Multiple Mozilla Products Memory Corruption/Code Injection/Access Restriction Bypass Vulnerabilities
BID:16476
Info
Multiple Mozilla Products Memory Corruption/Code Injection/Access Restriction Bypass Vulnerabilities
| Bugtraq ID: | 16476 |
| Class: | Unknown |
| CVE: |
CVE-2006-0298 CVE-2006-0297 CVE-2006-0296 CVE-2006-0295 CVE-2006-0294 CVE-2006-0293 CVE-2006-0292 CVE-2006-0299 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 02 2006 12:00AM |
| Updated: | Sep 10 2008 08:20PM |
| Credit: | These issues were disclosed by the vendor. Credit goes to Igor Bukanov, Martijn Wargers, ZIPLOCK, Georgi Guninski, moz_bug_r_a4, Johnny Stenback and Brendan Eich for the discovery of these issues. |
| Vulnerable: |
Ubuntu Ubuntu Linux 5.10 powerpc Ubuntu Ubuntu Linux 5.10 i386 Ubuntu Ubuntu Linux 5.10 amd64 Ubuntu Ubuntu Linux 5.0 4 powerpc Ubuntu Ubuntu Linux 5.0 4 i386 Ubuntu Ubuntu Linux 5.0 4 amd64 Ubuntu Ubuntu Linux 4.1 ppc Ubuntu Ubuntu Linux 4.1 ia64 Ubuntu Ubuntu Linux 4.1 ia32 Sun Solaris 9_x86 Update 2 Sun Solaris 9_x86 Sun Solaris 9 Sun Solaris 8_x86 Sun Solaris 8_sparc Sun Solaris 10_x86 Sun Solaris 10.0_x86 Sun Solaris 10.0 Sun Solaris 10 Sun Java Desktop System (JDS) 2.0 SGI ProPack 3.0 SP6 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 Redhat Linux 9.0 i386 Redhat Linux 7.3 i686 Redhat Linux 7.3 i386 Redhat Linux 7.3 Redhat Fedora Core4 Redhat Fedora Core3 Redhat Fedora Core2 Redhat Fedora Core1 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux WS 2.1 IA64 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux ES 2.1 IA64 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux AS 4 Redhat Enterprise Linux AS 3 Redhat Enterprise Linux AS 2.1 IA64 Redhat Enterprise Linux AS 2.1 Redhat Desktop 4.0 Redhat Desktop 3.0 Redhat Advanced Workstation for the Itanium Processor 2.1 IA64 Redhat Advanced Workstation for the Itanium Processor 2.1 Mozilla Thunderbird 1.5 beta 2 Mozilla Thunderbird 1.5 Mozilla Thunderbird 1.0.7 Mozilla Thunderbird 1.0.6 Mozilla Thunderbird 1.0.5 Mozilla Thunderbird 1.0.2 Mozilla Thunderbird 1.0.1 Mozilla Thunderbird 1.0 Mozilla Thunderbird 0.9 Mozilla Thunderbird 0.8 Mozilla Thunderbird 0.7.3 Mozilla Thunderbird 0.7.2 Mozilla Thunderbird 0.7.1 Mozilla Thunderbird 0.7 Mozilla Thunderbird 0.6 Mozilla SeaMonkey 1.0 dev Mozilla Firefox 1.5 beta 2 Mozilla Firefox 1.5 beta 1 Mozilla Firefox 1.5 Mozilla Firefox 1.0.7 Mozilla Firefox 1.0.6 Mozilla Firefox 1.0.5 Mozilla Firefox 1.0.5 Mozilla Firefox 1.0.4 Mozilla Firefox 1.0.3 Mozilla Firefox 1.0.2 Mozilla Firefox 1.0.1 Mozilla Firefox 1.0 Mozilla Firefox 0.10.1 Mozilla Firefox 0.10 Mozilla Firefox 0.9.3 Mozilla Firefox 0.9.2 Mozilla Firefox 0.9.1 Mozilla Firefox 0.9 rc Mozilla Firefox 0.9 Mozilla Firefox 0.8 Mozilla Firefox Preview Release Mozilla Browser 1.7.12 Mozilla Browser 1.7.11 Mozilla Browser 1.7.10 Mozilla Browser 1.7.9 Mozilla Browser 1.7.8 Mozilla Browser 1.7.7 Mozilla Browser 1.7.6 Mozilla Browser 1.7.5 Mozilla Browser 1.7.4 Mozilla Browser 1.7.3 Mozilla Browser 1.7.2 Mozilla Browser 1.7.1 Mozilla Browser 1.7 rc3 Mozilla Browser 1.7 rc2 Mozilla Browser 