Home page logo
/

fulldisclosure logo Full Disclosure mailing list archives

[SECURITY] [DSA 1306-1] New xulrunner packages fix several vulnerabilities
From: Moritz Muehlenhoff <jmm () debian org>
Date: Tue, 12 Jun 2007 17:57:27 +0200

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- --------------------------------------------------------------------------
Debian Security Advisory DSA 1306-1                    security () debian org
http://www.debian.org/security/                         Moritz Muehlenhoff
June 12th, 2007                         http://www.debian.org/security/faq
- --------------------------------------------------------------------------

Package        : xulrunner
Vulnerability  : several
Problem-Type   : remote
Debian-specific: no 
CVE ID         : CVE-2007-1362 CVE-2007-2867 CVE-2007-2868 CVE-2007-2869 CVE-2007-2870 CVE-2007-2871

Several remote vulnerabilities have been discovered in Xulrunner, a
runtime environment for XUL applications. The Common Vulnerabilities
and Exposures project identifies the following problems:

CVE-2007-1362 

    Nicolas Derouet discovered that Xulrunner performs insufficient
    validation of cookies, which could lead to denial of service.

CVE-2007-2867 

    Boris Zbarsky, Eli Friedman, Georgi Guninski, Jesse Ruderman, Martijn
    Wargers and Olli Pettay discovered crashes in the layout engine, which
    might allow the execution of arbitrary code.

CVE-2007-2868 

    Brendan Eich, Igor Bukanov, Jesse Ruderman, moz_bug_r_a4 and Wladimir
    Palant discovered crashes in the Javascript engine, which might allow
    the execution of arbitrary code.

CVE-2007-2869

    "Marcel" discovered that malicous web sites can cause massive
    ressource comsumption through the auto completion feature, resulting
    in denial of service.

CVE-2007-2870 

    "moz_bug_r_a4" discovered that adding an event listener through the
     addEventListener() function allows cross-site scripting.

CVE-2007-2871 

     Chris Thomas discovered that XUL popups can can be abused for spoofing
     or phishing attacks.

The oldstable distribution (sarge) doesn't include xulrunner.

For the stable distribution (etch) these problems have been fixed in
version 1.8.0.12-0etch1.

The unstable distribution (sid) will be fixed soon.

We recommend that you upgrade your xulrunner packages.

Upgrade Instructions
- --------------------

wget url
        will fetch the file for you
dpkg -i file.deb
        will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
        will update the internal database
apt-get upgrade
        will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.

Debian GNU/Linux 4.0 alias etch
- -------------------------------

  Source archives:

    http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.12-0etch1.dsc
      Size/MD5 checksum:     1313 4f4787356a8f51583fbe4ef6769d7498
    http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.12-0etch1.diff.gz
      Size/MD5 checksum:   142067 29a41f4dbe73b9763dd4ad75baa0be66
    http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.12.orig.tar.gz
      Size/MD5 checksum: 40834867 06773f13e3b0da3101fd4a9f91847d12

  Architecture independent components:

    http://security.debian.org/pool/updates/main/x/xulrunner/libmozillainterfaces-java_1.8.0.12-0etch1_all.deb
      Size/MD5 checksum:  1023966 eb58e44016511800f2d76975e5d29a5e
    http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs-dev_1.8.0.12-0etch1_all.deb
      Size/MD5 checksum:   174572 ac05853741bfbd01a0aac334c5358f13
    http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-dev_1.8.0.12-0etch1_all.deb
      Size/MD5 checksum:   206012 6edb06f9bac0856b3314652ba1f2e325
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-dev_1.8.0.12-0etch1_all.deb
      Size/MD5 checksum:   229480 61720cd9c866af82f152932338775ffb
    http://security.debian.org/pool/updates/main/x/xulrunner/libsmjs-dev_1.8.0.12-0etch1_all.deb
      Size/MD5 checksum:    34744 9154e206ef4d175281c3630d42270e12
    http://security.debian.org/pool/updates/main/x/xulrunner/libsmjs1_1.8.0.12-0etch1_all.deb
      Size/MD5 checksum:    34708 13f08f88301901b43d49134fe8950e23
    http://security.debian.org/pool/updates/main/x/xulrunner/libxul-common_1.8.0.12-0etch1_all.deb
      Size/MD5 checksum:  1047214 907a3c7639caa26d9f1399798937b099
    http://security.debian.org/pool/updates/main/x/xulrunner/libxul-dev_1.8.0.12-0etch1_all.deb
      Size/MD5 checksum:  2625926 d3b01bc9eb576ea71b7319161c15fab9

