm
File outdated by:  RHSA-2013:1476
    MD5: 1cfe70867fa6f71eea72f653cf58cbde
xulrunner-1.9.0.12-1.el5_3.s390x.rpm
File outdated by:  RHSA-2013:1476
    MD5: 5e731f51e7ee88db1ddb4a82b2372d0b
xulrunner-devel-1.9.0.12-1.el5_3.s390.rpm
File outdated by:  RHSA-2013:1476
    MD5: e79706383a80730a96c3d065d2880ec9
xulrunner-devel-1.9.0.12-1.el5_3.s390x.rpm
File outdated by:  RHSA-2013:1476
    MD5: 92f2b2ec4a9344c33ba170a11dd77955
xulrunner-devel-unstable-1.9.0.12-1.el5_3.s390x.rpm
File outdated by:  RHSA-2010:0332
    MD5: c01cf7643f0bd75cf3ef468dee1f4a87
 
x86_64:
firefox-3.0.12-1.el5_3.i386.rpm
File outdated by:  RHSA-2014:0310
    MD5: aa263e19f45a51fc0bf815dca97a4760
firefox-3.0.12-1.el5_3.x86_64.rpm
File outdated by:  RHSA-2014:0310
    MD5: ad1b9dbc62eb04d1ca8c276ba5aa697f
xulrunner-1.9.0.12-1.el5_3.i386.rpm
File outdated by:  RHSA-2013:1476
    MD5: a592f92f2e24422127503f5a08fd4dff
xulrunner-1.9.0.12-1.el5_3.x86_64.rpm
File outdated by:  RHSA-2013:1476
    MD5: b5c443e3acda04532dc251878aa0fe2c
xulrunner-devel-1.9.0.12-1.el5_3.i386.rpm
File outdated by:  RHSA-2013:1476
    MD5: 930c76da9a362adb70b4304ca3cbc639
xulrunner-devel-1.9.0.12-1.el5_3.x86_64.rpm
File outdated by:  RHSA-2013:1476
    MD5: bc6cd1fcc7e6e4e33d581e752f59744f
xulrunner-devel-unstable-1.9.0.12-1.el5_3.x86_64.rpm
File outdated by:  RHSA-2010:0332
    MD5: acd783b32be7c72679a81b53cc0a6def
 
Red Hat Enterprise Linux AS (v. 4)

SRPMS:
firefox-3.0.12-1.el4.src.rpm
File outdated by:  RHSA-2012:0142
    MD5: 1e4b2e2d928d6f594a57a8b51b3f946b
 
IA-32:
firefox-3.0.12-1.el4.i386.rpm
File outdated by:  RHSA-2012:0142
    MD5: 26bd18dd8b9fd6823638e7e9cabb120f
 
IA-64:
firefox-3.0.12-1.el4.ia64.rpm
File outdated by:  RHSA-2012:0142
    MD5: 7b4d7bffeee691ec35b5c98a0c1ed4ca
 
PPC:
firefox-3.0.12-1.el4.ppc.rpm
File outdated by:  RHSA-2012:0142
    MD5: 12c84ba587b93167446be9987d2db20f
 
s390:
firefox-3.0.12-1.el4.s390.rpm
File outdated by:  RHSA-2012:0142
    MD5: 393e23b339cd836d682d7f5ee78b3a2d
 
s390x:
firefox-3.0.12-1.el4.s390x.rpm
File outdated by:  RHSA-2012:0142
    MD5: a551abe090b027aa756d8b7b92226285
 
x86_64:
firefox-3.0.12-1.el4.x86_64.rpm
File outdated by:  RHSA-2012:0142
    MD5: 221ef62cdfa2832d433d8aee3d3af649
 
Red Hat Enterprise Linux AS (v. 4.8.z)

SRPMS:
firefox-3.0.12-1.el4.src.rpm
File outdated by:  RHSA-2012:0142
    MD5: 1e4b2e2d928d6f594a57a8b51b3f946b
 
IA-32:
firefox-3.0.12-1.el4.i386.rpm
File outdated by:  RHSA-2011:0885
    MD5: 26bd18dd8b9fd6823638e7e9cabb120f
 
