Multiple Mozilla/Firefox/Thunderbird Vulnerabilities
BID:12407
Info
Multiple Mozilla/Firefox/Thunderbird Vulnerabilities
| Bugtraq ID: | 12407 |
| Class: | Unknown |
| CVE: |
CVE-2005-0141 CVE-2005-0143 CVE-2005-0144 CVE-2005-0145 CVE-2005-0146 CVE-2005-0147 CVE-2005-0148 CVE-2005-0149 CVE-2005-0150 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 31 2005 12:00AM |
| Updated: | Jan 25 2007 04:21PM |
| Credit: | Omar Khan <[email protected]>, Michiel van Leeuwen (email: mvl+moz@) <[email protected]>, Tom Braun <[email protected]>, Christopher Nebergall <[email protected]>, Jesse Ruderman <[email protected]>, and Kohei Yoshino <[email protected]> are cre |
| Vulnerable: |
SGI ProPack 3.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 Redhat Linux 9.0 i386 Redhat Linux 7.3 i686 Redhat Linux 7.3 i386 Redhat Linux 7.3 Redhat Fedora Core3 Redhat Fedora Core2 Redhat Fedora Core1 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux WS 2.1 IA64 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux ES 2.1 IA64 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux AS 3 Redhat Enterprise Linux AS 2.1 IA64 Redhat Enterprise Linux AS 2.1 Redhat Desktop 3.0 Redhat Advanced Workstation for the Itanium Processor 2.1 IA64 Redhat Advanced Workstation for the Itanium Processor 2.1 Netscape Netscape 7.2 Netscape Netscape 7.1 Netscape Netscape 7.0 Mozilla Thunderbird 0.9 Mozilla Thunderbird 0.8 Mozilla Thunderbird 0.7.3 Mozilla Thunderbird 0.7.2 Mozilla Thunderbird 0.7.1 Mozilla Thunderbird 0.7 Mozilla Thunderbird 0.6 Mozilla Firefox 0.10.1 Mozilla Firefox 0.10 Mozilla Firefox 0.9.3 Mozilla Firefox 0.9.2 Mozilla Firefox 0.9.1 Mozilla Firefox 0.9 rc Mozilla Firefox 0.9 Mozilla Firefox 0.8 Mozilla Firefox Preview Release Mozilla Firebird 0.7 Mozilla Firebird 0.6.1 Mozilla Firebird 0.5 Mozilla Browser 1.7.6 Mozilla Browser 1.7.4 Mozilla Browser 1.7.3 Mozilla Browser 1.7.2 Mozilla Browser 1.7.1 Mozilla Browser 1.7 rc3 Mozilla Browser 1.7 rc2 Mozilla Browser 1.7 rc1 Mozilla Browser 1.7 beta Mozilla Browser 1.7 alpha Mozilla Browser 1.7 Mozilla Browser 1.6 Mozilla Browser 1.5.1 Mozilla Browser 1.5 Mozilla Browser 1.4.4 Mozilla Browser 1.4.2 Mozilla Browser 1.4.1 Mozilla Browser 1.4 b Mozilla Browser 1.4 a Mozilla Browser 1.4 Mozilla Browser 1.3.1 Mozilla Browser 1.3 Mozilla Browser 1.2.1 Mozilla Browser 1.2 Beta Mozilla Browser 1.2 Alpha Mozilla Browser 1.2 Mozilla Browser 1.1 Beta Mozilla Browser 1.1 Alpha Mozilla Browser 1.1 Mozilla Browser 1.0.2 Mozilla Browser 1.0.1 Mozilla Browser 1.0 RC2 Mozilla Browser 1.0 RC1 Mozilla Browser 1.0 Mozilla Browser 0.9.48 Mozilla Browser 0.9.35 Mozilla Browser 0.9.9 Mozilla Browser 0.9.8 Mozilla Browser 0.9.7 Mozilla Browser 0.9.6 Mozilla Browser 0.9.5 Mozilla Browser 0.9.4 .1 Mozilla Browser 0.9.4 Mozilla Browser 0.9.3 Mozilla Browser 0.9.2 .1 Mozilla Browser 0.9.2 Mozilla Browser 0.8 Mandriva Linux Mandrake 10.2 x86_64 Mandriva Linux Mandrake 10.2 Mandriva Linux Mandrake 10.1 x86_64 Mandriva Linux Mandrake 10.1 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 HP HP-UX B.11.23 HP HP-UX B.11.22 HP HP-UX B.11.11 HP HP-UX B.11.00 |
| Not Vulnerable: |
Netscape Netscape 8.0 Mozilla Thunderbird 1.0 Mozilla Firefox 1.0 Mozilla Browser 1.7.5 |
Discussion
Multiple Mozilla/Firefox/Thunderbird Vulnerabilities
Mozilla, Firefox, and Thunderbird applications are reported prone to multiple vulnerabilities. The following specific issues are reported:
- Access-control bypass (Mozilla and Firefox browsers). Although unconfirmed, this vulnerability presumably may be exploited to access information pertaining to a target filesystem. For example, an attacker may be able to determine whether a file exists or not.