1.7 rc1 Mozilla Browser 1.7 beta Mozilla Browser 1.7 alpha Mozilla Browser 1.7 Mozilla Browser 1.6 Mozilla Browser 1.5.1 Mozilla Browser 1.5 Mozilla Browser 1.4.4 Mozilla Browser 1.4.2 Mozilla Browser 1.4.1 Mozilla Browser 1.4 b Mozilla Browser 1.4 a Mozilla Browser 1.4 Mozilla Browser 1.3.1 Mozilla Browser 1.3 Mozilla Browser 1.2.1 Mozilla Browser 1.2 Beta Mozilla Browser 1.2 Alpha Mozilla Browser 1.2 Mozilla Browser 1.1 Beta Mozilla Browser 1.1 Alpha Mozilla Browser 1.1 Mozilla Browser 1.0.2 Mozilla Browser 1.0.1 Mozilla Browser 1.0 RC2 Mozilla Browser 1.0 RC1 Mozilla Browser 1.0 Mozilla Browser 0.9.48 Mozilla Browser 0.9.35 Mozilla Browser 0.9.9 Mozilla Browser 0.9.8 Mozilla Browser 0.9.7 Mozilla Browser 0.9.6 Mozilla Browser 0.9.5 Mozilla Browser 0.9.4 .1 Mozilla Browser 0.9.4 Mozilla Browser 0.9.3 Mozilla Browser 0.9.2 .1 Mozilla Browser 0.9.2 Mozilla Browser 0.8 Mandriva Linux Mandrake 2006.0 x86_64 Mandriva Linux Mandrake 2006.0 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 HP HP-UX B.11.31 HP HP-UX B.11.23 HP HP-UX B.11.11 HP HP-UX B.11.11 HP HP-UX B.11.00 Gentoo Linux Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 |
| Not Vulnerable: |
Mozilla SeaMonkey 1.0 Mozilla Firefox 1.5.0.1 |
Discussion
Multiple Mozilla Products Memory Corruption/Code Injection/Access Restriction Bypass Vulnerabilities
Multiple Mozilla products are prone to multiple vulnerabilities. These issues include various memory-corruption, code-injection, and access-restriction-bypass vulnerabilities. Other undisclosed issues may have also been addressed in the various updated vendor applications.
Successful exploitation of these issues may permit an attacker to execute arbitrary code in the context of the affected application. This may facilitate a compromise of the affected computer; other attacks are also possible.
Multiple Mozilla products are prone to multiple vulnerabilities. These issues include various memory-corruption, code-injection, and access-restriction-bypass vulnerabilities. Other undisclosed issues may have also been addressed in the various updated vendor applications.
Successful exploitation of these issues may permit an attacker to execute arbitrary code in the context of the affected application. This may facilitate a compromise of the affected computer; other attacks are also possible.
Exploit / POC
Multiple Mozilla Products Memory Corruption/Code Injection/Access Restriction Bypass Vulnerabilities
An exploit is not required for some of these issues.
Metasploit has released modules that target the Firefox 'QueryInterface()' function to execute code. These modules target Firefox 1.5.0 for Linux and Apple Mac OS X.
An exploit is not required for some of these issues.
Metasploit has released modules that target the Firefox 'QueryInterface()' function to execute code. These modules target Firefox 1.5.0 for Linux and Apple Mac OS X.
Solution / Fix
Multiple Mozilla Products Memory Corruption/Code Injection/Access Restriction Bypass Vulnerabilities
Solution:
Please see the referenced vendor advisories for details on obtaining and applying fixes.