IA-64:
firefox-3.0.12-1.el4.ia64.rpm
File outdated by:  RHSA-2011:0885
    MD5: 7b4d7bffeee691ec35b5c98a0c1ed4ca
 
PPC:
firefox-3.0.12-1.el4.ppc.rpm
File outdated by:  RHSA-2011:0885
    MD5: 12c84ba587b93167446be9987d2db20f
 
s390:
firefox-3.0.12-1.el4.s390.rpm
File outdated by:  RHSA-2011:0885
    MD5: 393e23b339cd836d682d7f5ee78b3a2d
 
s390x:
firefox-3.0.12-1.el4.s390x.rpm
File outdated by:  RHSA-2011:0885
    MD5: a551abe090b027aa756d8b7b92226285
 
x86_64:
firefox-3.0.12-1.el4.x86_64.rpm
File outdated by:  RHSA-2011:0885
    MD5: 221ef62cdfa2832d433d8aee3d3af649
 
Red Hat Enterprise Linux Desktop (v. 5 client)

SRPMS:
firefox-3.0.12-1.el5_3.src.rpm
File outdated by:  RHSA-2014:0310
    MD5: 56860319f5b5846b21290d6d4257ac8c
 
IA-32:
firefox-3.0.12-1.el5_3.i386.rpm
File outdated by:  RHSA-2014:0310
    MD5: aa263e19f45a51fc0bf815dca97a4760
xulrunner-1.9.0.12-1.el5_3.i386.rpm
File outdated by:  RHSA-2013:1476
    MD5: a592f92f2e24422127503f5a08fd4dff
 
x86_64:
firefox-3.0.12-1.el5_3.i386.rpm
File outdated by:  RHSA-2014:0310
    MD5: aa263e19f45a51fc0bf815dca97a4760
firefox-3.0.12-1.el5_3.x86_64.rpm
File outdated by:  RHSA-2014:0310
    MD5: ad1b9dbc62eb04d1ca8c276ba5aa697f
xulrunner-1.9.0.12-1.el5_3.i386.rpm
File outdated by:  RHSA-2013:1476
    MD5: a592f92f2e24422127503f5a08fd4dff
xulrunner-1.9.0.12-1.el5_3.x86_64.rpm
File outdated by:  RHSA-2013:1476
    MD5: b5c443e3acda04532dc251878aa0fe2c
 
Red Hat Enterprise Linux ES (v. 4)

SRPMS:
firefox-3.0.12-1.el4.src.rpm
File outdated by:  RHSA-2012:0142
    MD5: 1e4b2e2d928d6f594a57a8b51b3f946b
 
IA-32:
firefox-3.0.12-1.el4.i386.rpm
File outdated by:  RHSA-2012:0142
    MD5: 26bd18dd8b9fd6823638e7e9cabb120f
 
IA-64:
firefox-3.0.12-1.el4.ia64.rpm
File outdated by:  RHSA-2012:0142
    MD5: 7b4d7bffeee691ec35b5c98a0c1ed4ca
 
x86_64:
firefox-3.0.12-1.el4.x86_64.rpm
File outdated by:  RHSA-2012:0142
    MD5: 221ef62cdfa2832d433d8aee3d3af649
 
Red Hat Enterprise Linux ES (v. 4.8.z)

SRPMS:
firefox-3.0.12-1.el4.src.rpm
File outdated by:  RHSA-2012:0142
    MD5: 1e4b2e2d928d6f594a57a8b51b3f946b
 
IA-32:
firefox-3.0.12-1.el4.i386.rpm
File outdated by:  RHSA-2011:0885
    MD5: 26bd18dd8b9fd6823638e7e9cabb120f
 
IA-64:
firefox-3.0.12-1.el4.ia64.rpm
File outdated by:  RHSA-2011:0885
    MD5: 7b4d7bffeee691ec35b5c98a0c1ed4ca
 
x86_64:
firefox-3.0.12-1.el4.x86_64.rpm
File outdated by:  RHSA-2011:0885
    MD5: 221ef62cdfa2832d433d8aee3d3af649
 
Red Hat Enterprise Linux EUS (v. 5.3.z server)