This vulnerability is reported to affect Mozilla Firefox versions prior to 1.0 and Mozilla Suite versions prior to 1.7.5.
- Status-bar misrepresentation (Mozilla and Firefox browsers). A remote attacker may exploit this vulnerability to aid in phishing-style attacks (e.g. to make a malicious site appear authentic).
This vulnerability is reported to affect Mozilla Firefox versions prior to 1.0 and Mozilla Suite versions prior to 1.7.5.
- Additional status-bar misrepresentation (Mozilla and Firefox browsers). Using JavaScript to automate the process, a remote attacker may exploit this vulnerability to aid in phishing-style attacks (e.g. to make a malicious site appear authentic).
This vulnerability is reported to affect Mozilla Firefox versions prior to 1.0 and Mozilla Suite versions prior to 1.7.5.
- Mozilla and Firefox browsers provide functionality (Alt-Click) to download files that are linked by URIs to the default download location without requiring a user prompt. Reports indicate that a malicious site may exploit this functionality to download a file to the default download location without user interaction.
This vulnerability is reported to affect Mozilla Firefox versions prior to 1.0.
- Clipboard information-disclosure vulnerability (Mozilla and Firefox browsers). A remote attacker may exploit this vulnerability to steal clipboard contents, which may reveal potentially sensitive information to a remote attacker.
This vulnerability is reported to affect Mozilla Firefox versions prior to 1.0 and Mozilla Suite versions prior to 1.7.5.
- Additional information-disclosure vulnerability (Mozilla and Firefox browsers). A remote malicious server may invoke a request against a vulnerable browser and the browser will respond with proxy-authentication credentials.
This vulnerability is reported to affect Mozilla Firefox versions prior to 1.0 and Mozilla Suite versions prior to 1.7.5.
- Mozilla Thunderbird erroneously responds to cookie requests that are contained in HTML-based email. Reportedly, a remote attacker may exploit this vulnerability to track emails to victim users.
This vulnerability is reported to affect Thunderbird versions 0.6 to 0.9 and Mozilla Suite 1.7 to 1.7.3.
- Local code-execution vulnerability (Mozilla Firefox). The vulnerability exists in the Livefeed bookmark functionality. If, for example, 'about:config' is displayed when the Livefeed is updated, then arbitrary code execution may reportedly occur on the affected computer.
This vulnerability is reported to affect Mozilla Firefox versions prior to 1.0.
- Mozilla Thunderbird reportedly fails to handle 'javascript:' URI links. The affected application employs the default handler for 'javascript:' URIs that is registered on the host operating system. This is incorrect behavior and may result in exposure to latent vulnerabilities due to a false sense of security.
This vulnerability is reported to affect Mozilla Thunderbird versions prior to 0.9.
This BID will be separated into individual BIDs as soon as further research into each of the vulnerabilities is completed.
Mozilla, Firefox, and Thunderbird applications are reported prone to multiple vulnerabilities. The following specific issues are reported:
- Access-control bypass (Mozilla and Firefox browsers). Although unconfirmed, this vulnerability presumably may be exploited to access information pertaining to a target filesystem. For example, an attacker may be able to determine whether a file exists or not.
This vulnerability is reported to affect Mozilla Firefox versions prior to 1.0 and Mozilla Suite versions prior to 1.7.5.
- Status-bar misrepresentation (Mozilla and Firefox browsers). A remote attacker may exploit this vulnerability to aid in phishing-style attacks (e.g. to make a malicious site appear authentic).