Sun Solaris 10.0
Sun Solaris 8_sparc
Mozilla SeaMonkey 1.0 dev
Mozilla Firefox 0.10.1
Mozilla Firefox 0.8
Mozilla Thunderbird 0.8
Mozilla Firefox 0.9
Mozilla Firefox 1.0.2
Mozilla Firefox 1.0.4
Mozilla Firefox 1.0.5
Mozilla Firefox 1.0.7
Mozilla Browser 1.4.1
Mozilla Firefox 1.5 beta 2
Mozilla Browser 1.6
S.u.S.E. Linux Professional 9.2
S.u.S.E. Linux Professional 9.3
Solution:
Please see the referenced vendor advisories for details on obtaining and applying fixes.
Sun Solaris 10.0
-
Sun 119115-19
Mozilla 1.7 for Solaris 10
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -119115-19-1
Sun Solaris 8_sparc
Mozilla SeaMonkey 1.0 dev
-
Mozilla SeaMonkey 1.0
http://ftp.mozilla.org/pub/mozilla.org/seamonkey/releases/1.0/seamonke y-1.0.en-US.win32.installer.exe
Mozilla Firefox 0.10.1
-
Mozilla Firefox 1.5.0.1
http://www.mozilla.com/products/download.html?product=firefox-1.5.0.1& os=win&lang=en-US -
RedHat firefox-1.0.7-1.3.fc3.legacy.i386.rpm
Fedora Core 3:
http://download.fedoralegacy.org/fedora/3/updates/i386/firefox-1.0.7-1 .3.fc3.legacy.i386.rpm -
RedHat firefox-1.0.7-1.3.fc3.legacy.x86_64.rpm
Fedora Core 3:
http://download.fedoralegacy.org/fedora/3/updates/x86_64/firefox-1.0.7 -1.3.fc3.legacy.x86_64.rpm
Mozilla Firefox 0.8
-
Mozilla Firefox 1.5.0.1
http://www.mozilla.com/products/download.html?product=firefox-1.5.0.1& os=win&lang=en-US
Mozilla Thunderbird 0.8
-
Fedora Legacy thunderbird-1.0.8-1.1.fc3.4.legacy.i386.rpm
Fedora Core 3:
http://download.fedoralegacy.org/fedora/3/updates/i386/thunderbird-1.0 .8-1.1.fc3.4.legacy.i386.rpm -
Fedora Legacy thunderbird-1.0.8-1.1.fc3.4.legacy.x86_64.rpm
Fedora Core 3:
http://download.fedoralegacy.org/fedora/3/updates/x86_64/thunderbird-1 .0.8-1.1.fc3.4.legacy.x86_64.rpm
Mozilla Firefox 0.9
-
Mozilla Firefox 1.5.0.1
http://www.mozilla.com/products/download.html?product=firefox-1.5.0.1& os=win&lang=en-US
Mozilla Firefox 1.0.2
-
Mozilla Firefox 1.5.0.1
http://www.mozilla.com/products/download.html?product=firefox-1.5.0.1& os=win&lang=en-US
Mozilla Firefox 1.0.4
-
Debian mozilla-firefox-dom-inspector_1.0.4-2sarge6_alpha.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla -firefox-dom-inspector_1.0.4-2sarge6_alpha.deb -
Debian mozilla-firefox-dom-inspector_1.0.4-2sarge6_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla -firefox-dom-inspector_1.0.4-2sarge6_amd64.deb -
Debian mozilla-firefox-dom-inspector_1.0.4-2sarge6_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla -firefox-dom-inspector_1.0.4-2sarge6_arm.deb -
Debian mozilla-firefox-dom-inspector_1.0.4-2sarge6_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla -firefox-dom-inspector_1.0.4-2sarge6_hppa.deb -
Debian mozilla-firefox-dom-inspector_1.0.4-2sarge6_i386.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla -firefox-dom-inspector_1.0.4-2sarge6_i386.deb -
Debian mozilla-firefox-dom-inspector_1.0.4-2sarge6_ia64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla -firefox-dom-inspector_1.0.4-2sarge6_ia64.deb -
Debian mozilla-firefox-dom-inspector_1.0.4-2sarge6_m68k.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla -firefox-dom-inspector_1.0.4-2sarge6_m68k.deb -
Debian mozilla-firefox-dom-inspector_1.0.4-2sarge6_mips.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla -firefox-dom-inspector_1.0.4-2sarge6_mips.deb -
Debian mozilla-firefox-dom-inspector_1.0.4-2sarge6_mipsel.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla -firefox-dom-inspector_1.0.4-2sarge6_mipsel.deb -
Debian mozilla-firefox-dom-inspector_1.0.4-2sarge6_powerpc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla -firefox-dom-inspector_1.0.4-2sarge6_powerpc.deb -
