Home page logo
/

fulldisclosure logo Full Disclosure mailing list archives

[SECURITY] [DSA 1797-1] New xulrunner packages fix several vulnerabilities
From: Moritz Muehlenhoff <jmm () debian org>
Date: Sat, 9 May 2009 15:00:16 +0200

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- ------------------------------------------------------------------------
Debian Security Advisory DSA-1797-1                  security () debian org
http://www.debian.org/security/                       Moritz Muehlenhoff
May 09, 2009                          http://www.debian.org/security/faq
- ------------------------------------------------------------------------

Package        : xulrunner
Vulnerability  : several
Problem-Type   : remote
Debian-specific: no
CVE ID         : CVE-2009-0652 CVE-2009-1302 CVE-2009-1303 CVE-2009-1304 CVE-2009-1305 CVE-2009-1306 CVE-2009-1307 
CVE-2009-1308 CVE-2009-1309 CVE-2009-1311

Several remote vulnerabilities have been discovered in Xulrunner, a 
runtime environment for XUL applications, such as the Iceweasel web
browser. The Common Vulnerabilities and Exposures project identifies
the following problems:

CVE-2009-0652

    Moxie Marlinspike discovered that Unicode box drawing characters inside of
    internationalised domain names could be used for phishing attacks.

CVE-2009-1302

    Olli Pettay, Martijn Wargers, Mats Palmgren, Oleg Romashin, Jesse Ruderman
    and Gary Kwong reported crashes in the in the layout engine, which might
    allow the execution of arbitrary code.

CVE-2009-1303

    Olli Pettay, Martijn Wargers, Mats Palmgren, Oleg Romashin, Jesse Ruderman
    and Gary Kwong reported crashes in the in the layout engine, which might
    allow the execution of arbitrary code.

CVE-2009-1304

    Igor Bukanov and Bob Clary discovered crashes in the Javascript engine,
    which might allow the execution of arbitrary code.

CVE-2009-1305

    Igor Bukanov and Bob Clary discovered crashes in the Javascript engine,
    which might allow the execution of arbitrary code.

CVE-2009-1306

    Daniel Veditz discovered that the Content-Disposition: header is ignored
    within the jar: URI scheme.

CVE-2009-1307

    Gregory Fleischer discovered that the same-origin policy for Flash files
    is inproperly enforced for files loaded through the view-source scheme,
    which may result in bypass of cross-domain policy restrictions.

CVE-2009-1308

    Cefn Hoile discovered that sites, which allow the embedding of third-party
    stylesheets are vulnerable to cross-site scripting attacks through XBL
    bindings.

CVE-2009-1309

    "moz_bug_r_a4" discovered bypasses of the same-origin policy in the
    XMLHttpRequest Javascript API and the XPCNativeWrapper.

CVE-2009-1311

    Paolo Amadini discovered that incorrect handling of POST data when
    saving a web site with an embedded frame may lead to information disclosure.

CVE-2009-1312

    It was discovered that Iceweasel allows Refresh: headers to redirect
    to Javascript URIs, resulting in cross-site scripting.

For the stable distribution (lenny), these problems have been fixed
in version 1.9.0.9-0lenny2.

As indicated in the Etch release notes, security support for the
Mozilla products in the oldstable distribution needed to be stopped
before the end of the regular Etch security maintenance life cycle.
You are strongly encouraged to upgrade to stable or switch to a still
supported browser.

For the unstable distribution (sid), these problems have been fixed in
version 1.9.0.9-1.

We recommend that you upgrade your xulrunner packages.

Upgrade instructions
- --------------------

wget url
        will fetch the file for you
dpkg -i file.deb
        will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
        will update the internal database
apt-get upgrade
        will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.


Debian GNU/Linux 5.0 alias lenny
- --------------------------------

Stable updates are available for alpha, amd64, arm, armel, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc.