  Alpha architecture:

    http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d_1.8.0.12-0etch1_alpha.deb
      Size/MD5 checksum:   383488 7762735a8a35cfd1ab40e362d170a61e
    http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d-dbg_1.8.0.12-0etch1_alpha.deb
      Size/MD5 checksum:   762040 5ae63d36539158ef7d0d8d7d89632f49
    http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d_1.8.0.12-0etch1_alpha.deb
      Size/MD5 checksum:   160170 a134d61072c4539b17416a04b978dc90
    http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d-dbg_1.8.0.12-0etch1_alpha.deb
      Size/MD5 checksum:   299838 fe6041b079ef45b851bff94eb82f2c9d
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d_1.8.0.12-0etch1_alpha.deb
      Size/MD5 checksum:   905214 d7a81e329a463ce8573def6fb4090474
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d-dbg_1.8.0.12-0etch1_alpha.deb
      Size/MD5 checksum:  3184996 4a23030c515dfff3d39e7f341b5d49f0
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-tools_1.8.0.12-0etch1_alpha.deb
      Size/MD5 checksum:   737046 7ac61b5bc88394ff84de65539dccf8e1
    http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d_1.8.0.12-0etch1_alpha.deb
      Size/MD5 checksum:  7314770 ffbc3238c8554e9e5f29efb675ca22b8
    http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d-dbg_1.8.0.12-0etch1_alpha.deb
      Size/MD5 checksum: 45874602 e54c416393d3c6d9884444c7f44d31f5
    http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.8.0.12-0etch1_alpha.deb
      Size/MD5 checksum:   128968 a21436b7701dfa73d60496a40b52f9fd
    http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.8.0.12-0etch1_alpha.deb
      Size/MD5 checksum:    51082 83f4df05fbd5aaebe409bf58aa547f7b
    http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.12-0etch1_alpha.deb
      Size/MD5 checksum:   289888 3ca3e45c87316673dc52be172ed5691a
    http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-gnome-support_1.8.0.12-0etch1_alpha.deb
      Size/MD5 checksum:    69642 27cc0be080b9c8936d37fab8ff70806a

  AMD64 architecture:

    http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d_1.8.0.12-0etch1_amd64.deb
      Size/MD5 checksum:   352916 fe63e1cf0b2945802f3d1ec88d216b0a
    http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d-dbg_1.8.0.12-0etch1_amd64.deb
      Size/MD5 checksum:   751360 1cf47163be23b5424809a4224ae84983
    http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d_1.8.0.12-0etch1_amd64.deb
      Size/MD5 checksum:   146820 5a5c47faa15c5f1177735dbf3ce12527
    http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d-dbg_1.8.0.12-0etch1_amd64.deb
      Size/MD5 checksum:   302700 ccc40bcbb7308f8190ca9a387ff12c7e
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d_1.8.0.12-0etch1_amd64.deb
      Size/MD5 checksum:   807470 a2a43329bf5ee19e3a7c7a080ce0c01e
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d-dbg_1.8.0.12-0etch1_amd64.deb
      Size/MD5 checksum:  3171970 ca89032400dbbb80cdd7e7175ecc98d6
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-tools_1.8.0.12-0etch1_amd64.deb
      Size/MD5 checksum:   668782 d2cdfc5e79074952407ec66d224ba003
    http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d_1.8.0.12-0etch1_amd64.deb
      Size/MD5 checksum:  6310252 908312fd8ded3e71ed997d6f2e600f4b
    http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d-dbg_1.8.0.12-0etch1_amd64.deb
      Size/MD5 checksum: 45072426 68a27208995b46aec483f434910e3be2
    http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.8.0.12-0etch1_amd64.deb
      Size/MD5 checksum:   123980 dc880da1e99272908548a871b6d81393
    http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.8.0.12-0etch1_amd64.deb
      Size/MD5 checksum:    50984 a7b3037d097d231c217646ddc9779e97
    http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.12-0etch1_amd64.deb
      Size/MD5 checksum:   275904 67a6d8b4279161d3838bd304d1073b45
    http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-gnome-support_1.8.0.12-0etch1_amd64.deb
      Size/MD5 checksum:    67400 edab5096256e05e5de46701c89024553