Debian mozilla-firefox-dom-inspector_1.0.4-2sarge6_s390.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla -firefox-dom-inspector_1.0.4-2sarge6_s390.deb -
Debian mozilla-firefox-dom-inspector_1.0.4-2sarge6_sparc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla -firefox-dom-inspector_1.0.4-2sarge6_sparc.deb -
Debian mozilla-firefox-gnome-support_1.0.4-2sarge6_alpha.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla -firefox-gnome-support_1.0.4-2sarge6_alpha.deb -
Debian mozilla-firefox-gnome-support_1.0.4-2sarge6_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla -firefox-gnome-support_1.0.4-2sarge6_amd64.deb -
Debian mozilla-firefox-gnome-support_1.0.4-2sarge6_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla -firefox-gnome-support_1.0.4-2sarge6_arm.deb -
Debian mozilla-firefox-gnome-support_1.0.4-2sarge6_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla -firefox-gnome-support_1.0.4-2sarge6_hppa.deb -
Debian mozilla-firefox-gnome-support_1.0.4-2sarge6_i386.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla -firefox-gnome-support_1.0.4-2sarge6_i386.deb -
Debian mozilla-firefox-gnome-support_1.0.4-2sarge6_ia64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla -firefox-gnome-support_1.0.4-2sarge6_ia64.deb -
Debian mozilla-firefox-gnome-support_1.0.4-2sarge6_m68k.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla -firefox-gnome-support_1.0.4-2sarge6_m68k.deb -
Debian mozilla-firefox-gnome-support_1.0.4-2sarge6_mips.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla -firefox-gnome-support_1.0.4-2sarge6_mips.deb -
Debian mozilla-firefox-gnome-support_1.0.4-2sarge6_mipsel.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla -firefox-gnome-support_1.0.4-2sarge6_mipsel.deb -
Debian mozilla-firefox-gnome-support_1.0.4-2sarge6_powerpc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla -firefox-gnome-support_1.0.4-2sarge6_powerpc.deb -
Debian mozilla-firefox-gnome-support_1.0.4-2sarge6_s390.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla -firefox-gnome-support_1.0.4-2sarge6_s390.deb -
Debian mozilla-firefox-gnome-support_1.0.4-2sarge6_sparc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla -firefox-gnome-support_1.0.4-2sarge6_sparc.deb -
Debian mozilla-firefox_1.0.4-2sarge6_alpha.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla -firefox_1.0.4-2sarge6_alpha.deb -
Debian mozilla-firefox_1.0.4-2sarge6_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla -firefox_1.0.4-2sarge6_amd64.deb -
Debian mozilla-firefox_1.0.4-2sarge6_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla -firefox_1.0.4-2sarge6_arm.deb -
Debian mozilla-firefox_1.0.4-2sarge6_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla -firefox_1.0.4-2sarge6_hppa.deb -
Debian mozilla-firefox_1.0.4-2sarge6_i386.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla -firefox_1.0.4-2sarge6_i386.deb -
Debian mozilla-firefox_1.0.4-2sarge6_ia64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla -firefox_1.0.4-2sarge6_ia64.deb -
Debian mozilla-firefox_1.0.4-2sarge6_m68k.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla -firefox_1.0.4-2sarge6_m68k.deb -
Debian mozilla-firefox_1.0.4-2sarge6_mips.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla -firefox_1.0.4-2sarge6_mips.deb -
Debian mozilla-firefox_1.0.4-2sarge6_mipsel.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla -firefox_1.0.4-2sarge6_mipsel.deb -
Debian mozilla-firefox_1.0.4-2sarge6_powerpc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla -firefox_1.0.4-2sarge6_powerpc.deb -