Source archives:

  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.9.0.9-0lenny2.diff.gz
    Size/MD5 checksum:   117026 d09669d48cd57ec9457f027e1cbb6513
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.9.0.9.orig.tar.gz
    Size/MD5 checksum: 43676083 2d15d3f226cf0fc7210eb112cdbd2869
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.9.0.9-0lenny2.dsc
    Size/MD5 checksum:     1785 4dfb97c89b31cc0395fe3e07ace099ad

Architecture independent packages:

  http://security.debian.org/pool/updates/main/x/xulrunner/libmozillainterfaces-java_1.9.0.9-0lenny2_all.deb
    Size/MD5 checksum:  1483776 a42bf756251f9e3e206ede146db8f956

alpha architecture (DEC Alpha)

  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9-gnome-support_1.9.0.9-0lenny2_alpha.deb
    Size/MD5 checksum:   111514 f9b3e0f98e2d20a0b809d21f8cf972e8
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9-dbg_1.9.0.9-0lenny2_alpha.deb
    Size/MD5 checksum: 51060838 f7811d5fce5d7a9d9543be65a03cec4b
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs-dev_1.9.0.9-0lenny2_alpha.deb
    Size/MD5 checksum:   220742 2c1ed1e0ca8e9ca72875c69455559b26
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9_1.9.0.9-0lenny2_alpha.deb
    Size/MD5 checksum:  9481232 2a10dd4c6875e7c8271fef8ba99dcedb
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs1d_1.9.0.9-0lenny2_alpha.deb
    Size/MD5 checksum:   428902 03eeed45c2d4ed5197af04aa56a0e7c3
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-dev_1.9.0.9-0lenny2_alpha.deb
    Size/MD5 checksum:  3648686 e8dcddf93a00cde658b9098048d77261
  http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.9.0.9-0lenny2_alpha.deb
    Size/MD5 checksum:   163408 fea42d292bf78fe08f73d98b2d9e178a
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs1d-dbg_1.9.0.9-0lenny2_alpha.deb
    Size/MD5 checksum:   933068 ee853413c63b6fe073c58e2701bc00ab
  http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.9.0.9-0lenny2_alpha.deb
    Size/MD5 checksum:    71174 53af8db13e823906067c8385b32b2dcc

amd64 architecture (AMD x86_64 (AMD64))

  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9_1.9.0.9-0lenny2_amd64.deb
    Size/MD5 checksum:  7727524 36d598c003dcb0b8e4c17f360b0681a3
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs1d-dbg_1.9.0.9-0lenny2_amd64.deb
    Size/MD5 checksum:   887532 cccbd9c7cf928cdbf524349874143a70
  http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.9.0.9-0lenny2_amd64.deb
    Size/MD5 checksum:   151242 0075b6dc5736b7ffb43161a20cd569e9
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs1d_1.9.0.9-0lenny2_amd64.deb
    Size/MD5 checksum:   371988 bb3c915099c05bc4ea9f0e9c0f5dcf4c
  http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.9.0.9-0lenny2_amd64.deb
    Size/MD5 checksum:    68952 92c0e7c9a369e29c2eaa10c508e9ef00
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9-dbg_1.9.0.9-0lenny2_amd64.deb
    Size/MD5 checksum: 50280932 6b6a63494c6f7411a8e98331ae952fb6
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9-gnome-support_1.9.0.9-0lenny2_amd64.deb
    Size/MD5 checksum:   100880 ab27a51c6ad46ead60760e90519f4e5c
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-dev_1.9.0.9-0lenny2_amd64.deb
    Size/MD5 checksum:  3583500 7cf24c1188cb886612a2c26915467f60
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs-dev_1.9.0.9-0lenny2_amd64.deb
    Size/MD5 checksum:   220552 638e195878722d207df6f63d22dc0190

arm architecture (ARM)