SRPMS:
firefox-3.0.12-1.el5_3.src.rpm
File outdated by:  RHSA-2014:0310
    MD5: 56860319f5b5846b21290d6d4257ac8c
 
IA-32:
firefox-3.0.12-1.el5_3.i386.rpm     MD5: aa263e19f45a51fc0bf815dca97a4760
xulrunner-1.9.0.12-1.el5_3.i386.rpm     MD5: a592f92f2e24422127503f5a08fd4dff
xulrunner-devel-1.9.0.12-1.el5_3.i386.rpm     MD5: 930c76da9a362adb70b4304ca3cbc639
xulrunner-devel-unstable-1.9.0.12-1.el5_3.i386.rpm     MD5: 62602e39714f4c523d2c7ad3ad1fa32a
 
IA-64:
firefox-3.0.12-1.el5_3.ia64.rpm     MD5: a458da59f18260217d7a730b079c195e
xulrunner-1.9.0.12-1.el5_3.ia64.rpm     MD5: 82a3213662110c1f8f6d9b2c9d3b41e3
xulrunner-devel-1.9.0.12-1.el5_3.ia64.rpm     MD5: 4d5c830be4a3f76ba5a0061d51e284a4
xulrunner-devel-unstable-1.9.0.12-1.el5_3.ia64.rpm     MD5: 1a72571c79e096c94297202b5cc7b35c
 
PPC:
firefox-3.0.12-1.el5_3.ppc.rpm     MD5: f88ab9abed6ebafb7c27a6c35a318d0b
xulrunner-1.9.0.12-1.el5_3.ppc.rpm     MD5: ae7417febcb4110c8400592de76a1463
xulrunner-1.9.0.12-1.el5_3.ppc64.rpm     MD5: 1ac88d2f5b9da0cfd3bb1f7b2498a3c4
xulrunner-devel-1.9.0.12-1.el5_3.ppc.rpm     MD5: 7a1514e7d10c9a44b0acd6dad61c69da
xulrunner-devel-1.9.0.12-1.el5_3.ppc64.rpm     MD5: b3b0b04d3abd962f4de3754684876aaa
xulrunner-devel-unstable-1.9.0.12-1.el5_3.ppc.rpm     MD5: c36f63437247579ab70751f9100e8ec8
 
s390x:
firefox-3.0.12-1.el5_3.s390.rpm     MD5: 8c7770f2d484cd79555993a5876274e7
firefox-3.0.12-1.el5_3.s390x.rpm     MD5: 4a8a68a019df6f7436a45d62aea3d355
xulrunner-1.9.0.12-1.el5_3.s390.rpm     MD5: 1cfe70867fa6f71eea72f653cf58cbde
xulrunner-1.9.0.12-1.el5_3.s390x.rpm     MD5: 5e731f51e7ee88db1ddb4a82b2372d0b
xulrunner-devel-1.9.0.12-1.el5_3.s390.rpm     MD5: e79706383a80730a96c3d065d2880ec9
xulrunner-devel-1.9.0.12-1.el5_3.s390x.rpm     MD5: 92f2b2ec4a9344c33ba170a11dd77955
xulrunner-devel-unstable-1.9.0.12-1.el5_3.s390x.rpm     MD5: c01cf7643f0bd75cf3ef468dee1f4a87
 
x86_64:
firefox-3.0.12-1.el5_3.i386.rpm     MD5: aa263e19f45a51fc0bf815dca97a4760
firefox-3.0.12-1.el5_3.x86_64.rpm     MD5: ad1b9dbc62eb04d1ca8c276ba5aa697f
xulrunner-1.9.0.12-1.el5_3.i386.rpm     MD5: a592f92f2e24422127503f5a08fd4dff
xulrunner-1.9.0.12-1.el5_3.x86_64.rpm     MD5: b5c443e3acda04532dc251878aa0fe2c
xulrunner-devel-1.9.0.12-1.el5_3.i386.rpm     MD5: 930c76da9a362adb70b4304ca3cbc639
xulrunner-devel-1.9.0.12-1.el5_3.x86_64.rpm     MD5: bc6cd1fcc7e6e4e33d581e752f59744f
xulrunner-devel-unstable-1.9.0.12-1.el5_3.x86_64.rpm     MD5: acd783b32be7c72679a81b53cc0a6def
 