This vulnerability is reported to affect Mozilla Firefox versions prior to 1.0 and Mozilla Suite versions prior to 1.7.5.
- Additional status-bar misrepresentation (Mozilla and Firefox browsers). Using JavaScript to automate the process, a remote attacker may exploit this vulnerability to aid in phishing-style attacks (e.g. to make a malicious site appear authentic).
This vulnerability is reported to affect Mozilla Firefox versions prior to 1.0 and Mozilla Suite versions prior to 1.7.5.
- Mozilla and Firefox browsers provide functionality (Alt-Click) to download files that are linked by URIs to the default download location without requiring a user prompt. Reports indicate that a malicious site may exploit this functionality to download a file to the default download location without user interaction.
This vulnerability is reported to affect Mozilla Firefox versions prior to 1.0.
- Clipboard information-disclosure vulnerability (Mozilla and Firefox browsers). A remote attacker may exploit this vulnerability to steal clipboard contents, which may reveal potentially sensitive information to a remote attacker.
This vulnerability is reported to affect Mozilla Firefox versions prior to 1.0 and Mozilla Suite versions prior to 1.7.5.
- Additional information-disclosure vulnerability (Mozilla and Firefox browsers). A remote malicious server may invoke a request against a vulnerable browser and the browser will respond with proxy-authentication credentials.
This vulnerability is reported to affect Mozilla Firefox versions prior to 1.0 and Mozilla Suite versions prior to 1.7.5.
- Mozilla Thunderbird erroneously responds to cookie requests that are contained in HTML-based email. Reportedly, a remote attacker may exploit this vulnerability to track emails to victim users.
This vulnerability is reported to affect Thunderbird versions 0.6 to 0.9 and Mozilla Suite 1.7 to 1.7.3.
- Local code-execution vulnerability (Mozilla Firefox). The vulnerability exists in the Livefeed bookmark functionality. If, for example, 'about:config' is displayed when the Livefeed is updated, then arbitrary code execution may reportedly occur on the affected computer.
This vulnerability is reported to affect Mozilla Firefox versions prior to 1.0.
- Mozilla Thunderbird reportedly fails to handle 'javascript:' URI links. The affected application employs the default handler for 'javascript:' URIs that is registered on the host operating system. This is incorrect behavior and may result in exposure to latent vulnerabilities due to a false sense of security.
This vulnerability is reported to affect Mozilla Thunderbird versions prior to 0.9.
This BID will be separated into individual BIDs as soon as further research into each of the vulnerabilities is completed.
Exploit / POC
Multiple Mozilla/Firefox/Thunderbird Vulnerabilities
Proof-of-concept exploits to trigger these vulnerabilities can be found in the referenced Bugzilla entries associated with each of the issues.
Proof-of-concept exploits to trigger these vulnerabilities can be found in the referenced Bugzilla entries associated with each of the issues.
Solution / Fix
Multiple Mozilla/Firefox/Thunderbird Vulnerabilities
Solution:
The vendor has released upgrades dealing with these issues.
Please see the referenced advisories for further information.
Redhat Fedora Core2
Mozilla Firefox 0.10
Mozilla Thunderbird 0.7.2
Mozilla Thunderbird 0.7.3
Mozilla Firefox 0.8
Mozilla Thunderbird 0.8
Mozilla Firefox 0.9
Mozilla Thunderbird 0.9
Mozilla Firefox 0.9.1
Mozilla Firefox 0.9.2
Mozilla Firefox 0.9.3
Mozilla Browser 0.9.9
Mozilla Browser 1.0
Mozilla Browser 1.0.1
Mozilla Browser 1.1
Mozilla Browser 1.2
Mozilla Browser 1.2.1
Mozilla Browser 1.4
Mozilla Browser 1.4 a
Mozilla Browser 1.4.1
Mozilla Browser 1.4.2
Mozilla Browser 1.5
Mozilla Browser 1.5.1
Mozilla Browser 1.7 rc1
Mozilla Browser 1.7
Mozilla Browser 1.7 rc2
Mozilla Browser 1.7.1
Mozilla Browser 1.7.2
Mozilla Browser 1.7.3
S.u.S.E. Linux Professional 10.0
Netscape Netscape 7.0
Netscape Netscape 7.1
Netscape Netscape 7.2
S.u.S.E. Linux Professional 9.1
S.u.S.E. Linux Professional 9.3
Solution:
The vendor has released upgrades dealing with these issues.
