Mozilla Suite And Firefox XPInstall JavaScript Object Instance Validation Vulnerability
BID:13232
Info
Mozilla Suite And Firefox XPInstall JavaScript Object Instance Validation Vulnerability
| Bugtraq ID: | 13232 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-1159 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 16 2005 12:00AM |
| Updated: | Feb 22 2007 04:46PM |
| Credit: | Georgi Guninski <[email protected]> is credited with the discovery of this issue. Juha-Matti Laurio identified this issue in Netscape. |
| Vulnerable: |
Ubuntu Ubuntu Linux 5.0 4 powerpc Ubuntu Ubuntu Linux 5.0 4 i386 Ubuntu Ubuntu Linux 5.0 4 amd64 Ubuntu Ubuntu Linux 4.1 ppc Ubuntu Ubuntu Linux 4.1 ia64 Ubuntu Ubuntu Linux 4.1 ia32 SuSE SUSE Linux Enterprise Server 8 SuSE Linux Enterprise Server 9 SuSE Linux Desktop 1.0 SGI ProPack 3.0 SCO Unixware 7.1.4 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 S.u.S.E. Linux Personal 8.2 Redhat Linux 9.0 i386 Redhat Linux 7.3 i686 Redhat Linux 7.3 i386 Redhat Linux 7.3 Redhat Fedora Core4 Redhat Fedora Core3 Redhat Fedora Core2 Redhat Fedora Core1 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux AS 3 Redhat Enterprise Linux AS 2.1 Redhat Desktop 3.0 Redhat Advanced Workstation for the Itanium Processor 2.1 Netscape Netscape 7.2 Netscape Netscape 7.1 Netscape Netscape 7.0 Netscape Navigator 7.2 Netscape Navigator 7.1 Netscape Navigator 7.0.2 Netscape Navigator 7.0 Mozilla Thunderbird 1.0.2 Mozilla Thunderbird 1.0.1 Mozilla Thunderbird 1.0 Mozilla Thunderbird 0.9 Mozilla Thunderbird 0.8 Mozilla Thunderbird 0.7.3 Mozilla Thunderbird 0.7.2 Mozilla Thunderbird 0.7.1 Mozilla Thunderbird 0.7 Mozilla Thunderbird 0.6 Mozilla Firefox 1.0.2 Mozilla Firefox 1.0.1 Mozilla Firefox 1.0 Mozilla Firefox 0.10.1 Mozilla Firefox 0.10 Mozilla Firefox 0.9.3 Mozilla Firefox 0.9.2 Mozilla Firefox 0.9.1 Mozilla Firefox 0.9 rc Mozilla Firefox 0.9 Mozilla Firefox 0.8 Mozilla Browser 1.7.6 Mozilla Browser 1.7.5 Mozilla Browser 1.7.4 Mozilla Browser 1.7.3 Mozilla Browser 1.7.2 Mozilla Browser 1.7.1 Mozilla Browser 1.7 rc3 Mozilla Browser 1.7 rc2 Mozilla Browser 1.7 rc1 Mozilla Browser 1.7 beta Mozilla Browser 1.7 alpha Mozilla Browser 1.7 Mandriva Linux Mandrake 10.2 x86_64 Mandriva Linux Mandrake 10.2 Mandriva Linux Mandrake 10.1 x86_64 Mandriva Linux Mandrake 10.1 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 HP HP-UX B.11.23 HP HP-UX B.11.22 HP HP-UX B.11.11 HP HP-UX B.11.00 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 |
| Not Vulnerable: |
Netscape Netscape 8.0 Mozilla Thunderbird 1.0.5 Mozilla Firefox 1.0.3 Mozilla Browser 1.7.7 |
Discussion
Mozilla Suite And Firefox XPInstall JavaScript Object Instance Validation Vulnerability
Mozilla Suite and Mozilla Firefox are affected by an input-validation vulnerability because the applications fail to verify input passed to installation objects.
