Scientific Linux Security Update : firefox on SL5.x i386/x86_64
High Nessus Plugin ID 60443
SynopsisThe remote Scientific Linux host is missing one or more security updates.
DescriptionAn integer overflow flaw was found in the way Firefox displayed certain web content. A malicious website could cause Firefox to crash, or execute arbitrary code with the permissions of the user running Firefox. (CVE-2008-2785)
A flaw was found in the way Firefox handled certain command line URLs.
If another application passed Firefox a malformed URL, it could result in Firefox executing local malicious content with chrome privileges.
SolutionUpdate the affected packages.