firefox-3.6.17-1.0.1.AXS4, xulrunner-1.9.2.17-4.0.1.AXS4

エラータID: AXSA:2011-198:03

リリース日: 
2011/05/20 Friday - 21:45
題名: 
firefox-3.6.17-1.0.1.AXS4, xulrunner-1.9.2.17-4.0.1.AXS4
影響のあるチャネル: 
Asianux Server 4 for x86_64
Asianux Server 4 for x86
Severity: 
High
Description: 

Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability.
Security issues fixed with this release:
CVE-2011-0065
Use-after-free vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, allows remote attackers to execute arbitrary code via vectors related to OBJECT's mChannel.
CVE-2011-0066
Use-after-free vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, allows remote attackers to execute arbitrary code via vectors related to OBJECT's mObserverList.
CVE-2011-0067
Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, does not properly implement autocompletion for forms, which allows remote attackers to read form history entries via a Java applet that spoofs interaction with the autocomplete controls.
CVE-2011-0069
Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19, 3.6.x before 3.6.17, and 4.x before 4.0.1; Thunderbird before 3.1.10; and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0070.
CVE-2011-0070
Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19, 3.6.x before 3.6.17, and 4.x before 4.0.1; Thunderbird before 3.1.10; and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0069.
CVE-2011-0071
Directory traversal vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 on Windows allows remote attackers to determine the existence of arbitrary files, and possibly load resources, via vectors involving a resource: URL.
CVE-2011-0072
Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0074, CVE-2011-0075, CVE-2011-0077, and CVE-2011-0078.
CVE-2011-0073
Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, does not properly use nsTreeRange data structures, which allows remote attackers to execute arbitrary code via unspecified vectors that lead to a dangling pointer.
CVE-2011-0074
Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0072, CVE-2011-0075, CVE-2011-0077, and CVE-2011-0078.
CVE-2011-0075
Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0072, CVE-2011-0074, CVE-2011-0077, and CVE-2011-0078.
CVE-2011-0077
Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0072, CVE-2011-0074, CVE-2011-0075, and CVE-2011-0078.
CVE-2011-0078
Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0072, CVE-2011-0074, CVE-2011-0075, and CVE-2011-0077.
CVE-2011-0080
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
CVE-2011-0081
Unspecified vulnerability in the browser engine in Mozilla Firefox 3.6.x before 3.6.17 and 4.x before 4.0.1, and Thunderbird 3.1.x before 3.1.10, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
CVE-2011-1202
The xsltGenerateIdFunction function in functions.c in libxslt 1.1.26 and earlier, as used in Google Chrome before 10.0.648.127 and other products, allows remote attackers to obtain potentially sensitive information about heap memory addresses via an XML document containing a call to the XSLT generate-id XPath function.

解決策: 

Update packages.

追加情報: 

N/A

ダウンロード: 

SRPMS
  1. firefox-3.6.17-1.0.1.AXS4.src.rpm
    MD5: 9eb5599f336fb5e8c0572ecf1959eef6
    SHA-256: 95869faa2f9f358ea74df8907d5f5678c550a63e45d9834923858e90afaf5723
    Size: 58.03 MB
  2. xulrunner-1.9.2.17-4.0.1.AXS4.src.rpm
    MD5: 65f4f9f9e91221f582010f97d1c62f8d
    SHA-256: 05888d30ea401c4a0c34ace782eaca3a2f07a731f26ca0ed4642614fc2db14ca
    Size: 48.90 MB

Asianux Server 4 for x86
  1. firefox-3.6.17-1.0.1.AXS4.i686.rpm
    MD5: f39809d158e11a8c31dff9121404b025
    SHA-256: 38ed1436883d27df3dbc1ae18f876da4cd7389ebf9040d6d9d037e6495702ad8
    Size: 14.05 MB
  2. xulrunner-1.9.2.17-4.0.1.AXS4.i686.rpm
    MD5: bb38e483ff4ee496584fcac6d5b13a1f
    SHA-256: a0a9eb28d8c69e9e6d9577332cdf3adc58244b31d4ce50e94bf5824e73d1f70a
    Size: 9.19 MB

Asianux Server 4 for x86_64
  1. firefox-3.6.17-1.0.1.AXS4.x86_64.rpm
    MD5: 4e767adb4032689a3e01eb203f4f3f7f
    SHA-256: d8e0db0889540517612781cff0347b7eaf5206158c9906b92863b6c7d9f57d9d
    Size: 14.04 MB
  2. xulrunner-1.9.2.17-4.0.1.AXS4.x86_64.rpm
    MD5: 94fe92b3224cfd36cd902d58eccfbcaf
    SHA-256: 359644699f92ccdce08a34f118b16deaca100bda437494b9efafab790966d951
    Size: 8.93 MB
  3. xulrunner-1.9.2.17-4.0.1.AXS4.i686.rpm
    MD5: bb38e483ff4ee496584fcac6d5b13a1f
    SHA-256: a0a9eb28d8c69e9e6d9577332cdf3adc58244b31d4ce50e94bf5824e73d1f70a
    Size: 9.19 MB