An attacker may be able to exploit this issue to execute malicious code in the context of the affected browser, subsequently facilitating unauthorized access.
Note that this issue was previously reported in BID 13208 (Mozilla Suite Multiple Code Execution, Cross-Site Scripting, And Policy Bypass Vulnerabilities); it has been assigned its own BID.
Mozilla Suite and Mozilla Firefox are affected by an input-validation vulnerability because the applications fail to verify input passed to installation objects.
An attacker may be able to exploit this issue to execute malicious code in the context of the affected browser, subsequently facilitating unauthorized access.
Note that this issue was previously reported in BID 13208 (Mozilla Suite Multiple Code Execution, Cross-Site Scripting, And Policy Bypass Vulnerabilities); it has been assigned its own BID.
Exploit / POC
Mozilla Suite And Firefox XPInstall JavaScript Object Instance Validation Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution / Fix
Mozilla Suite And Firefox XPInstall JavaScript Object Instance Validation Vulnerability
Solution:
Mozilla has released and advisory along with upgrades dealing with this issue.
Please see the referenced advisories for more information.
Mozilla Firefox 0.10
Mozilla Thunderbird 0.7
Mozilla Thunderbird 0.7.2
Mozilla Thunderbird 0.7.3
Mozilla Firefox 0.8
Mozilla Thunderbird 0.8
Mozilla Firefox 0.9
Mozilla Thunderbird 0.9
Mozilla Firefox 0.9.1
Mozilla Firefox 0.9.2
Mozilla Firefox 0.9.3
Mozilla Firefox 1.0
Mozilla Thunderbird 1.0
Mozilla Firefox 1.0.1
Mozilla Thunderbird 1.0.1
Mozilla Firefox 1.0.2
Mozilla Thunderbird 1.0.2
Mozilla Browser 1.7 rc1
Mozilla Browser 1.7
Mozilla Browser 1.7 rc2
Mozilla Browser 1.7 alpha
Mozilla Browser 1.7 beta
Mozilla Browser 1.7.1
Mozilla Browser 1.7.2
Mozilla Browser 1.7.3
Mozilla Browser 1.7.4
Mozilla Browser 1.7.5
Mozilla Browser 1.7.6
S.u.S.E. Linux Professional 10.0
Netscape Netscape 7.0
Netscape Netscape 7.1
Netscape Netscape 7.2
S.u.S.E. Linux Professional 9.1 x86_64
S.u.S.E. Linux Professional 9.1
S.u.S.E. Linux Professional 9.2 x86_64
S.u.S.E. Linux Professional 9.3 x86_64
S.u.S.E. Linux Professional 9.3
Solution:
Mozilla has released and advisory along with upgrades dealing with this issue.
Please see the referenced advisories for more information.