Red Hat Enterprise Linux Long Life (v. 5.3 server)

SRPMS:
firefox-3.0.12-1.el5_3.src.rpm
File outdated by:  RHSA-2014:0310
    MD5: 56860319f5b5846b21290d6d4257ac8c
 
IA-32:
firefox-3.0.12-1.el5_3.i386.rpm     MD5: aa263e19f45a51fc0bf815dca97a4760
xulrunner-1.9.0.12-1.el5_3.i386.rpm     MD5: a592f92f2e24422127503f5a08fd4dff
xulrunner-devel-1.9.0.12-1.el5_3.i386.rpm     MD5: 930c76da9a362adb70b4304ca3cbc639
xulrunner-devel-unstable-1.9.0.12-1.el5_3.i386.rpm     MD5: 62602e39714f4c523d2c7ad3ad1fa32a
 
IA-64:
firefox-3.0.12-1.el5_3.ia64.rpm     MD5: a458da59f18260217d7a730b079c195e
xulrunner-1.9.0.12-1.el5_3.ia64.rpm     MD5: 82a3213662110c1f8f6d9b2c9d3b41e3
xulrunner-devel-1.9.0.12-1.el5_3.ia64.rpm     MD5: 4d5c830be4a3f76ba5a0061d51e284a4
xulrunner-devel-unstable-1.9.0.12-1.el5_3.ia64.rpm     MD5: 1a72571c79e096c94297202b5cc7b35c
 
x86_64:
firefox-3.0.12-1.el5_3.i386.rpm     MD5: aa263e19f45a51fc0bf815dca97a4760
firefox-3.0.12-1.el5_3.x86_64.rpm     MD5: ad1b9dbc62eb04d1ca8c276ba5aa697f
xulrunner-1.9.0.12-1.el5_3.i386.rpm     MD5: a592f92f2e24422127503f5a08fd4dff
xulrunner-1.9.0.12-1.el5_3.x86_64.rpm     MD5: b5c443e3acda04532dc251878aa0fe2c
xulrunner-devel-1.9.0.12-1.el5_3.i386.rpm     MD5: 930c76da9a362adb70b4304ca3cbc639
xulrunner-devel-1.9.0.12-1.el5_3.x86_64.rpm     MD5: bc6cd1fcc7e6e4e33d581e752f59744f
xulrunner-devel-unstable-1.9.0.12-1.el5_3.x86_64.rpm     MD5: acd783b32be7c72679a81b53cc0a6def
 
Red Hat Enterprise Linux WS (v. 4)

SRPMS:
firefox-3.0.12-1.el4.src.rpm
File outdated by:  RHSA-2012:0142
    MD5: 1e4b2e2d928d6f594a57a8b51b3f946b
 
IA-32:
firefox-3.0.12-1.el4.i386.rpm
File outdated by:  RHSA-2012:0142
    MD5: 26bd18dd8b9fd6823638e7e9cabb120f
 
IA-64:
firefox-3.0.12-1.el4.ia64.rpm
File outdated by:  RHSA-2012:0142
    MD5: 7b4d7bffeee691ec35b5c98a0c1ed4ca
 
x86_64:
firefox-3.0.12-1.el4.x86_64.rpm
File outdated by:  RHSA-2012:0142
    MD5: 221ef62cdfa2832d433d8aee3d3af649
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

512128 - CVE-2009-2462 Mozilla Browser engine crashes
512131 - CVE-2009-2463 Mozilla Base64 decoding crash
512133 - CVE-2009-2464 Mozilla crash with multiple RDFs in XUL tree
512135 - CVE-2009-2465 Mozilla double frame construction crashes
512136 - CVE-2009-2466 Mozilla JavaScript engine crashes
512137 - CVE-2009-2467 Mozilla remote code execution during Flash player unloading
512142 - CVE-2009-2469 Mozilla remote code execution using watch and __defineSetter__ on SVG element
512146 - CVE-2009-2471 Mozilla setTimeout loses XPCNativeWrappers
512147 - CVE-2009-2472 Mozilla multiple cross origin wrapper bypasses


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/