This script is Copyright (C) 2009-2016 Tenable Network Security, Inc.
The remote openSUSE host is missing a security update.
This update brings MozillaFirefox to version 3.0.3, fixing a number of
bugs and security problems :
MFSA 2008-44 / CVE-2008-4067 / CVE-2008-4068: resource: traversal
CVE-2008-4065: Stripped BOM characters bug CVE-2008-4066: HTML escaped
low surrogates bug
MFSA 2008-42 Crashes with evidence of memory corruption
(rv:22.214.171.124/126.96.36.199): CVE-2008-4061: Jesse Ruderman reported a crash
in the layout engine. CVE-2008-4062: Igor Bukanov, Philip Taylor,
engine. CVE-2008-4063: Jesse Ruderman, Bob Clary, and Martijn Wargers
reported crashes in the layout engine which only affected Firefox 3.
CVE-2008-4064: David Maciejak and Drew Yao reported crashes in
graphics rendering which only affected Firefox 3.
MFSA 2008-41 Privilege escalation via XPCnativeWrapper pollution
CVE-2008-4058: XPCnativeWrapper pollution bugs CVE-2008-4059:
XPCnativeWrapper pollution (Firefox 2) CVE-2008-4060: Documents
without script handling objects
MFSA 2008-40 / CVE-2008-3837: Forced mouse drag
See also :
Update the affected MozillaFirefox packages.
Risk factor :
Critical / CVSS Base Score : 10.0
Family: SuSE Local Security Checks
Nessus Plugin ID: 39883 ()
Get Nessus Professional to scan unlimited IPs, run compliance checks & moreBuy Nessus Professional Now