Please see the referenced advisories for further information.
Redhat Fedora Core2
-
Fedora devhelp-0.9.1-0.2.5.i386.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora devhelp-0.9.1-0.2.5.x86_64.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora devhelp-debuginfo-0.9.1-0.2.5.i386.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora devhelp-debuginfo-0.9.1-0.2.5.x86_64.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora epiphany-1.2.10-0.2.1.i386.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora epiphany-1.2.10-0.2.1.x86_64.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora epiphany-debuginfo-1.2.10-0.2.1.i386.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora epiphany-debuginfo-1.2.10-0.2.1.x86_64.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
Mozilla Firefox 0.10
-
Mozilla Firefox 1.0
http://www.mozilla.org/products/firefox/
Mozilla Thunderbird 0.7.2
-
Mozilla Thunderbird 1.0
http://download.mozilla.org/?product=thunderbird&os=win&lang=en-US
Mozilla Thunderbird 0.7.3
-
Mozilla Thunderbird 1.0
http://download.mozilla.org/?product=thunderbird&os=win&lang=en-US
Mozilla Firefox 0.8
-
Mozilla Firefox 1.0
http://www.mozilla.org/products/firefox/
Mozilla Thunderbird 0.8
-
Mozilla Thunderbird 1.0
http://download.mozilla.org/?product=thunderbird&os=win&lang=en-US
Mozilla Firefox 0.9
-
Mozilla Firefox 1.0
http://www.mozilla.org/products/firefox/
Mozilla Thunderbird 0.9
-
Mozilla Thunderbird 1.0
http://download.mozilla.org/?product=thunderbird&os=win&lang=en-US
Mozilla Firefox 0.9.1
-
Mozilla Firefox 1.0
http://www.mozilla.org/products/firefox/
Mozilla Firefox 0.9.2
-
Mozilla Firefox 1.0
http://www.mozilla.org/products/firefox/
Mozilla Firefox 0.9.3
-
Mozilla Firefox 1.0
http://www.mozilla.org/products/firefox/
Mozilla Browser 0.9.9
-
Red Hat Fedora galeon-1.2.14-0.73.2.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/redhat/7.3/updates/i386/galeon-1.2.14 -0.73.2.legacy.i386.rpm -
Red Hat Fedora mozilla-1.7.7-0.73.2.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/redhat/7.3/updates/i386/mozilla-1.7.7 -0.73.2.legacy.i386.rpm -
Red Hat Fedora mozilla-chat-1.7.7-0.73.2.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/redhat/7.3/updates/i386/mozilla-chat- 1.7.7-0.73.2.legacy.i386.rpm -
Red Hat Fedora mozilla-devel-1.7.7-0.73.2.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/redhat/7.3/updates/i386/mozilla-1.7.7 -0.73.2.legacy.i386.rpm -
Red Hat Fedora mozilla-dom-inspector-1.7.7-0.73.2.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/redhat/7.3/updates/i386/mozilla-dom-i nspector-1.7.7-0.73.2.legacy.i386.rpm -
Red Hat Fedora mozilla-js-debugger-1.7.7-0.73.2.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/redhat/7.3/updates/i386/mozilla-js-de bugger-1.7.7-0.73.2.legacy.i386.rpm -
Red Hat Fedora mozilla-mail-1.7.7-0.73.2.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/redhat/7.3/updates/i386/mozilla-mail- 1.7.7-0.73.2.legacy.i386.rpm -
Red Hat Fedora mozilla-nspr-1.7.7-0.73.2.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/redhat/7.3/updates/i386/mozilla-nspr- 1.7.7-0.73.2.legacy.i386.rpm -
Red Hat Fedora mozilla-nspr-devel-1.7.7-0.73.2.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/redhat/7.3/updates/i386/mozilla-nspr- devel-1.7.7-0.73.2.legacy.i386.rpm -
Red Hat Fedora mozilla-nss-1.7.7-0.73.2.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/redhat/7.3/updates/i386/mozilla-nss-1 .7.7-0.73.2.legacy.i386.rpm -
Red Hat Fedora mozilla-nss-devel-1.7.7-0.73.2.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/redhat/7.3/updates/i386/mozilla-nss-d evel-1.7.7-0.73.2.legacy.i386.rpm
Mozilla Browser 1.0
-
Mozilla Mozilla 1.7.5
http://www.mozilla.org/releases/
Mozilla Browser 1.0.1
