SuSE 10 Security Update : MozillaFirefox (ZYPP Patch Number 5644)

Critical Nessus Plugin ID 34319


The remote SuSE 10 host is missing a security-related patch.


This update brings MozillaFirefox to version to fix bugs and security issues :

- XBM image uninitialized memory reading. (MFSA 2008-45 / CVE-2008-4069)

- resource: traversal vulnerabilities. (MFSA 2008-44 / CVE-2008-4067 / CVE-2008-4068)

- BOM characters stripped from JavaScript before execution CVE-2008-4065: Stripped BOM characters bug CVE-2008-4066: HTML escaped low surrogates bug. (MFSA 2008-43)

- Crashes with evidence of memory corruption (rv: CVE-2008-4061: Jesse Ruderman reported a crash in the layout engine. CVE-2008-4062:
Igor Bukanov, Philip Taylor, Georgi Guninski, and Antoine Labour reported crashes in the JavaScript engine. CVE-2008-4063: Jesse Ruderman, Bob Clary, and Martijn Wargers reported crashes in the layout engine which only affected Firefox 3. CVE-2008-4064: David Maciejak and Drew Yao reported crashes in graphics rendering which only affected Firefox 3. (MFSA 2008-42)

- Privilege escalation via XPCnativeWrapper pollution CVE-2008-4058: XPCnativeWrapper pollution bugs CVE-2008-4059: XPCnativeWrapper pollution (Firefox 2) CVE-2008-4060: Documents without script handling objects. (MFSA 2008-41)

- Forced mouse drag. (MFSA 2008-40 / CVE-2008-3837)

- Privilege escalation using feed preview page and XSS flaw. (MFSA 2008-39 / CVE-2008-3836)

- nsXMLDocument::OnChannelRedirect() same-origin violation. (MFSA 2008-38 / CVE-2008-3835)

- UTF-8 URL stack buffer overflow. (MFSA 2008-37 / CVE-2008-0016)

For more details: x20.html


Apply ZYPP patch number 5644.

See Also

Plugin Details

Severity: Critical

ID: 34319

File Name: suse_MozillaFirefox-5644.nasl

Version: $Revision: 1.19 $

Type: local

Agent: unix

Published: 2008/10/01

Modified: 2016/12/22

Dependencies: 12634

Risk Information

Risk Factor: Critical


Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: cpe:/o:suse:suse_linux

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2008/09/26

Exploitable With


Core Impact

Reference Information

CVE: CVE-2008-0016, CVE-2008-3835, CVE-2008-3836, CVE-2008-3837, CVE-2008-4058, CVE-2008-4059, CVE-2008-4060, CVE-2008-4061, CVE-2008-4062, CVE-2008-4063, CVE-2008-4064, CVE-2008-4065, CVE-2008-4066, CVE-2008-4067, CVE-2008-4068, CVE-2008-4069

CWE: 22, 79, 119, 189, 200, 264, 399