Mozilla Firefox 0.10
-
Mozilla Firefox 1.0.3
http://www.mozilla.org/products/firefox/
Mozilla Thunderbird 0.7
-
Mozilla Thunderbird 1.0.5
http://www.mozilla.org/products/thunderbird/
Mozilla Thunderbird 0.7.2
-
Mozilla Thunderbird 1.0.5
http://www.mozilla.org/products/thunderbird/
Mozilla Thunderbird 0.7.3
-
Mozilla Thunderbird 1.0.5
http://www.mozilla.org/products/thunderbird/
Mozilla Firefox 0.8
-
Mozilla Firefox 1.0.3
http://www.mozilla.org/products/firefox/
Mozilla Thunderbird 0.8
-
Mozilla Thunderbird 1.0.5
http://www.mozilla.org/products/thunderbird/
Mozilla Firefox 0.9
-
Mozilla Firefox 1.0.3
http://www.mozilla.org/products/firefox/
Mozilla Thunderbird 0.9
-
Mozilla Thunderbird 1.0.5
http://www.mozilla.org/products/thunderbird/
Mozilla Firefox 0.9.1
-
Mozilla Firefox 1.0.3
http://www.mozilla.org/products/firefox/
Mozilla Firefox 0.9.2
-
Mozilla Firefox 1.0.3
http://www.mozilla.org/products/firefox/
Mozilla Firefox 0.9.3
-
Mozilla Firefox 1.0.3
http://www.mozilla.org/products/firefox/
Mozilla Firefox 1.0
-
Mozilla Firefox 1.0.3
http://www.mozilla.org/products/firefox/
Mozilla Thunderbird 1.0
-
Mozilla Thunderbird 1.0.5
http://www.mozilla.org/products/thunderbird/
Mozilla Firefox 1.0.1
-
Mozilla Firefox 1.0.3
http://www.mozilla.org/products/firefox/
Mozilla Thunderbird 1.0.1
-
Mozilla Thunderbird 1.0.5
http://www.mozilla.org/products/thunderbird/
Mozilla Firefox 1.0.2
-
Mozilla Firefox 1.0.3
http://www.mozilla.org/products/firefox/
Mozilla Thunderbird 1.0.2
-
Debian mozilla-thunderbird-dev_1.0.2-2.sarge1.0.6_alpha.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird-dev_1.0.2-2.sarge1.0.6_alpha.deb -
Debian mozilla-thunderbird-dev_1.0.2-2.sarge1.0.6_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird-dev_1.0.2-2.sarge1.0.6_amd64.deb -
Debian mozilla-thunderbird-dev_1.0.2-2.sarge1.0.6_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird-dev_1.0.2-2.sarge1.0.6_arm.deb -
Debian mozilla-thunderbird-dev_1.0.2-2.sarge1.0.6_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird-dev_1.0.2-2.sarge1.0.6_hppa.deb -
Debian mozilla-thunderbird-dev_1.0.2-2.sarge1.0.6_i386.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird-dev_1.0.2-2.sarge1.0.6_i386.deb -
Debian mozilla-thunderbird-dev_1.0.2-2.sarge1.0.6_ia64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird-dev_1.0.2-2.sarge1.0.6_ia64.deb -
Debian mozilla-thunderbird-dev_1.0.2-2.sarge1.0.6_m68k.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird-dev_1.0.2-2.sarge1.0.6_m68k.deb -
Debian mozilla-thunderbird-dev_1.0.2-2.sarge1.0.6_mips.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird-dev_1.0.2-2.sarge1.0.6_mips.deb -
Debian mozilla-thunderbird-dev_1.0.2-2.sarge1.0.6_mipsel.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird-dev_1.0.2-2.sarge1.0.6_mipsel.deb -
Debian mozilla-thunderbird-dev_1.0.2-2.sarge1.0.6_powerpc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird-dev_1.0.2-2.sarge1.0.6_powerpc.deb -
Debian mozilla-thunderbird-dev_1.0.2-2.sarge1.0.6_s390.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird-dev_1.0.2-2.sarge1.0.6_s390.deb -
Debian mozilla-thunderbird-dev_1.0.2-2.sarge1.0.6_sparc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird-dev_1.0.2-2.sarge1.0.6_sparc.deb -
