firefox-17.0.9-1.0.1.AXS4, xulrunner-17.0.9-1.0.1.AXS4

エラータID: AXSA:2013-625:07

Release date: 
Monday, September 23, 2013 - 18:49
Subject: 
firefox-17.0.9-1.0.1.AXS4, xulrunner-17.0.9-1.0.1.AXS4
Affected Channels: 
Asianux Server 4 for x86
Asianux Server 4 for x86_64
Asianux Server 4 for ppc
Severity: 
High
Description: 

Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability.

Security issues fixed with this release:

• CVE-2013-1701
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

• CVE-2013-1709
Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 do not properly handle the interaction between FRAME elements and history, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors involving spoofing a relative location in a previously visited document.

• CVE-2013-1710
The crypto.generateCRMFRequest function in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 allows remote attackers to execute arbitrary JavaScript code or conduct cross-site scripting (XSS) attacks via vectors related to Certificate Request Message Format (CRMF) request generation.

• CVE-2013-1713
Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 use an incorrect URI within unspecified comparisons during enforcement of the Same Origin Policy, which allows remote attackers to conduct cross-site scripting (XSS) attacks or install arbitrary add-ons via a crafted web site.

• CVE-2013-1714
The Web Workers implementation in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 does not properly restrict XMLHttpRequest calls, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via unspecified vectors.

• CVE-2013-1717
Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 do not properly restrict local-filesystem access by Java applets, which allows user-assisted remote attackers to read arbitrary files by leveraging a download to a fixed pathname or other predictable pathname.

• CVE-2013-1718
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

• CVE-2013-1722
Use-after-free vulnerability in the nsAnimationManager::BuildAnimations function in the Animation Manager in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving stylesheet cloning.

• CVE-2013-1725
Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 do not ensure that initialization occurs for JavaScript objects with compartments, which allows remote attackers to execute arbitrary code by leveraging incorrect scope handling.

• CVE-2013-1730
Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 do not properly handle movement of XBL-backed nodes between documents, which allows remote attackers to execute arbitrary code or cause a denial of service (JavaScript compartment mismatch, or assertion failure and application exit) via a crafted web site.

• CVE-2013-1732
Buffer overflow in the nsFloatManager::GetFlowArea function in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 allows remote attackers to execute arbitrary code via crafted use of lists and floats within a multi-column layout.

• CVE-2013-1735
Use-after-free vulnerability in the mozilla::layout::ScrollbarActivity function in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 allows remote attackers to execute arbitrary code via vectors related to image-document scrolling.

• CVE-2013-1736
The nsGfxScrollFrameInner::IsLTR function in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to improperly establishing parent-child relationships of range-request nodes.

• CVE-2013-1737
Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 do not properly identify the "this" object during use of user-defined getter methods on DOM proxies, which might allow remote attackers to bypass intended access restrictions via vectors involving an expando object.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. firefox-17.0.9-1.0.1.AXS4.src.rpm
    MD5: ae81824672afb0dbaa7643efa3285d23
    SHA-256: 8d86624aaca272f830267fb327a7b5975d6b759eb8d35a298174de1360533a2f
    Size: 108.05 MB
  2. xulrunner-17.0.9-1.0.1.AXS4.src.rpm
    MD5: 6195d23f2b0317e2237faa2c942c7390
    SHA-256: 6686f2ad6f2ef9fd993c69f25c8e326f2691bff46817d993fef951dcd67151f8
    Size: 86.31 MB

Asianux Server 4 for x86
  1. firefox-17.0.9-1.0.1.AXS4.i686.rpm
    MD5: 0559a241e43cc38c8b51bf22cc77d3a2
    SHA-256: 49f5a56ec2be2a7fa0c0f0f97cd8d5a29b8d4f7b58f9017e7f74b030bdaf96f1
    Size: 25.39 MB
  2. xulrunner-17.0.9-1.0.1.AXS4.i686.rpm
    MD5: 9a80eaa490fe713786e1328a7396e8c4
    SHA-256: 28ed3f36a8371748df5453f6d30377a972784c9316661fb1680f44c54bfecbd4
    Size: 14.09 MB

Asianux Server 4 for x86_64
  1. firefox-17.0.9-1.0.1.AXS4.x86_64.rpm
    MD5: faefd5133debcfda8060dfdd9a5c3192
    SHA-256: 8e230695b46c00df1bc403c3e0956924bb6fbf86d2954a20f2c39544b7211d2c
    Size: 25.37 MB
  2. firefox-17.0.9-1.0.1.AXS4.i686.rpm
    MD5: 0559a241e43cc38c8b51bf22cc77d3a2
    SHA-256: 49f5a56ec2be2a7fa0c0f0f97cd8d5a29b8d4f7b58f9017e7f74b030bdaf96f1
    Size: 25.39 MB
  3. xulrunner-17.0.9-1.0.1.AXS4.x86_64.rpm
    MD5: 1b2645273ec261fa38dc5949b500c17f
    SHA-256: c49ee1ad3bf066c84cbab1454367e61cc17f34d4aa2d1ac6a169bbb562065274
    Size: 15.32 MB
  4. xulrunner-17.0.9-1.0.1.AXS4.i686.rpm
    MD5: 9a80eaa490fe713786e1328a7396e8c4
    SHA-256: 28ed3f36a8371748df5453f6d30377a972784c9316661fb1680f44c54bfecbd4
    Size: 14.09 MB