  http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.9.0.9-0lenny2_arm.deb
    Size/MD5 checksum:    67188 87bc838f4f3670f9351c24fc1a0bee83
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9-dbg_1.9.0.9-0lenny2_arm.deb
    Size/MD5 checksum: 49237086 71c4d1c873dfdcea156ac2ff17fb7bdd
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-dev_1.9.0.9-0lenny2_arm.deb
    Size/MD5 checksum:  3578816 4e2ff63e582037fec48658747f99ba0a
  http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.9.0.9-0lenny2_arm.deb
    Size/MD5 checksum:   141146 48e1e4f7e842de538505c558d32626ce
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs1d_1.9.0.9-0lenny2_arm.deb
    Size/MD5 checksum:   348552 6e33e224e6495782a2770c9e2517c785
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs1d-dbg_1.9.0.9-0lenny2_arm.deb
    Size/MD5 checksum:   814400 6d91a49ce94c64d1d168c6b78a6b41a4
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9-gnome-support_1.9.0.9-0lenny2_arm.deb
    Size/MD5 checksum:    83412 62e4f3c8140c7dd842c08b3cae2d90be
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9_1.9.0.9-0lenny2_arm.deb
    Size/MD5 checksum:  6790870 429d3a80ad4929f50f932bc2a9f55d70
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs-dev_1.9.0.9-0lenny2_arm.deb
    Size/MD5 checksum:   222650 88d47b4b6bfa2fff6fbb52f444d55910

armel architecture (ARM EABI)

  http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.9.0.9-0lenny2_armel.deb
    Size/MD5 checksum:   140878 62b5c5aff1efdd654e4fdb336241df71
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-dev_1.9.0.9-0lenny2_armel.deb
    Size/MD5 checksum:  3576452 b1f3f4274747850f65ff6c6bc0321a5a
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9-gnome-support_1.9.0.9-0lenny2_armel.deb
    Size/MD5 checksum:    83860 74c170216a259ceb9c65f15654d9f1bf
  http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.9.0.9-0lenny2_armel.deb
    Size/MD5 checksum:    68854 ebabe0aff31cbf050f5539dd65841d84
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs1d_1.9.0.9-0lenny2_armel.deb
    Size/MD5 checksum:   350300 ecf4a8c2404b099f24f04b6b9da4d29a
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9_1.9.0.9-0lenny2_armel.deb
    Size/MD5 checksum:  6941614 70f8d7debcdadac8f7344d483102966c
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs-dev_1.9.0.9-0lenny2_armel.deb
    Size/MD5 checksum:   222324 838ad274ad9c4d1ae4520d20337ef5f5
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9-dbg_1.9.0.9-0lenny2_armel.deb
    Size/MD5 checksum: 50076310 ab97521543110a0fbc5f2ef5fa24a1ba
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs1d-dbg_1.9.0.9-0lenny2_armel.deb
    Size/MD5 checksum:   818918 67f9d2de565405f736be414f22883a3d

hppa architecture (HP PA RISC)

  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs1d_1.9.0.9-0lenny2_hppa.deb
    Size/MD5 checksum:   408960 b804388039608c12f3839cf661f66198
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs-dev_1.9.0.9-0lenny2_hppa.deb
    Size/MD5 checksum:   221864 dc011e19e0e51ca360814e2ccac45ff5
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9-dbg_1.9.0.9-0lenny2_hppa.deb
    Size/MD5 checksum: 51165016 dc62b362f3a484e63dfd4c4e0a3abd8f
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9-gnome-support_1.9.0.9-0lenny2_hppa.deb
    Size/MD5 checksum:   105354 e56c6f430f6bf0c440d32d9d77f521ec
  http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.9.0.9-0lenny2_hppa.deb
    Size/MD5 checksum:    70442 a93054b9893c8560744735056faa0782
  http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.9.0.9-0lenny2_hppa.deb
    Size/MD5 checksum:   158222 763d8678b7b0847d5892ecd91aa1aed2
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-dev_1.9.0.9-0lenny2_hppa.deb
    Size/MD5 checksum:  3618860 9f74be813e8e955fc0e17ddf2ba956ed
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9_1.9.0.9-0lenny2_hppa.deb
    Size/MD5 checksum:  9497008 f4b428777416a985792a4205fe2c4559
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs1d-dbg_1.9.0.9-0lenny2_hppa.deb
    Size/MD5 checksum:   895604 a40bd99de09688c3cebc1afb8f9b0ed3

