DESCRIPTION
Mozilla[1] is an open-source web browser designed for standards
compliance, performance and portability.
This announcement updates mozilla packages for Conectiva Linux 9 and
10 to mozilla version 1.7.3. This updates fixes lots of
vulnerabilities, which the most recent and important is listed
bellow:
CAN-2004-0597: multiple buffer overflows in libpng
CAN-2004-0598: denial of service via a certain PNG image
CAN-2004-0599: multiple integer overflows in libpng
CAN-2004-0718: content in unrelated windows could be modified
CAN-2004-0722: integer overflow in the SOAPParameter object
constructor
CAN-2004-0757: heap-based buffer overflow in the SendUidl of POP3
code
CAN-2004-0758: denial-of-service with malicious SSL certificates
CAN-2004-0759: read files via JavaScript
CAN-2004-0760: MIME code handles %00 incorrectly
CAN-2004-0761: spoofing of security lock icon
CAN-2004-0763: spoofing of SSL certificates by using redirects and
JavaScript
CAN-2004-0764: hijacking the user interface via the "chrome" flag and
XML User Interface Language (XUL) files
CAN-2004-0765: spoofing SSL certificates due to incorrecting
comparsion of hostnames
CAN-2004-0902: Several heap based buffer overflows in Mozilla
Browsers.
CAN-2004-0903: Stack-based buffer overflow in the writeGroup function
in vcard handling.
CAN-2004-0904: Buffer overflow in BMP images decoding.
CAN-2004-0905: Crossdomain scripting and possible code execution by
javascript drag and drop.
CAN-2004-0906: XPI Installer sets insecure permissions, allowing
local users to overwrite files of the user.
CAN-2004-0908: Allow untrusted javascript code to read and write to
the clipboard.
CAN-2004-0909: Allow remote attackers to trick the user into
performing dangerous operations by modifying security relevant dialog
boxes.
SOLUTION
All mozilla users should upgrade their packages. Galeon users on
Conectiva Linux 9.0 must choose another browser, becose all galeon's
available versions for this Conectiva Linux are not compatible with
the new mozilla.