-
Mozilla Mozilla 1.7.5
http://www.mozilla.org/releases/
Mozilla Browser 1.1
-
Mozilla Mozilla 1.7.5
http://www.mozilla.org/releases/
Mozilla Browser 1.2
-
Mozilla Mozilla 1.7.5
http://www.mozilla.org/releases/
Mozilla Browser 1.2.1
-
Mozilla Mozilla 1.7.5
http://www.mozilla.org/releases/ -
Red Hat Fedora galeon-1.2.14-0.90.2.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/redhat/9/updates/i386/galeon-1.2.14-0 .90.2.legacy.i386.rpm -
Red Hat Fedora mozilla-1.7.7-0.90.1.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/redhat/9/updates/i386/mozilla-1.7.7-0 .90.1.legacy.i386.rpm -
Red Hat Fedora mozilla-chat-1.7.7-0.90.1.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/redhat/9/updates/i386/mozilla-chat-1. 7.7-0.90.1.legacy.i386.rpm -
Red Hat Fedora mozilla-devel-1.7.7-0.90.1.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/redhat/9/updates/i386/mozilla-devel-1 .7.7-0.90.1.legacy.i386.rpm -
Red Hat Fedora mozilla-dom-inspector-1.7.7-0.90.1.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/redhat/9/updates/i386/mozilla-dom-ins pector-1.7.7-0.90.1.legacy.i386.rpm -
Red Hat Fedora mozilla-js-debugger-1.7.7-0.90.1.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/redhat/9/updates/i386/mozilla-js-debu gger-1.7.7-0.90.1.legacy.i386.rpm -
Red Hat Fedora mozilla-mail-1.7.7-0.90.1.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/redhat/9/updates/i386/mozilla-mail-1. 7.7-0.90.1.legacy.i386.rpm -
Red Hat Fedora mozilla-nspr-1.7.7-0.90.1.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/redhat/9/updates/i386/mozilla-nspr-1. 7.7-0.90.1.legacy.i386.rpm -
Red Hat Fedora mozilla-nspr-devel-1.7.7-0.90.1.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/redhat/9/updates/i386/mozilla-nspr-de vel-1.7.7-0.90.1.legacy.i386.rpm -
Red Hat Fedora mozilla-nss-1.7.7-0.90.1.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/redhat/9/updates/i386/mozilla-nss-1.7 .7-0.90.1.legacy.i386.rpm -
Red Hat Fedora mozilla-nss-devel-1.7.7-0.90.1.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/redhat/9/updates/i386/mozilla-nss-dev el-1.7.7-0.90.1.legacy.i386.rpm
Mozilla Browser 1.4
-
Mozilla Mozilla 1.7.5
http://www.mozilla.org/releases/ -
Slackware gaim-1.2.0-i486-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-9.1/patches/packages/g aim-1.2.0-i486-1.tgz -
Slackware mozilla-1.4.4-i486-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-9.1/patches/packages/m ozilla-1.4.4-i486-1.tgz -
Slackware mozilla-plugins-1.4.4-noarch-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-9.1/patches/packages/m ozilla-plugins-1.4.4-noarch-1.tgz
Mozilla Browser 1.4 a
-
Mozilla Mozilla 1.7.5
http://www.mozilla.org/releases/
Mozilla Browser 1.4.1
-
Mozilla Mozilla 1.7.5
http://www.mozilla.org/releases/ -
Red Hat Fedora epiphany-1.0.8-1.fc1.2.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/fedora/1/updates/i386/epiphany-1.0.8- 1.fc1.2.legacy.i386.rpm -
Red Hat Fedora mozilla-1.7.7-1.1.2.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-1.7.7-1 .1.2.legacy.i386.rpm -
Red Hat Fedora mozilla-chat-1.7.7-1.1.2.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-chat-1. 7.7-1.1.2.legacy.i386.rpm -
Red Hat Fedora mozilla-devel-1.7.7-1.1.2.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-devel-1 .7.7-1.1.2.legacy.i386.rpm -
Red Hat Fedora mozilla-dom-inspector-1.7.7-1.1.2.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-dom-ins pector-1.7.7-1.1.2.legacy.i386.rpm -
Red Hat Fedora mozilla-js-debugger-1.7.7-1.1.2.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-js-debu gger-1.7.7-1.1.2.legacy.i386.rpm -
Red Hat Fedora mozilla-mail-1.7.7-1.1.2.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-mail-1. 7.7-1.1.2.legacy.i386.rpm -
