NASLDB: SuSE 11.0 Security Update: MozillaFirefox (2009-04-07)
General
ID: 39888
Name: SuSE 11.0 Security Update: MozillaFirefox (2009-04-07)
Summary: Check for the MozillaFirefox package
Credits: Tenable Network Security, Inc.
Classification
Risk: –
CVSS: –
CVSS Base Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C
CVSS Temporal Vector: –
Port: 0
Family: SuSE Local Security Checks
Type: Local
Description
The Mozilla Firefox Browser was updated to the 3.0.8
release. It fixes several security issues:
MFSA 2009-13 / CVE-2009-1044: Security researcher Nils
reported via TippingPoint’s Zero Day Initiative that the
XUL tree method _moveToEdgeShift was in some cases
triggering garbage collection routines on objects which
were still in use. In such cases, the browser would crash
when attempting to access a previously destroyed object and
this crash could be used by an attacker to run arbitrary
code on a victim’s computer. This vulnerability was used by
the reporter to win the 2009 CanSecWest Pwn2Own contest.
This vulnerability does not affect Firefox 2, Thunderbird
2, or released versions of SeaMonkey.
MFSA 2009-12 / CVE-2009-1169:Security researcher Guido
Landi discovered that a XSL stylesheet could be used to
crash the browser during a XSL transformation. An attacker
could potentially use this crash to run arbitrary code on a
victim’s computer. This vulnerability was also previously
reported as a stability problem by Ubuntu community member,
Andre. Ubuntu community member Michael Rooney reported
Andre’s findings to Mozilla, and Mozilla community member
Martin helped reduce Andre’s original testcase and
contributed a patch to fix the vulnerability.
Exploiting
Exploit Available: –
Exploitability Ease: –
Sources
CVE: CVE-2009-1044
OSVDB: –
Bugtraq: –
scipID: –
Timeline
Vulnerability Disclosure: –
Patch Release: –
Plugin Release: 2009/07/21
Plugin
Version: 1.9
Filename: suse_11_0_MozillaFirefox-090407.nasl
Filesize: 4645 bytes
MD5 Hash: 223602f848009de2432dbc3b1b5945a0
Identification: Host/SuSE/rpm-list
Require Keys: Host/SuSE/rpm-list
Dependencies: "ssh_get_info.nasl"
Copyright: This script is Copyright© 2009-2012 Tenable Network Security, Inc.
- Latest Plugins
- USN-1611-1 : thunderbird vulnerabilities
- USN-1610-1 : linux vulnerability
- USN-1609-1 : linux-ti-omap4 vulnerability
- SuSE 10 Security Update : PostgreSQL
- RHSA-2012-1364: bind97
- RHSA-2012-1363: bind
- RHSA-2012-1362: thunderbird
- RHSA-2012-1361: xulrunner
- Mandriva Linux Security Advisory : graphicsmagick
- FreeBSD : phpMyAdmin — Multiple XSS due to unescaped HTML output in Trigger, Procedure and Event pages and Fetching the version information from a non-SSL site is vulnerable to a MITM attack