Debian mozilla-firefox_1.0.4-2sarge6_s390.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla -firefox_1.0.4-2sarge6_s390.deb -
Debian mozilla-firefox_1.0.4-2sarge6_sparc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla -firefox_1.0.4-2sarge6_sparc.deb -
Mozilla Firefox 1.5.0.1
http://www.mozilla.com/products/download.html?product=firefox-1.5.0.1& os=win&lang=en-US
Mozilla Firefox 1.0.5
-
Mozilla Firefox 1.5.0.1
http://www.mozilla.com/products/download.html?product=firefox-1.5.0.1& os=win&lang=en-US
Mozilla Firefox 1.0.7
-
Mozilla Firefox 1.5.0.1
http://www.mozilla.com/products/download.html?product=firefox-1.5.0.1& os=win&lang=en-US
Mozilla Browser 1.4.1
-
RedHat mozilla-1.7.12-1.1.2.legacy.i386.rpm
Fedora Core 1:
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-1.7.12- 1.1.2.legacy.i386.rpm -
RedHat mozilla-chat-1.7.12-1.1.2.legacy.i386.rpm
Fedora Core 1:
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-chat-1. 7.12-1.1.2.legacy.i386.rpm -
RedHat mozilla-devel-1.7.12-1.1.2.legacy.i386.rpm
Fedora Core 1:
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-devel-1 .7.12-1.1.2.legacy.i386.rpm -
RedHat mozilla-dom-inspector-1.7.12-1.1.2.legacy.i386.rpm
Fedora Core 1:
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-dom-ins pector-1.7.12-1.1.2.legacy.i386.rpm -
RedHat mozilla-js-debugger-1.7.12-1.1.2.legacy.i386.rpm
Fedora Core 1:
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-js-debu gger-1.7.12-1.1.2.legacy.i386.rpm -
RedHat mozilla-mail-1.7.12-1.1.2.legacy.i386.rpm
Fedora Core 1:
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-mail-1. 7.12-1.1.2.legacy.i386.rpm -
RedHat mozilla-nspr-1.7.12-1.1.2.legacy.i386.rpm
Fedora Core 1:
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-nspr-1. 7.12-1.1.2.legacy.i386.rpm -
RedHat mozilla-nspr-devel-1.7.12-1.1.2.legacy.i386.rpm
Fedora Core 1:
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-nspr-de vel-1.7.12-1.1.2.legacy.i386.rpm -
RedHat mozilla-nss-1.7.12-1.1.2.legacy.i386.rpm
Fedora Core 1:
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-nss-1.7 .12-1.1.2.legacy.i386.rpm -
RedHat mozilla-nss-devel-1.7.12-1.1.2.legacy.i386.rpm
Fedora Core 1:
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-nss-dev el-1.7.12-1.1.2.legacy.i386.rpm
Mozilla Firefox 1.5 beta 2
-
Mozilla Firefox 1.5.0.1
http://www.mozilla.com/products/download.html?product=firefox-1.5.0.1& os=win&lang=en-US
Mozilla Browser 1.6
-
Mandriva lib64nspr4-1.0.6-16.4.20060mdk.x86_64.rpm
Mandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads/ -
Mandriva lib64nspr4-1.7.8-0.7.C30mdk.x86_64.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads/ -
Mandriva lib64nspr4-devel-1.0.6-16.4.20060mdk.x86_64.rpm
Mandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads/ -
Mandriva lib64nspr4-devel-1.7.8-0.7.C30mdk.x86_64.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads/ -
Mandriva lib64nss3-1.0.6-16.4.20060mdk.x86_64.rpm
Mandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads/ -
Mandriva lib64nss3-1.7.8-0.7.C30mdk.x86_64.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads/ -
Mandriva lib64nss3-devel-1.0.6-16.4.20060mdk.x86_64.rpm
Mandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads/ -
Mandriva lib64nss3-devel-1.7.8-0.7.C30mdk.x86_64.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads/ -
Mandriva libnspr4-1.0.6-16.4.20060mdk.i586.rpm
Mandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads/ -
Mandriva libnspr4-1.7.8-0.7.C30mdk.i586.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads/ -
Mandriva libnspr4-devel-1.0.6-16.4.20060mdk.i586.rpm
Mandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads/ -