Red Hat Fedora mozilla-nspr-1.7.7-1.1.2.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-nspr-1. 7.7-1.1.2.legacy.i386.rpm -
Red Hat Fedora mozilla-nspr-devel-1.7.7-1.1.2.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-nspr-de vel-1.7.7-1.1.2.legacy.i386.rpm -
Red Hat Fedora mozilla-nss-1.7.7-1.1.2.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-nss-1.7 .7-1.1.2.legacy.i386.rpm -
Red Hat Fedora mozilla-nss-devel-1.7.7-1.1.2.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-nss-dev el-1.7.7-1.1.2.legacy.i386.rpm
Mozilla Browser 1.4.2
-
Mozilla Mozilla 1.7.5
http://www.mozilla.org/releases/
Mozilla Browser 1.5
-
Mozilla Mozilla 1.7.5
http://www.mozilla.org/releases/
Mozilla Browser 1.5.1
-
Mozilla Mozilla 1.7.5
http://www.mozilla.org/releases/
Mozilla Browser 1.7 rc1
-
Mozilla Mozilla 1.7.5
http://www.mozilla.org/releases/
Mozilla Browser 1.7
-
Mozilla Mozilla 1.7.5
http://www.mozilla.org/releases/ -
Slackware gaim-1.2.0-i486-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-10.0/patches/packages/ gaim-1.2.0-i486-1.tgz -
Slackware gaim-1.2.0-i486-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-10.1/patches/packages/ gaim-1.2.0-i486-1.tgz -
Slackware mozilla-1.7.6-i486-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-10.0/patches/packages/ mozilla-1.7.6-i486-1.tgz -
Slackware mozilla-1.7.6-i486-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-10.1/patches/packages/ mozilla-1.7.6-i486-1.tgz -
Slackware mozilla-plugins-1.7.6-noarch-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-10.0/patches/packages/ mozilla-plugins-1.7.6-noarch-1.tgz -
Slackware mozilla-plugins-1.7.6-noarch-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-10.1/patches/packages/ mozilla-plugins-1.7.6-noarch-1.tgz
Mozilla Browser 1.7 rc2
-
Mozilla Mozilla 1.7.5
http://www.mozilla.org/releases/
Mozilla Browser 1.7.1
-
Mozilla Mozilla 1.7.5
http://www.mozilla.org/releases/
Mozilla Browser 1.7.2
-
Mozilla Mozilla 1.7.5
http://www.mozilla.org/releases/
Mozilla Browser 1.7.3
-
Fedora mozilla-1.7.6-1.3.2.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora mozilla-1.7.6-1.3.2.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora mozilla-chat-1.7.6-1.3.2.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora mozilla-chat-1.7.6-1.3.2.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora mozilla-debuginfo-1.7.6-1.3.2.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora mozilla-debuginfo-1.7.6-1.3.2.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora mozilla-devel-1.7.6-1.3.2.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora mozilla-devel-1.7.6-1.3.2.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora mozilla-dom-inspector-1.7.6-1.3.2.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora mozilla-dom-inspector-1.7.6-1.3.2.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora mozilla-js-debugger-1.7.6-1.3.2.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora mozilla-js-debugger-1.7.6-1.3.2.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora mozilla-mail-1.7.6-1.3.2.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora mozilla-mail-1.7.6-1.3.2.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora mozilla-nspr-1.7.6-1.3.2.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora mozilla-nspr-1.7.6-1.3.2.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora mozilla-nspr-devel-1.7.6-1.3.2.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora mozilla-nspr-devel-1.7.6-1.3.2.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora mozilla-nss-1.7.6-1.3.2.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora mozilla-nss-1.7.6-1.3.2.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora mozilla-nss-devel-1.7.6-1.3.2.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora mozilla-nss-devel-1.7.6-1.3.2.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Mozilla Mozilla 1.7.5