  ARM architecture:

    http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d_1.8.0.12-0etch1_arm.deb
      Size/MD5 checksum:   323592 8e3a8568daeb0498a5ee8100dc728744
    http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d-dbg_1.8.0.12-0etch1_arm.deb
      Size/MD5 checksum:   702608 676d48a2a38b229e28dc83676ee07ab8
    http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d_1.8.0.12-0etch1_arm.deb
      Size/MD5 checksum:   134078 ff30694472c5868eff8e724043de60d3
    http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d-dbg_1.8.0.12-0etch1_arm.deb
      Size/MD5 checksum:   289398 302199ce15bc38f4e25041cdf4aa191b
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d_1.8.0.12-0etch1_arm.deb
      Size/MD5 checksum:   729908 00111501a530a0172c97d91e3df12ac0
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d-dbg_1.8.0.12-0etch1_arm.deb
      Size/MD5 checksum:  2964970 ccfcd52010153ba87601535186a0636c
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-tools_1.8.0.12-0etch1_arm.deb
      Size/MD5 checksum:   592556 47dba2209b0b26035e8f1cb671441f24
    http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d_1.8.0.12-0etch1_arm.deb
      Size/MD5 checksum:  5343324 6741d7b54d44133c072920b071f83ef0
    http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d-dbg_1.8.0.12-0etch1_arm.deb
      Size/MD5 checksum: 44592824 87f366af49f35064c77098a22d3b1e1f
    http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.8.0.12-0etch1_arm.deb
      Size/MD5 checksum:   116190 6fb4cbe7dd3596361a8121e15a706fb8
    http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.8.0.12-0etch1_arm.deb
      Size/MD5 checksum:    49368 31076333acf952aaa102dafb01d4616b
    http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.12-0etch1_arm.deb
      Size/MD5 checksum:   263108 eb6fdb566eff736d101e4ba32a725049
    http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-gnome-support_1.8.0.12-0etch1_arm.deb
      Size/MD5 checksum:    61468 4ec5b2304c0405e9a64f1ff1cffa0db4

  HP Precision architecture:

    http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d_1.8.0.12-0etch1_hppa.deb
      Size/MD5 checksum:   387240 b5237626f447bae58c67faaeafb6b4c2
    http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d-dbg_1.8.0.12-0etch1_hppa.deb
      Size/MD5 checksum:   748380 5dafc95b97b9e65005a5d38019b2cdce
    http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d_1.8.0.12-0etch1_hppa.deb
      Size/MD5 checksum:   158562 0af06f16b88de08ba3981b04e271b845
    http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d-dbg_1.8.0.12-0etch1_hppa.deb
      Size/MD5 checksum:   299726 041114d0006784421cac3ada097b8335
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d_1.8.0.12-0etch1_hppa.deb
      Size/MD5 checksum:   873226 83794b58c2686de6bbf77a73dfbe87c8
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d-dbg_1.8.0.12-0etch1_hppa.deb
      Size/MD5 checksum:  3101538 11bf59f7b8bc172f575373cfb5230534
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-tools_1.8.0.12-0etch1_hppa.deb
      Size/MD5 checksum:   701712 91dba6bc0d987511c29603a23a60a488
    http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d_1.8.0.12-0etch1_hppa.deb
      Size/MD5 checksum:  7513632 eafcb2c4315b182148d3948f3f4ef761
    http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d-dbg_1.8.0.12-0etch1_hppa.deb
      Size/MD5 checksum: 45977736 9cedf8f048f24eb0eeb9fec401a2147a
    http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.8.0.12-0etch1_hppa.deb
      Size/MD5 checksum:   131366 02ce80f549b850f58d131e2d4cf2371d
    http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.8.0.12-0etch1_hppa.deb
      Size/MD5 checksum:    51618 61c831b6ff809fa3af096e38eb4acdf1
    http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.12-0etch1_hppa.deb
      Size/MD5 checksum:   285324 3f21d4fc87f089cecef1defad0fc5906
    http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-gnome-support_1.8.0.12-0etch1_hppa.deb
      Size/MD5 checksum:    69122 6171b627a3e39a3959e69c007084c841

  Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d_1.8.0.12-0etch1_i386.deb
      Size/MD5 checksum:   332924 19e9352c24850d2051c9ac6172ab5ab1
    http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d-dbg_1.8.0.12-0etch1_i386.deb
      Size/MD5 checksum:   708430 15fc419de582aa73dd1b55052d9e399b
    http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d_1.8.0.12-0etch1_i386.deb
      Size/MD5 checksum:   137666 b6b8ef52b1db48b0ba2b742a0b450d9a
    http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d-dbg_1.8.0.12-0etch1_i386.deb
      Size/MD5 checksum:   294476 f781af4aefc05ca7e2881dcc5cffc2c4
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d_1.8.0.12-0etch1_i386.deb
      Size/MD5 checksum:   740708 925ace5f95d24a46bcccc9361fa56bc5
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d-dbg_1.8.0.12-0etch1_i386.deb
      Size/MD5 checksum:  3031990 c36ea3626eb39348884fa81bb5ef6de1
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-tools_1.8.0.12-0etch1_i386.deb
      Size/MD5 checksum:   626338 8a76dc27d429344cd54ff2a58731dac8
    http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d_1.8.0.12-0etch1_i386.deb
      Size/MD5 checksum:  5353838 edde2c3c72836d403dfed328168e37d0
    http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d-dbg_1.8.0.12-0etch1_i386.deb
      Size/MD5 checksum: 44553380 12527a08888a7e59a43e3f5732b226d9
    http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.8.0.12-0etch1_i386.deb
      Size/MD5 checksum:   116284 f5d44eaf328f983705aba605834e34a8
    http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.8.0.12-0etch1_i386.deb
      Size/MD5 checksum:    49678 e54627a554cb941e794a32adb2027d28
    http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.12-0etch1_i386.deb
      Size/MD5 checksum:   265938 22e30a153c21b48370667b1a285cc6b2
    http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-gnome-support_1.8.0.12-0etch1_i386.deb
      Size/MD5 checksum:    61842 2042d9bae98b3c6021492aa43e2e8c3b

  Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d_1.8.0.12-0etch1_ia64.deb
      Size/MD5 checksum:   528812 b8c28fec22d6a717c72b813463b62306
    http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d-dbg_1.8.0.12-0etch1_ia64.deb
      Size/MD5 checksum:   754184 addbb37106095e21f8ef71d7f873d2fe
    http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d_1.8.0.12-0etch1_ia64.deb
      Size/MD5 checksum:   197026 3f6499f96b15cb0f5de6067b60eef090
    http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d-dbg_1.8.0.12-0etch1_ia64.deb
      Size/MD5 checksum:   285338 39e4597412558247a923911c4eb7c6fa
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d_1.8.0.12-0etch1_ia64.deb
      Size/MD5 checksum:  1121014 7fa13b84ee6480f2b538e9d028af6e29
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d-dbg_1.8.0.12-0etch1_ia64.deb
      Size/MD5 checksum:  3051250 9b4eb6f104516f46f82a2ad4186868e6
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-tools_1.8.0.12-0etch1_ia64.deb
      Size/MD5 checksum:   936330 467dabab643d87a868d1fb7ad62003b3
    http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d_1.8.0.12-0etch1_ia64.deb
      Size/MD5 checksum:  9631722 e71ef55142e7be74c69bf64807ba57f6
    http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d-dbg_1.8.0.12-0etch1_ia64.deb
      Size/MD5 checksum: 45283826 12d621ad4ffc64fe24688a103eceb6a3
    http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.8.0.12-0etch1_ia64.deb
      Size/MD5 checksum:   147730 9ab407079040f6d472fe394611cd283e
    http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.8.0.12-0etch1_ia64.deb
      Size/MD5 checksum:    55504 cf12d13012265ac707777c4ce7a30870
    http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.12-0etch1_ia64.deb
      Size/MD5 checksum:   331482 ccc79d0c66401dbb80f7e520ce79482c
    http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-gnome-support_1.8.0.12-0etch1_ia64.deb
      Size/MD5 checksum:    79014 49b1eb29f62f79394ddfc7e8bba73f0a