Mandriva libnspr4-devel-1.7.8-0.7.C30mdk.i586.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads/ -
Mandriva libnss3-1.0.6-16.4.20060mdk.i586.rpm
Mandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads/ -
Mandriva libnss3-1.7.8-0.7.C30mdk.i586.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads/ -
Mandriva libnss3-devel-1.0.6-16.4.20060mdk.i586.rpm
Mandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads/ -
Mandriva libnss3-devel-1.7.8-0.7.C30mdk.i586.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads/ -
Mandriva mozilla-1.7.8-0.7.C30mdk.i586.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads/ -
Mandriva mozilla-1.7.8-0.7.C30mdk.x86_64.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads/ -
Mandriva mozilla-devel-1.7.8-0.7.C30mdk.i586.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads/ -
Mandriva mozilla-devel-1.7.8-0.7.C30mdk.x86_64.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads/ -
Mandriva mozilla-dom-inspector-1.7.8-0.7.C30mdk.i586.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads/ -
Mandriva mozilla-dom-inspector-1.7.8-0.7.C30mdk.x86_64.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads/ -
Mandriva mozilla-enigmail-1.7.8-0.7.C30mdk.i586.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads/ -
Mandriva mozilla-enigmail-1.7.8-0.7.C30mdk.x86_64.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads/ -
Mandriva mozilla-enigmime-1.7.8-0.7.C30mdk.i586.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads/ -
Mandriva mozilla-enigmime-1.7.8-0.7.C30mdk.x86_64.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads/ -
Mandriva mozilla-firefox-1.0.6-16.4.20060mdk.i586.rpm
Mandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads/ -
Mandriva mozilla-firefox-1.0.6-16.4.20060mdk.x86_64.rpm
Mandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads/ -
Mandriva mozilla-firefox-devel-1.0.6-16.4.20060mdk.i586.rpm
Mandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads/ -
Mandriva mozilla-firefox-devel-1.0.6-16.4.20060mdk.x86_64.rpm
Mandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads/ -
Mandriva mozilla-irc-1.7.8-0.7.C30mdk.i586.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads/ -
Mandriva mozilla-irc-1.7.8-0.7.C30mdk.x86_64.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads/ -
Mandriva mozilla-js-debugger-1.7.8-0.7.C30mdk.i586.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads/ -
Mandriva mozilla-js-debugger-1.7.8-0.7.C30mdk.x86_64.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads/ -
Mandriva mozilla-mail-1.7.8-0.7.C30mdk.i586.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads/ -
Mandriva mozilla-mail-1.7.8-0.7.C30mdk.x86_64.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads/ -
Mandriva mozilla-spellchecker-1.7.8-0.7.C30mdk.i586.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads/ -
Mandriva mozilla-spellchecker-1.7.8-0.7.C30mdk.x86_64.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads/ -
RedHat mozilla-1.7.12-1.2.3.legacy.i386.rpm
Fedora Core 2:
http://download.fedoralegacy.org/fedora/2/updates/i386/mozilla-1.7.12- 1.2.3.legacy.i386.rpm -
RedHat mozilla-chat-1.7.12-1.2.3.legacy.i386.rpm
Fedora Core 2:
http://download.fedoralegacy.org/fedora/2/updates/i386/mozilla-chat-1. 7.12-1.2.3.legacy.i386.rpm -
RedHat mozilla-devel-1.7.12-1.2.3.legacy.i386.rpm
Fedora Core 2:
http://download.fedoralegacy.org/fedora/2/updates/i386/mozilla-devel-1 .7.12-1.2.3.legacy.i386.rpm -
RedHat mozilla-dom-inspector-1.7.12-1.2.3.legacy.i386.rpm
Fedora Core 2:
http://download.fedoralegacy.org/fedora/2/updates/i386/mozilla-dom-ins pector-1.7.12-1.2.3.legacy.i386.rpm -