i386 architecture (Intel ia32)

  http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.9.0.9-0lenny2_i386.deb
    Size/MD5 checksum:    67304 a365211be353564113d2dd7674902022
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9-dbg_1.9.0.9-0lenny2_i386.deb
    Size/MD5 checksum: 49446708 55375bd2f9c55fad85bdf642ba148b8b
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs-dev_1.9.0.9-0lenny2_i386.deb
    Size/MD5 checksum:   222280 a30bec3e1243fbcc85e10b50c70b0eec
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs1d-dbg_1.9.0.9-0lenny2_i386.deb
    Size/MD5 checksum:   849508 051f75cda756e30664ce1b90d884def5
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-dev_1.9.0.9-0lenny2_i386.deb
    Size/MD5 checksum:  3562302 1534d9cba1162456023d4bef69b786e0
  http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.9.0.9-0lenny2_i386.deb
    Size/MD5 checksum:   140878 5520c260080eb9c08bbd1708d36eaecd
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9_1.9.0.9-0lenny2_i386.deb
    Size/MD5 checksum:  6590836 c632ce21a2a5fd4257283ff7cf32bef4
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9-gnome-support_1.9.0.9-0lenny2_i386.deb
    Size/MD5 checksum:    78612 353db3ef38a240bb039c550c33616610
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs1d_1.9.0.9-0lenny2_i386.deb
    Size/MD5 checksum:   348080 1f8dd3a001b62aabbce52ded83717f77

ia64 architecture (Intel ia64)

  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs1d_1.9.0.9-0lenny2_ia64.deb
    Size/MD5 checksum:   538866 a0fc35488ffb492956c1b2602f3332fa
  http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.9.0.9-0lenny2_ia64.deb
    Size/MD5 checksum:   179534 c70d0f8e437de971416dd66af25ecffd
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs-dev_1.9.0.9-0lenny2_ia64.deb
    Size/MD5 checksum:   222276 45cc6e76a2aae05706272ab4f0b2b9ef
  http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.9.0.9-0lenny2_ia64.deb
    Size/MD5 checksum:    75556 e70c1001ce1cba88bcd2970e271af0ff
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9-gnome-support_1.9.0.9-0lenny2_ia64.deb
    Size/MD5 checksum:   121026 828e0e511c559d05c40c88171bd03aff
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9_1.9.0.9-0lenny2_ia64.deb
    Size/MD5 checksum: 11282130 23f4515cf3fb9ea5af74da10235236ee
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9-dbg_1.9.0.9-0lenny2_ia64.deb
    Size/MD5 checksum: 49618524 635a2adbe4c8c0723e2f3e598c172872
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-dev_1.9.0.9-0lenny2_ia64.deb
    Size/MD5 checksum:  3393098 3348f2fda7f048257b66b9b1934c955b
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs1d-dbg_1.9.0.9-0lenny2_ia64.deb
    Size/MD5 checksum:   809114 78ae7bcb24e0b8710336fb170d82e90e

mips architecture (MIPS (Big Endian))