  Big endian MIPS architecture:

    http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d_1.8.0.12-0etch1_mips.deb
      Size/MD5 checksum:   349536 c3f8a5e52e2a157a718c54188b6d747b
    http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d-dbg_1.8.0.12-0etch1_mips.deb
      Size/MD5 checksum:   781874 4395ac1529b801a872843d088b2370ff
    http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d_1.8.0.12-0etch1_mips.deb
      Size/MD5 checksum:   144602 55dc285ccb8dd769e4c0be65e5cf7207
    http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d-dbg_1.8.0.12-0etch1_mips.deb
      Size/MD5 checksum:   310762 9eca6f68c5af19311b86b83160d44c7f
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d_1.8.0.12-0etch1_mips.deb
      Size/MD5 checksum:   807352 48c80607d8cc12eec3dd437a7bc56320
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d-dbg_1.8.0.12-0etch1_mips.deb
      Size/MD5 checksum:  3286276 05a113a3e38b9ec7a3a26d99d80d6c5d
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-tools_1.8.0.12-0etch1_mips.deb
      Size/MD5 checksum:   668994 9cfdd64f8ae34e2a9e59b2eeb5951646
    http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d_1.8.0.12-0etch1_mips.deb
      Size/MD5 checksum:  5925444 489c55633bbb6f247cb557feee9f2d86
    http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d-dbg_1.8.0.12-0etch1_mips.deb
      Size/MD5 checksum: 46607494 9415e46c465361981edc5d88d99a34ee
    http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.8.0.12-0etch1_mips.deb
      Size/MD5 checksum:   117052 0d87aad09b87ff8e9bab1e5645fa8c49
    http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.8.0.12-0etch1_mips.deb
      Size/MD5 checksum:    50130 dee6b13d3a36b40e1f5614e21e1d0cf9
    http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.12-0etch1_mips.deb
      Size/MD5 checksum:   271768 ee71dceff7b6ae6d1395d9de76da71d8
    http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-gnome-support_1.8.0.12-0etch1_mips.deb
      Size/MD5 checksum:    63332 f3f0723efe5610ca01c627f8e574183f

  Little endian MIPS architecture:

    http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d_1.8.0.12-0etch1_mipsel.deb
      Size/MD5 checksum:   348430 83cfdc0cbe52ebf73ea71752ed148aac
    http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d-dbg_1.8.0.12-0etch1_mipsel.deb
      Size/MD5 checksum:   763144 4263ee2cea49444b9d64f5942aea2f37
    http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d_1.8.0.12-0etch1_mipsel.deb
      Size/MD5 checksum:   144216 7d5c19c9bbb1d3cca7a7704367eb1239
    http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d-dbg_1.8.0.12-0etch1_mipsel.deb
      Size/MD5 checksum:   304090 18684c2f0e06e1e3e5d83fe9c3243296
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d_1.8.0.12-0etch1_mipsel.deb
      Size/MD5 checksum:   783822 7623b39eec2026a4e00105aa0730d7c6
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d-dbg_1.8.0.12-0etch1_mipsel.deb
      Size/MD5 checksum:  3184078 badc9ed2449a95860c88f08b388d61b4
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-tools_1.8.0.12-0etch1_mipsel.deb
      Size/MD5 checksum:   668760 89f9142b8b42cee2440f4c084de8a060
    http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d_1.8.0.12-0etch1_mipsel.deb
      Size/MD5 checksum:  5727546 c1d85bacbf70e822ada14d4d7fe037bd
    http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d-dbg_1.8.0.12-0etch1_mipsel.deb
      Size/MD5 checksum: 45223572 29aab4c2197e6c1531dacc985b2a241c
    http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.8.0.12-0etch1_mipsel.deb
      Size/MD5 checksum:   116842 8ee267aaa60642a84bbee4de83b0c6eb
    http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.8.0.12-0etch1_mipsel.deb
      Size/MD5 checksum:    50192 b6ef945bd7f2b61965231d5b3a4596bc
    http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.12-0etch1_mipsel.deb
      Size/MD5 checksum:   272552 02ec24cc4692ae05ebf7a84f3093e3a6
    http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-gnome-support_1.8.0.12-0etch1_mipsel.deb
      Size/MD5 checksum:    63124 da41f4e2dbfd504c69085dd7a7bc8da6

  PowerPC architecture:

    http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d_1.8.0.12-0etch1_powerpc.deb
      Size/MD5 checksum:   346782 24b240737f6ed533ca776c47652bc728
    http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d-dbg_1.8.0.12-0etch1_powerpc.deb
      Size/MD5 checksum:   771734 11568c1c587bd611c603ef96195629f4
    http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d_1.8.0.12-0etch1_powerpc.deb
      Size/MD5 checksum:   145982 0f48aee6f9b16f80e5b820dd27bf4ad2
    http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d-dbg_1.8.0.12-0etch1_powerpc.deb
      Size/MD5 checksum:   309260 f5339856bc127f0561fac235cbc03a22
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d_1.8.0.12-0etch1_powerpc.deb
      Size/MD5 checksum:   808294 c7e6d09046216b7decb2015e4abd310a
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d-dbg_1.8.0.12-0etch1_powerpc.deb
      Size/MD5 checksum:  3205924 3bf336e7421523d4c44cceade4ce8e32
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-tools_1.8.0.12-0etch1_powerpc.deb
      Size/MD5 checksum:   638390 a1f1d89b0a8c16078a4ca3d38b8849b7
    http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d_1.8.0.12-0etch1_powerpc.deb
      Size/MD5 checksum:  6060390 314a1e183f5e2572c7a48d98827ee354
    http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d-dbg_1.8.0.12-0etch1_powerpc.deb
      Size/MD5 checksum: 46617004 2af2f942a9910451fb4d144a10c981e1
    http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.8.0.12-0etch1_powerpc.deb
      Size/MD5 checksum:   121740 3747df9e092ee7489487000cf459aa51
    http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.8.0.12-0etch1_powerpc.deb
      Size/MD5 checksum:    51458 12df7de41ec30a473efb5ce641d1b770
    http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.12-0etch1_powerpc.deb
      Size/MD5 checksum:   276690 8f7b1f0608c1a4093979fc2f2ec42a98
    http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-gnome-support_1.8.0.12-0etch1_powerpc.deb
      Size/MD5 checksum:    63058 b1b4faf5d8ae92836ef59ed2855c737f

  IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d_1.8.0.12-0etch1_s390.deb
      Size/MD5 checksum:   369836 4cf54115f24b470c3c220fdf6b10620a
    http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d-dbg_1.8.0.12-0etch1_s390.deb
      Size/MD5 checksum:   754706 7b882d04cae1fa5654f6a31aa7a6d25d
    http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d_1.8.0.12-0etch1_s390.deb
      Size/MD5 checksum:   158592 d7df83db626e3f60b5042c33f136a42d
    http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d-dbg_1.8.0.12-0etch1_s390.deb
      Size/MD5 checksum:   304556 6dac55e34c1dd52e6cad6d88821545d1
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d_1.8.0.12-0etch1_s390.deb
      Size/MD5 checksum:   896718 6e98295250efe9f8a497bbebdc39a9e3
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d-dbg_1.8.0.12-0etch1_s390.deb
      Size/MD5 checksum:  3178412 777513a3e1649150765765b3574f48c3
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-tools_1.8.0.12-0etch1_s390.deb
      Size/MD5 checksum:   687036 80036c22bcebe56767dc690257df3752
    http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d_1.8.0.12-0etch1_s390.deb
      Size/MD5 checksum:  6782518 cec36665deb15f28ebe1cbe4a94c6238
    http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d-dbg_1.8.0.12-0etch1_s390.deb
      Size/MD5 checksum: 45937774 47c01e8654480df0eb8f737133162948
    http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.8.0.12-0etch1_s390.deb
      Size/MD5 checksum:   124828 c6994af884ccf2823aa84b1846b279ff
    http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.8.0.12-0etch1_s390.deb
      Size/MD5 checksum:    51712 81d86a7e56fadc4c7ac49a97e160fe25
    http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.12-0etch1_s390.deb
      Size/MD5 checksum:   280368 74eb0266128ca06210fd9f4148e18272
    http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-gnome-support_1.8.0.12-0etch1_s390.deb
      Size/MD5 checksum:    68054 b03e3232b24b303a21b84cb2a7c419ce

  Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d_1.8.0.12-0etch1_sparc.deb
      Size/MD5 checksum:   320766 663075e2434f26c028eb94bfa3d82f23
    http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d-dbg_1.8.0.12-0etch1_sparc.deb
      Size/MD5 checksum:   672016 e780972831e8105d8fd62d60f8bad5eb
    http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d_1.8.0.12-0etch1_sparc.deb
      Size/MD5 checksum:   134784 f49609a2307eab562b7322391188bc0a
    http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d-dbg_1.8.0.12-0etch1_sparc.deb
      Size/MD5 checksum:   282070 18dcc342f0acbd16f953c6d8251823dc
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d_1.8.0.12-0etch1_sparc.deb
      Size/MD5 checksum:   717994 de31088978544559243a9191b21f4d45
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d-dbg_1.8.0.12-0etch1_sparc.deb
      Size/MD5 checksum:  2853272 a73847fe770158ce9db3bd2bc7510eae
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-tools_1.8.0.12-0etch1_sparc.deb
      Size/MD5 checksum:   584140 45767de7a4e759ed2ae1881f5c86adcf
    http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d_1.8.0.12-0etch1_sparc.deb
      Size/MD5 checksum:  5662364 aa43ce56fc0b4f23445d3c1f1c29ec11
    http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d-dbg_1.8.0.12-0etch1_sparc.deb
      Size/MD5 checksum: 44648600 c9e41d11ca80663265548e05fcde5427
    http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.8.0.12-0etch1_sparc.deb
      Size/MD5 checksum:   117066 bcd162709901fff579a98dc11a743c39
    http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.8.0.12-0etch1_sparc.deb
      Size/MD5 checksum:    49578 2e60f50fa37cbc80fe58f6e321479d55
    http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.12-0etch1_sparc.deb
      Size/MD5 checksum:   258990 7fd68f7047886d4831a90398ff0bd2a5
    http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-gnome-support_1.8.0.12-0etch1_sparc.deb
      Size/MD5 checksum:    61364 d4b0edf8d0756f4bf8a6260c22c0b7d5


  These files will probably be moved into the stable distribution on
  its next update.

- ---------------------------------------------------------------------------------
For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
Mailing list: debian-security-announce () lists debian org
Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFGbsIsXm3vHE4uyloRAutiAKCL076aesSzgt3OYmWFB1FuRI1zJgCgyNEB
xbtoy1RRaYOoNWFOmVgf2qc=
=Clo1
-----END PGP SIGNATURE-----

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


  By Date           By Thread  

Current thread:
  • [SECURITY] [DSA 1306-1] New xulrunner packages fix several vulnerabilities Moritz Muehlenhoff (Jun 12)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]