Debian mozilla-thunderbird-inspector_1.0.2-2.sarge1.0.6_alpha.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird-inspector_1.0.2-2.sarge1.0.6_alpha.deb -
Debian mozilla-thunderbird-inspector_1.0.2-2.sarge1.0.6_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird-inspector_1.0.2-2.sarge1.0.6_amd64.deb -
Debian mozilla-thunderbird-inspector_1.0.2-2.sarge1.0.6_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird-inspector_1.0.2-2.sarge1.0.6_arm.deb -
Debian mozilla-thunderbird-inspector_1.0.2-2.sarge1.0.6_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird-inspector_1.0.2-2.sarge1.0.6_hppa.deb -
Debian mozilla-thunderbird-inspector_1.0.2-2.sarge1.0.6_i386.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird-inspector_1.0.2-2.sarge1.0.6_i386.deb -
Debian mozilla-thunderbird-inspector_1.0.2-2.sarge1.0.6_ia64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird-inspector_1.0.2-2.sarge1.0.6_ia64.deb -
Debian mozilla-thunderbird-inspector_1.0.2-2.sarge1.0.6_m68k.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird-inspector_1.0.2-2.sarge1.0.6_m68k.deb -
Debian mozilla-thunderbird-inspector_1.0.2-2.sarge1.0.6_mips.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird-inspector_1.0.2-2.sarge1.0.6_mips.deb -
Debian mozilla-thunderbird-inspector_1.0.2-2.sarge1.0.6_mipsel.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird-inspector_1.0.2-2.sarge1.0.6_mipsel.deb -
Debian mozilla-thunderbird-inspector_1.0.2-2.sarge1.0.6_powerpc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird-inspector_1.0.2-2.sarge1.0.6_powerpc.deb -
Debian mozilla-thunderbird-inspector_1.0.2-2.sarge1.0.6_s390.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird-inspector_1.0.2-2.sarge1.0.6_s390.deb -
Debian mozilla-thunderbird-inspector_1.0.2-2.sarge1.0.6_sparc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird-inspector_1.0.2-2.sarge1.0.6_sparc.deb -
Debian mozilla-thunderbird-inspector_1.0.2-2.sarge1.0.6_sparc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird-offline_1.0.2-2.sarge1.0.6_sparc.deb -
Debian mozilla-thunderbird-offline_1.0.2-2.sarge1.0.6_alpha.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird-offline_1.0.2-2.sarge1.0.6_alpha.deb -
Debian mozilla-thunderbird-offline_1.0.2-2.sarge1.0.6_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird-offline_1.0.2-2.sarge1.0.6_amd64.deb -
Debian mozilla-thunderbird-offline_1.0.2-2.sarge1.0.6_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird-offline_1.0.2-2.sarge1.0.6_arm.deb -
Debian mozilla-thunderbird-offline_1.0.2-2.sarge1.0.6_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird-offline_1.0.2-2.sarge1.0.6_hppa.deb -
Debian mozilla-thunderbird-offline_1.0.2-2.sarge1.0.6_i386.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird-offline_1.0.2-2.sarge1.0.6_i386.deb -
Debian mozilla-thunderbird-offline_1.0.2-2.sarge1.0.6_ia64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird-offline_1.0.2-2.sarge1.0.6_ia64.deb -
Debian mozilla-thunderbird-offline_1.0.2-2.sarge1.0.6_m68k.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird-offline_1.0.2-2.sarge1.0.6_m68k.deb -
Debian mozilla-thunderbird-offline_1.0.2-2.sarge1.0.6_mips.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird-offline_1.0.2-2.sarge1.0.6_mips.deb -
Debian mozilla-thunderbird-offline_1.0.2-2.sarge1.0.6_mipsel.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird-offline_1.0.2-2.sarge1.0.6_mipsel.deb -