  http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.9.0.9-0lenny2_mips.deb
    Size/MD5 checksum:   144800 6b1d8b5d6844b88a87c6f0d64fd3a5cc
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs-dev_1.9.0.9-0lenny2_mips.deb
    Size/MD5 checksum:   222288 42ff24ac5979ebccbfeeec2409a18efd
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9-dbg_1.9.0.9-0lenny2_mips.deb
    Size/MD5 checksum: 51798468 200dcac5fb819d0093740d8b528c20a5
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs1d-dbg_1.9.0.9-0lenny2_mips.deb
    Size/MD5 checksum:   914892 24a8f94d6576adfaf8219489667e9349
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs1d_1.9.0.9-0lenny2_mips.deb
    Size/MD5 checksum:   377492 3da9e13727df30690dab740c3a11a4f1
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9-gnome-support_1.9.0.9-0lenny2_mips.deb
    Size/MD5 checksum:    96578 72d433b5b9755ead0e9519140b7e4c17
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9_1.9.0.9-0lenny2_mips.deb
    Size/MD5 checksum:  7635294 eab0a84b74f7a707722e6b593fa7fe45
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-dev_1.9.0.9-0lenny2_mips.deb
    Size/MD5 checksum:  3303462 e35a5582f64f0b03baaf34344766286d
  http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.9.0.9-0lenny2_mips.deb
    Size/MD5 checksum:    69138 c0a61b85fd08547ef785f1ab664fc272

mipsel architecture (MIPS (Little Endian))

  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs-dev_1.9.0.9-0lenny2_mipsel.deb
    Size/MD5 checksum:   222290 5d4e1c8a7defd4812f1cdc90c3376b79
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9_1.9.0.9-0lenny2_mipsel.deb
    Size/MD5 checksum:  7366384 daadd45a701ee1372b13d04c479e8945
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs1d-dbg_1.9.0.9-0lenny2_mipsel.deb
    Size/MD5 checksum:   896196 bb30cfb8930a0f56f007779a114d8cce
  http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.9.0.9-0lenny2_mipsel.deb
    Size/MD5 checksum:   144512 d9b0d61807107a8d6b6b9cd88ac78f2d
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9-gnome-support_1.9.0.9-0lenny2_mipsel.deb
    Size/MD5 checksum:    96276 fdbf9354e6a7f13ffbdc15631425bedc
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9-dbg_1.9.0.9-0lenny2_mipsel.deb
    Size/MD5 checksum: 49922418 08204077c0e28e67e8126b0a08bb5cfa
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-dev_1.9.0.9-0lenny2_mipsel.deb
    Size/MD5 checksum:  3304646 31bdebd6c18527ac71407f9ffab254b9
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs1d_1.9.0.9-0lenny2_mipsel.deb
    Size/MD5 checksum:   375296 2cff3b541b78c45eac1374b486f3185a
  http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.9.0.9-0lenny2_mipsel.deb
    Size/MD5 checksum:    69060 d8b85f76f874fcfba60dbdf88dfa1ba9

powerpc architecture (PowerPC)

  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs1d-dbg_1.9.0.9-0lenny2_powerpc.deb
    Size/MD5 checksum:   885826 cd7a75d90beeedc19ed56cab418f9229
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs1d_1.9.0.9-0lenny2_powerpc.deb
    Size/MD5 checksum:   359694 1a4bd1074a8d9e02af3d3e4ca6b6e184
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-dev_1.9.0.9-0lenny2_powerpc.deb
    Size/MD5 checksum:  3576628 487af4934c26c9607f2c973211f9e893
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9_1.9.0.9-0lenny2_powerpc.deb
    Size/MD5 checksum:  7282378 37d983a3b8ac149e3425f196a0a76cee
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs-dev_1.9.0.9-0lenny2_powerpc.deb
    Size/MD5 checksum:   222610 ed41ecc9d50a8e8cdb97f07c02d40635
  http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.9.0.9-0lenny2_powerpc.deb
    Size/MD5 checksum:    72514 cc2a157ba460b58ecb6d4bb1645463b0
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9-gnome-support_1.9.0.9-0lenny2_powerpc.deb
    Size/MD5 checksum:    94214 4d9018798582ddf501e7e96fbb1cb52f
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9-dbg_1.9.0.9-0lenny2_powerpc.deb
    Size/MD5 checksum: 51342054 ff91b365569570f23bdc050ef1b10aab
  http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.9.0.9-0lenny2_powerpc.deb
    Size/MD5 checksum:   152434 5de3549eb40701dcf4280395a9d46ef6

s390 architecture (IBM S/390)

