firefox-3.6.7-3.0.1.AXS3, xulrunner-1.9.2.7-3.0.1.AXS3

エラータID: AXSA:2010-391:05

Release date: 
Wednesday, July 28, 2010 - 14:21
Subject: 
firefox-3.6.7-3.0.1.AXS3, xulrunner-1.9.2.7-3.0.1.AXS3
Affected Channels: 
Asianux Server 3 for x86
Asianux Server 3 for x86_64
Severity: 
High
Description: 

Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability.
XULRunner provides the XUL Runtime environment for Gecko applications.
Security issues fixed with this release:
CVE-2010-0654
Mozilla Firefox permits cross-origin loading of CSS stylesheets even when the stylesheet download has an incorrect MIME type and the stylesheet document is malformed, which allows remote HTTP servers to obtain sensitive information via a crafted document.
CVE-2010-1205
Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data row.
CVE-2010-1206
The startDocumentLoad function in browser/base/content/browser.js in Mozilla Firefox before 3.6.6 does not properly implement the Same Origin Policy in certain circumstances related to the about:blank document and a document that is currently loading, which allows (1) remote web servers to conduct spoofing attacks via vectors involving a 204 (aka No Content) status code, and allows (2) remote attackers to conduct spoofing attacks via vectors involving a window.stop call.
CVE-2010-1207
CVE-2010-1208
CVE-2010-1209
CVE-2010-1210
CVE-2010-1211
CVE-2010-1212
CVE-2010-1213
CVE-2010-1214
CVE-2010-1215
CVE-2010-2751
CVE-2010-2752
CVE-2010-2753
CVE-2010-2754
CVE-2010-2755
No description available at the time of reporting, please see the links below.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. firefox-3.6.7-3.0.1.AXS3.src.rpm
    MD5: c40849125b52a59a174d00ed9d080a74
    SHA-256: 7a134b3263a3f15bf2f0f8e252c79f159f208ccfb1d571d64456b65507fffd32
    Size: 57.59 MB
  2. xulrunner-1.9.2.7-3.0.1.AXS3.src.rpm
    MD5: 16f96c9499bb7c8c9a8d94ec44f177a4
    SHA-256: 9c066e6932523f8f69b11aea295292d747c320b197b0a0bbead508b35a7eb5ad
    Size: 48.59 MB

Asianux Server 3 for x86
  1. firefox-3.6.7-3.0.1.AXS3.i386.rpm
    MD5: d3d03281e7962b4e21ceb082ca43bd33
    SHA-256: 46530ec6c41561bb260a51c9d553b863ccd1029c4a0099434cb05abcaff7472a
    Size: 14.30 MB
  2. xulrunner-1.9.2.7-3.0.1.AXS3.i386.rpm
    MD5: 104839a0c1be3031aad0b039055d8d7f
    SHA-256: 280935316d4831db5fee75f6c2391c00d9ae1bce577546d8e49ce69ae9068fb6
    Size: 11.54 MB

Asianux Server 3 for x86_64
  1. firefox-3.6.7-3.0.1.AXS3.x86_64.rpm
    MD5: 8a73c011010c2f6197b5170a68c005eb
    SHA-256: 2d92cfb55bdfb5a4ba8f7c86a8edc53de41d34725081b6a2e964808b9642abd9
    Size: 14.30 MB
  2. xulrunner-1.9.2.7-3.0.1.AXS3.x86_64.rpm
    MD5: fbefe047eb046167f5b69c41d1bcb668
    SHA-256: caaada721f932828e64ed42397ad5d1be03a900abae10f4599002d1a79739f76
    Size: 10.98 MB