Debian mozilla-thunderbird-offline_1.0.2-2.sarge1.0.6_powerpc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird-offline_1.0.2-2.sarge1.0.6_powerpc.deb -
Debian mozilla-thunderbird-offline_1.0.2-2.sarge1.0.6_s390.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird-offline_1.0.2-2.sarge1.0.6_s390.deb -
Debian mozilla-thunderbird-offline_1.0.2-2.sarge1.0.6_sparc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird-offline_1.0.2-2.sarge1.0.6_sparc.deb -
Debian mozilla-thunderbird-typeaheadfind_1.0.2-2.sarge1.0.6_alpha.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird-typeaheadfind_1.0.2-2.sarge1.0.6_alpha.deb -
Debian mozilla-thunderbird-typeaheadfind_1.0.2-2.sarge1.0.6_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird-typeaheadfind_1.0.2-2.sarge1.0.6_amd64.deb -
Debian mozilla-thunderbird-typeaheadfind_1.0.2-2.sarge1.0.6_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird-typeaheadfind_1.0.2-2.sarge1.0.6_arm.deb -
Debian mozilla-thunderbird-typeaheadfind_1.0.2-2.sarge1.0.6_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird-typeaheadfind_1.0.2-2.sarge1.0.6_hppa.deb -
Debian mozilla-thunderbird-typeaheadfind_1.0.2-2.sarge1.0.6_i386.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird-typeaheadfind_1.0.2-2.sarge1.0.6_i386.deb -
Debian mozilla-thunderbird-typeaheadfind_1.0.2-2.sarge1.0.6_ia64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird-typeaheadfind_1.0.2-2.sarge1.0.6_ia64.deb -
Debian mozilla-thunderbird-typeaheadfind_1.0.2-2.sarge1.0.6_m68k.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird-typeaheadfind_1.0.2-2.sarge1.0.6_m68k.deb -
Debian mozilla-thunderbird-typeaheadfind_1.0.2-2.sarge1.0.6_mips.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird-typeaheadfind_1.0.2-2.sarge1.0.6_mips.deb -
Debian mozilla-thunderbird-typeaheadfind_1.0.2-2.sarge1.0.6_mipsel.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird-typeaheadfind_1.0.2-2.sarge1.0.6_mipsel.deb -
Debian mozilla-thunderbird-typeaheadfind_1.0.2-2.sarge1.0.6_powerpc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird-typeaheadfind_1.0.2-2.sarge1.0.6_powerpc.deb -
Debian mozilla-thunderbird-typeaheadfind_1.0.2-2.sarge1.0.6_s390.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird-typeaheadfind_1.0.2-2.sarge1.0.6_s390.deb -
Debian mozilla-thunderbird-typeaheadfind_1.0.2-2.sarge1.0.6_sparc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird-typeaheadfind_1.0.2-2.sarge1.0.6_sparc.deb -
Debian mozilla-thunderbird_1.0.2-2.sarge1.0.6_alpha.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird_1.0.2-2.sarge1.0.6_alpha.deb -
Debian mozilla-thunderbird_1.0.2-2.sarge1.0.6_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird_1.0.2-2.sarge1.0.6_amd64.deb -
Debian mozilla-thunderbird_1.0.2-2.sarge1.0.6_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird_1.0.2-2.sarge1.0.6_arm.deb -
Debian mozilla-thunderbird_1.0.2-2.sarge1.0.6_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird_1.0.2-2.sarge1.0.6_hppa.deb -
Debian mozilla-thunderbird_1.0.2-2.sarge1.0.6_i386.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird_1.0.2-2.sarge1.0.6_i386.deb -
Debian mozilla-thunderbird_1.0.2-2.sarge1.0.6_ia64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird_1.0.2-2.sarge1.0.6_ia64.deb -