  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs-dev_1.9.0.9-0lenny2_s390.deb
    Size/MD5 checksum:   222272 7520554f059b97d8107a70b9cb4c7d23
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-dev_1.9.0.9-0lenny2_s390.deb
    Size/MD5 checksum:  3302468 4c4f9963496b1e03307c049d4d0c8d71
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9_1.9.0.9-0lenny2_s390.deb
    Size/MD5 checksum:  8375790 f83467abcb35b7f21e36ae4dccfd2894
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs1d_1.9.0.9-0lenny2_s390.deb
    Size/MD5 checksum:   404194 939a4ac485c2889a8d8cefc01b099c3c
  http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.9.0.9-0lenny2_s390.deb
    Size/MD5 checksum:   155590 ec7601e7165fb077dc49ad5106ccbbe8
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9-gnome-support_1.9.0.9-0lenny2_s390.deb
    Size/MD5 checksum:   105062 d39129d6b2734ac40116873346998598
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9-dbg_1.9.0.9-0lenny2_s390.deb
    Size/MD5 checksum: 51124872 12297ecc689f3b5271c83e741ec88f0b
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs1d-dbg_1.9.0.9-0lenny2_s390.deb
    Size/MD5 checksum:   906520 aae8f82cb27c09cb33ed382c38c369fc
  http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.9.0.9-0lenny2_s390.deb
    Size/MD5 checksum:    72060 1d46777a0678c4e3e5d8fd2643109325

sparc architecture (Sun SPARC/UltraSPARC)

  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9-gnome-support_1.9.0.9-0lenny2_sparc.deb
    Size/MD5 checksum:    83282 3acccfab973fea6f2b78d9943c771b97
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs1d-dbg_1.9.0.9-0lenny2_sparc.deb
    Size/MD5 checksum:   819016 51ece19aac73ae8ca1f6bd17334267ba
  http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.9.0.9-0lenny2_sparc.deb
    Size/MD5 checksum:   143104 c80a213a549b2720b5aa257c590487dd
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9-dbg_1.9.0.9-0lenny2_sparc.deb
    Size/MD5 checksum: 49311996 719762824e3ea8e87311872457dbe714
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-dev_1.9.0.9-0lenny2_sparc.deb
    Size/MD5 checksum:  3573006 993e514fcf0bbea88f945b12ced5677c
  http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.9.0.9-0lenny2_sparc.deb
    Size/MD5 checksum:    69290 2f1e603498b14c1ff42a7b7dad8896b7
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9_1.9.0.9-0lenny2_sparc.deb
    Size/MD5 checksum:  7160766 f33069ea4089317a616f12fbe1a4bbd0
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs-dev_1.9.0.9-0lenny2_sparc.deb
    Size/MD5 checksum:   222422 225e2f431d1ca2358737199b383b065d
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs1d_1.9.0.9-0lenny2_sparc.deb
    Size/MD5 checksum:   347584 5cfa8a467e38c4fdfbaa941da15ef737


  These files will probably be moved into the stable distribution on
  its next update.

- ---------------------------------------------------------------------------------
For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
Mailing list: debian-security-announce () lists debian org
Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iEYEARECAAYFAkoFfhcACgkQXm3vHE4uylo9ZgCgld+5uD+UFvGy2JlWOZJf7q1b
EWcAnAwBOeNtIfgBlmM6S9U+AZNWY+2J
=JQcD
-----END PGP SIGNATURE-----

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


  By Date           By Thread  

Current thread:
  • [SECURITY] [DSA 1797-1] New xulrunner packages fix several vulnerabilities Moritz Muehlenhoff (May 09)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]