Fedora 8 : Miro-1.2.3-4.fc8 / blam-1.8.3-18.fc8 / cairo-dock-1.6.2.3-1.fc8.1 / chmsee-1.0.0-4.31.fc8 / etc (2008-8399)

This script is Copyright (C) 2008-2015 Tenable Network Security, Inc.


Synopsis :

The remote Fedora host is missing one or more security updates.

Description :

Mozilla Firefox is an open source Web browser. Several flaws were
found in the processing of malformed web content. A web page
containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code as the user running Firefox.
(CVE-2008-4058, CVE-2008-4060, CVE-2008-4061, CVE-2008-4062,
CVE-2008-4063, CVE-2008-4064) Several flaws were found in the way
malformed web content was displayed. A web page containing specially
crafted content could potentially trick a Firefox user into
surrendering sensitive information. (CVE-2008-4067, CVE-2008-4068) A
flaw was found in the way Firefox handles mouse click events. A web
page containing specially crafted JavaScript code could move the
content window while a mouse-button was pressed, causing any item
under the pointer to be dragged. This could, potentially, cause the
user to perform an unsafe drag-and-drop action. (CVE-2008-3837) A flaw
was found in Firefox that caused certain characters to be stripped
from JavaScript code. This flaw could allow malicious JavaScript to
bypass or evade script filters. (CVE-2008-4065) For technical details
regarding these flaws, please see the Mozilla security advisories for
Firefox 3.0.2.[1] All Firefox users should upgrade to these updated
packages, which contain patches that correct these issues. [1]
http://www.mozilla.org/security/known-
vulnerabilities/firefox30.html#firefox3.0.2

Note that Tenable Network Security has extracted the preceding
description block directly from the Fedora security advisory. Tenable
has attempted to automatically clean and format it as much as possible
without introducing additional issues.

See also :

http://www.mozilla.org/security/known-
http://www.nessus.org/u?c516f095
http://www.nessus.org/u?7982fe32
http://www.nessus.org/u?a7882e5a
http://www.nessus.org/u?f4ca227c
http://www.nessus.org/u?f6d89a51
http://www.nessus.org/u?b2071fd4
http://www.nessus.org/u?69a1905c
http://www.nessus.org/u?988e68dc
http://www.nessus.org/u?3ff0226d
http://www.nessus.org/u?c15e2d72
http://www.nessus.org/u?44bb6340
http://www.nessus.org/u?ba4f29ef
http://www.nessus.org/u?459d9fad
http://www.nessus.org/u?3b8f4eb6
http://www.nessus.org/u?ea5a052a
http://www.nessus.org/u?12a1556f
http://www.nessus.org/u?f361f20a
http://www.nessus.org/u?47e9f8dd

Solution :

Update the affected packages.

Risk factor :

High

Family: Fedora Local Security Checks

Nessus Plugin ID: 34306 (fedora_2008-8399.nasl)

Bugtraq ID:

CVE ID:

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now