Debian mozilla-thunderbird_1.0.2-2.sarge1.0.6_m68k.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird_1.0.2-2.sarge1.0.6_m68k.deb -
Debian mozilla-thunderbird_1.0.2-2.sarge1.0.6_mips.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird_1.0.2-2.sarge1.0.6_mips.deb -
Debian mozilla-thunderbird_1.0.2-2.sarge1.0.6_mipsel.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird_1.0.2-2.sarge1.0.6_mipsel.deb -
Debian mozilla-thunderbird_1.0.2-2.sarge1.0.6_powerpc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird_1.0.2-2.sarge1.0.6_powerpc.deb -
Debian mozilla-thunderbird_1.0.2-2.sarge1.0.6_s390.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird_1.0.2-2.sarge1.0.6_s390.deb -
Debian mozilla-thunderbird_1.0.2-2.sarge1.0.6_sparc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-thunderbird/moz illa-thunderbird_1.0.2-2.sarge1.0.6_sparc.deb -
Mandriva 10.2/RPMS/mozilla-thunderbird-1.0.2-2.1.102mdk.i586.rpm
Mandrakelinux 10.2
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva 10.2/RPMS/mozilla-thunderbird-devel-1.0.2-2.1.102mdk.i586.rpm
Mandrakelinux 10.2
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva 10.2/RPMS/mozilla-thunderbird-enigmail-1.0.2-2.1.102mdk.i586.rpm
Mandrakelinux 10.2
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva 10.2/RPMS/mozilla-thunderbird-enigmime-1.0.2-2.1.102mdk.i586.rpm
Mandrakelinux 10.2
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva x86_64/10.2/RPMS/mozilla-thunderbird-1.0.2-2.1.102mdk.x86_64.rpm
Mandrakelinux 10.2/X86_64
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva x86_64/10.2/RPMS/mozilla-thunderbird-devel-1.0.2-2.1.102mdk.x86_64.rpm
Mandrakelinux 10.2/X86_64
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva x86_64/10.2/RPMS/mozilla-thunderbird-enigmail-1.0.2-2.1.102mdk.x86_64.rpm
Mandrakelinux 10.2/X86_64
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva x86_64/10.2/RPMS/mozilla-thunderbird-enigmime-1.0.2-2.1.102mdk.x86_64.rpm
Mandrakelinux 10.2/X86_64
http://www1.mandrivalinux.com/en/ftp.php3 -
Mozilla Thunderbird 1.0.5
http://www.mozilla.org/products/thunderbird/
Mozilla Browser 1.7 rc1
-
Mozilla Suite 1.7.7
http://www.mozilla.org/products/mozilla1.x/
Mozilla Browser 1.7
-
Mozilla Suite 1.7.7
http://www.mozilla.org/products/mozilla1.x/
Mozilla Browser 1.7 rc2
-
Mozilla Suite 1.7.7
http://www.mozilla.org/products/mozilla1.x/
Mozilla Browser 1.7 alpha
-
Mozilla Suite 1.7.7
http://www.mozilla.org/products/mozilla1.x/
Mozilla Browser 1.7 beta
-
Mozilla Suite 1.7.7
http://www.mozilla.org/products/mozilla1.x/
Mozilla Browser 1.7.1
-
Mozilla Suite 1.7.7
http://www.mozilla.org/products/mozilla1.x/
Mozilla Browser 1.7.2
-
Mozilla Suite 1.7.7
http://www.mozilla.org/products/mozilla1.x/
Mozilla Browser 1.7.3
-
Mozilla Suite 1.7.7
http://www.mozilla.org/products/mozilla1.x/
Mozilla Browser 1.7.4
-
Mozilla Suite 1.7.7
http://www.mozilla.org/products/mozilla1.x/
Mozilla Browser 1.7.5
-
Mozilla Suite 1.7.7
http://www.mozilla.org/products/mozilla1.x/
Mozilla Browser 1.7.6
-
Mozilla Suite 1.7.7
http://www.mozilla.org/products/mozilla1.x/
S.u.S.E. Linux Professional 10.0
-
SuSE MozillaFirefox-1.0.8-0.2.ppc.rpm
SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/MozillaFirefox-1. 0.8-0.2.ppc.rpm -
SuSE MozillaThunderbird-1.0.8-0.2.i586.rpm
SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/MozillaThunderbi rd-1.0.8-0.2.i586.rpm -
SuSE MozillaThunderbird-1.0.8-0.2.x86_64.rpm
SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/x86_64/MozillaThunder bird-1.0.8-0.2.x86_64.rpm
Netscape Netscape 7.0
-
Netscape Netscape 8.0
http://browser.netscape.com/ns8/download/
Netscape Netscape 7.1
-
Netscape Netscape 8.0
http://browser.netscape.com/ns8/download/
Netscape Netscape 7.2
-
Netscape Netscape 8.0
http://browser.netscape.com/ns8/download/
S.u.S.E. Linux Professional 9.1 x86_64
-
SuSE MozillaFirefox-1.0.3-0.5.x86_64.rpm
SUSE Linux 9.1:
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/MozillaFirefo x-1.0.3-0.5.x86_64.rpm
S.u.S.E. Linux Professional 9.1
-
SuSE MozillaFirefox-1.0.3-0.5.i586.rpm
SUSE Linux 9.1:
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/MozillaFirefox-1. 0.3-0.5.i586.rpm -
SuSE MozillaThunderbird-1.0.8-0.1.i586.rpm
SUSE LINUX 9.1:
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/MozillaThunderbir d-1.0.8-0.1.i586.rpm -
SuSE MozillaThunderbird-1.0.8-0.1.x86_64.rpm
SUSE LINUX 9.1:
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/MozillaThunde rbird-1.0.8-0.1.x86_64.rpm
S.u.S.E. Linux Professional 9.2 x86_64
-
SuSE mozilla-1.7.2-17.9.x86_64.rpm
SUSE Linux 9.2:
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/x86_64/mozilla-1.7.2-1 7.9.x86_64.rpm -
SuSE mozilla-calendar-1.7.2-17.9.x86_64.rpm
SUSE Linux 9.2:
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/x86_64/mozilla-calenda r-1.7.2-17.9.x86_64.rpm -
SuSE mozilla-devel-1.7.2-17.9.x86_64.rpm
SUSE Linux 9.2:
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/x86_64/mozilla-devel-1 .7.2-17.9.x86_64.rpm -
SuSE mozilla-dom-inspector-1.7.2-17.9.x86_64.rpm
SUSE Linux 9.2:
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/x86_64/mozilla-dom-ins pector-1.7.2-17.9.x86_64.rpm -
SuSE mozilla-irc-1.7.2-17.9.x86_64.rpm
SUSE Linux 9.2:
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/x86_64/mozilla-irc-1.7 .2-17.9.x86_64.rpm -
SuSE mozilla-mail-1.7.2-17.9.x86_64.rpm
SUSE Linux 9.2:
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/x86_64/mozilla-mail-1. 7.2-17.9.x86_64.rpm -
SuSE mozilla-spellchecker-1.7.2-17.9.x86_64.rpm
SUSE Linux 9.2:
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/x86_64/mozilla-spellch ecker-1.7.2-17.9.x86_64.rpm -
SuSE mozilla-venkman-1.7.2-17.9.x86_64.rpm
SUSE Linux 9.2:
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/x86_64/mozilla-venkman -1.7.2-17.9.x86_64.rpm -
SuSE MozillaFirefox-1.0.3-1.1.x86_64.rpm
SUSE Linux 9.2:
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/x86_64/MozillaFirefox- 1.0.3-1.1.x86_64.rpm
S.u.S.E. Linux Professional 9.3 x86_64
-
SuSE mozilla-1.7.5-17.2.x86_64.rpm
SUSE Linux 9.3:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/x86_64/mozilla-1.7.5-1 7.2.x86_64.rpm -
SuSE mozilla-calendar-1.7.5-17.2.x86_64.rpm
SUSE Linux 9.3:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/x86_64/mozilla-calenda r-1.7.5-17.2.x86_64.rpm -
SuSE mozilla-devel-1.7.5-17.2.x86_64.rpm
SUSE Linux 9.3:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/x86_64/mozilla-devel-1 .7.5-17.2.x86_64.rpm -
SuSE mozilla-dom-inspector-1.7.5-17.2.x86_64.rpm
SUSE Linux 9.3:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/x86_64/mozilla-dom-ins pector-1.7.5-17.2.x86_64.rpm -