http://www.mozilla.org/releases/
S.u.S.E. Linux Professional 10.0
-
SuSE MozillaFirefox-1.0.8-0.2.ppc.rpm
SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/MozillaFirefox-1. 0.8-0.2.ppc.rpm -
SuSE MozillaThunderbird-1.0.8-0.2.i586.rpm
SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/MozillaThunderbi rd-1.0.8-0.2.i586.rpm -
SuSE MozillaThunderbird-1.0.8-0.2.x86_64.rpm
SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/x86_64/MozillaThunder bird-1.0.8-0.2.x86_64.rpm
Netscape Netscape 7.0
-
Netscape Netscape 8.0
http://browser.netscape.com/ns8/download/
Netscape Netscape 7.1
-
Netscape Netscape 8.0
http://browser.netscape.com/ns8/download/
Netscape Netscape 7.2
-
Netscape Netscape 8.0
http://browser.netscape.com/ns8/download/
S.u.S.E. Linux Professional 9.1
-
SuSE MozillaThunderbird-1.0.8-0.1.i586.rpm
SUSE LINUX 9.1:
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/MozillaThunderbir d-1.0.8-0.1.i586.rpm -
SuSE MozillaThunderbird-1.0.8-0.1.x86_64.rpm
SUSE LINUX 9.1:
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/MozillaThunde rbird-1.0.8-0.1.x86_64.rpm
S.u.S.E. Linux Professional 9.3
-
SuSE MozillaThunderbird-1.0.8-0.2.i586.rpm
SUSE LINUX 9.3:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/i586/MozillaThunderbir d-1.0.8-0.2.i586.rpm -
SuSE MozillaThunderbird-1.0.8-0.2.x86_64.rpm
SUSE LINUX 9.3:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/x86_64/MozillaThunderb ird-1.0.8-0.2.x86_64.rpm
References
Multiple Mozilla/Firefox/Thunderbird Vulnerabilities
References:
References:
- Bug 249332 Bypassing CheckLoadURI using custom getters and changing toString ret (Mozilla - Bugzilla)
- Bug 257308 Visual indicators of site security appear for the wrong site (lock ic (Mozilla - Bugzilla)
- Bug 262689 lock icon and certificates spoofable with "view-source:" (Mozilla - Bugzilla)
- Bug 263546 Security risk: TB uses IE to open javascript pop-up in news-feed item (Mozilla - Bugzilla)
- Bug 265176 Javascript allows websites to download content without prompt. (Mozilla - Bugzilla)
- Bug 265668 Live bookmarks can have javascript: and data: URLs (Mozilla - Bugzilla)
- Bug 265728 Synthetic middle-click event can paste (Mozilla - Bugzilla)
- Bug 267263 Browser does not test to see that server sending proxy auth request i (Mozilla - Bugzilla)
- Bug 268107 mailnews allows cookies, despite the pref (Mozilla - Bugzilla)
- Cisco NX-OS Download Page (Cisco)
- Mozilla Firefox Home Page (Mozilla)
- Mozilla Foundation Security Advisory 2005-01 - Link opened in new tab can load (Mozilla)
- Mozilla Foundation Security Advisory 2005-03 - Secure site lock can be spoofed (Mozilla)
- Mozilla Foundation Security Advisory 2005-04 - Secure site lock can be spoofed (Mozilla)
- Mozilla Foundation Security Advisory 2005-07 - Script-generated event can dow (Mozilla)
- Mozilla Foundation Security Advisory 2005-08 - Synthetic middle-click event can (Mozilla)
- Mozilla Foundation Security Advisory 2005-09 - Browser responds to proxy auth r (Mozilla)
- Mozilla Foundation Security Advisory 2005-10 - javascript: links in Thunderbir (Mozilla)
- Mozilla Foundation Security Advisory 2005-11 - Mail responds to cookie request (Mozilla)
- Mozilla Foundation Security Advisory 2005-12 - javascript: Livefeed bookmarks c (Mozilla)
- RHSA-2005:323-10 Critical: mozilla security update (RedHat)
- RHSA-2005:335-07 Critical: mozilla security update (RedHat)
- RHSA-2005:384-11 - Mozilla security update (Red Hat)
- Security Alerts (Netscape)
- SSA:2005-085-01 - Mozilla/Firefox/Thunderbird (Slackware)