RedHat mozilla-js-debugger-1.7.12-1.2.3.legacy.i386.rpm
Fedora Core 2:
http://download.fedoralegacy.org/fedora/2/updates/i386/mozilla-js-debu gger-1.7.12-1.2.3.legacy.i386.rpm -
RedHat mozilla-mail-1.7.12-1.2.3.legacy.i386.rpm
Fedora Core 2:
http://download.fedoralegacy.org/fedora/2/updates/i386/mozilla-mail-1. 7.12-1.2.3.legacy.i386.rpm -
RedHat mozilla-nspr-1.7.12-1.2.3.legacy.i386.rpm
Fedora Core 2:
http://download.fedoralegacy.org/fedora/2/updates/i386/mozilla-nspr-1. 7.12-1.2.3.legacy.i386.rpm -
RedHat mozilla-nspr-devel-1.7.12-1.2.3.legacy.i386.rpm
Fedora Core 2:
http://download.fedoralegacy.org/fedora/2/updates/i386/mozilla-nspr-de vel-1.7.12-1.2.3.legacy.i386.rpm -
RedHat mozilla-nss-1.7.12-1.2.3.legacy.i386.rpm
Fedora Core 2:
http://download.fedoralegacy.org/fedora/2/updates/i386/mozilla-nss-1.7 .12-1.2.3.legacy.i386.rpm -
RedHat mozilla-nss-devel-1.7.12-1.2.3.legacy.i386.rpm
Fedora Core 2:
http://download.fedoralegacy.org/fedora/2/updates/i386/mozilla-nss-dev el-1.7.12-1.2.3.legacy.i386.rpm
S.u.S.E. Linux Professional 9.2
-
SuSE MozillaThunderbird-1.0.8-0.2.i586.rpm
SUSE LINUX 9.2:
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/i586/MozillaThunderbir d-1.0.8-0.2.i586.rpm -
SuSE MozillaThunderbird-1.0.8-0.2.x86_64.rpm
SUSE LINUX 9.2:
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/x86_64/MozillaThunderb ird-1.0.8-0.2.x86_64.rpm
S.u.S.E. Linux Professional 9.3
-
SuSE MozillaThunderbird-1.0.8-0.2.i586.rpm
SUSE LINUX 9.3:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/i586/MozillaThunderbir d-1.0.8-0.2.i586.rpm -
SuSE MozillaThunderbird-1.0.8-0.2.x86_64.rpm
SUSE LINUX 9.3:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/x86_64/MozillaThunderb ird-1.0.8-0.2.x86_64.rpm
References
Multiple Mozilla Products Memory Corruption/Code Injection/Access Restriction Bypass Vulnerabilities
References:
References:
- 102550 - Multiple Security Vulnerabilites in Mozilla 1.4 and 1.7 for Solaris and (Sun)
- Bugzilla Bug 316885 (Mozilla bugzilla)
- Bugzilla Bug 317934 (Mozilla bugzilla)
- Bugzilla Bug 319296 (Mozilla bugzilla)
- Bugzilla Bug 319847 (Mozilla bugzilla)
- Bugzilla Bug 319872 (Mozilla bugzilla)
- Bugzilla Bug 320375 (Mozilla bugzilla)
- Bugzilla Bug 322045 (Mozilla bugzilla)
- Bugzilla Bug 322215 (Mozilla Bugzilla)
- Bugzilla Bug 322312 (Mozilla bugzilla)
- HPSBUX02122 SSRT061158 rev.1 - HP-UX Mozilla Remote Execution of Arbitrary Code, (HP)
- HPSBUX02156 SSRT061236 rev.1 - HP-UX Running Thunderbird, Remote Unauthorized Ac (Hewlett-Packard )
- Mozilla Foundation Security Advisory 2006-01 - JavaScript garbage-collection haz (Mozilla)
- Mozilla Foundation Security Advisory 2006-02 - Changing postion:relative to stat (Mozilla)
- Mozilla Foundation Security Advisory 2006-04 - Memory corruption via QueryInterf (Mozilla)
- Mozilla Foundation Security Advisory 2006-05 - Localstore.rdf XML injection thro (Mozilla)
- Mozilla Foundation Security Advisory 2006-06 -Integer overflows in E4X, SVG, and (Mozilla)
- Mozilla Foundation Security Advisory 2006-07 - Read beyond buffer while parsing (Mozilla)
- Mozilla Foundation Security Advisory 2006-08 - AnyName entrainment and access co (Mozilla)
- RHSA-2006:0199-10 - mozilla security update (RedHat)
- RHSA-2006:0200-8 - firefox security update (RedHat)
- RHSA-2006:0330-10 - thunderbird security update (RedHat)
- HPSBUX02156 SSRT061236 rev.2 - HP-UX Running (HP)
- HPSBUX02156 SSRT061236 rev.3 - HP-UX Running Thunderbird, Remote Unauthorized Ac (HP)
- Solution 228526: Multiple Security Vulnerabilites in Mozilla 1.4 and 1.7 for Sol (Sun)