SuSE mozilla-irc-1.7.5-17.2.x86_64.rpm
SUSE Linux 9.3:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/x86_64/mozilla-irc-1.7 .5-17.2.x86_64.rpm -
SuSE mozilla-mail-1.7.5-17.2.x86_64.rpm
SUSE Linux 9.3:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/x86_64/mozilla-mail-1. 7.5-17.2.x86_64.rpm -
SuSE mozilla-spellchecker-1.7.5-17.2.x86_64.rpm
SUSE Linux 9.3:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/x86_64/mozilla-spellch ecker-1.7.5-17.2.x86_64.rpm -
SuSE mozilla-venkman-1.7.5-17.2.x86_64.rpm
SUSE Linux 9.3:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/x86_64/mozilla-venkman -1.7.5-17.2.x86_64.rpm
S.u.S.E. Linux Professional 9.3
-
SuSE mozilla-1.7.5-17.2.i586.rpm
SUSE Linux 9.3:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/i586/mozilla-1.7.5-17. 2.i586.rpm -
SuSE mozilla-32bit-9.3-7.1.x86_64.rpm
SUSE Linux 9.3:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/x86_64/mozilla-32bit-9 .3-7.1.x86_64.rpm -
SuSE mozilla-calendar-1.7.5-17.2.i586.rpm
SUSE Linux 9.3:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/i586/mozilla-calendar- 1.7.5-17.2.i586.rpm -
SuSE mozilla-devel-1.7.5-17.2.i586.rpm
SUSE Linux 9.3:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/i586/mozilla-devel-1.7 .5-17.2.i586.rpm -
SuSE mozilla-dom-inspector-1.7.5-17.2.i586.rpm
SUSE Linux 9.3:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/i586/mozilla-dom-inspe ctor-1.7.5-17.2.i586.rpm -
SuSE mozilla-irc-1.7.5-17.2.i586.rpm
SUSE Linux 9.3:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/i586/mozilla-irc-1.7.5 -17.2.i586.rpm -
SuSE mozilla-mail-1.7.5-17.2.i586.rpm
SUSE Linux 9.3:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/i586/mozilla-mail-1.7. 5-17.2.i586.rpm -
SuSE mozilla-spellchecker-1.7.5-17.2.i586.rpm
SUSE Linux 9.3:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/i586/mozilla-spellchec ker-1.7.5-17.2.i586.rpm -
SuSE mozilla-venkman-1.7.5-17.2.i586.rpm
SUSE Linux 9.3:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/i586/mozilla-venkman-1 .7.5-17.2.i586.rpm -
SuSE MozillaFirefox-1.0.3-1.1.i586.rpm
SUSE Linux 9.3:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/i586/MozillaFirefox-1. 0.3-1.1.i586.rpm -
SuSE MozillaFirefox-translations-1.0.3-1.1.i586.rpm
SUSE Linux 9.3:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/i586/MozillaFirefox-tr anslations-1.0.3-1.1.i586.rpm -
SuSE MozillaThunderbird-1.0.8-0.2.i586.rpm
SUSE LINUX 9.3:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/i586/MozillaThunderbir d-1.0.8-0.2.i586.rpm -
SuSE MozillaThunderbird-1.0.8-0.2.x86_64.rpm
SUSE LINUX 9.3:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/x86_64/MozillaThunderb ird-1.0.8-0.2.x86_64.rpm
References
Mozilla Suite And Firefox XPInstall JavaScript Object Instance Validation Vulnerability
References:
References:
- Mozilla Firefox Home Page (Mozilla)
- Mozilla Foundation Security Advisory 2005-37 - Code execution through javascrip (Mozilla)
- Mozilla Foundation Security Advisory 2005-40 - Missing Install object instance (Mozilla)
- Mozilla Homepage (Mozilla Foundation)
- RHSA-2005:383-07 - firefox security update (RedHat)
- RHSA-2005:384-11 - Mozilla security update (Red Hat)
- RHSA-2005:386-08 - Mozilla security update (RedHat)
- Security Alerts (Netscape)
- Firelinking [Firefox 1.0.2] ("mikx"
)