Accepted firefox 2.0.0.2+0dfsg-0ubuntu0.6.10 (source)
Ubuntu Installer
archive at ubuntu.com
Tue Feb 27 16:59:34 GMT 2007
Accepted:
OK: firefox_2.0.0.2+0dfsg-0ubuntu0.6.10.dsc
-> Component: main Section: web
OK: firefox_2.0.0.2+0dfsg.orig.tar.gz
OK: firefox_2.0.0.2+0dfsg-0ubuntu0.6.10.diff.gz
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Sun, 25 Feb 2006 16:00:00 +0100
Source: firefox
Binary: libnspr4 firefox-dom-inspector firefox-dev mozilla-firefox mozilla-firefox-dev mozilla-firefox-dom-inspector libnss3 libnspr-dev firefox-gnome-support firefox-dbg libnss-dev mozilla-firefox-gnome-support firefox
Architecture: source
Version: 2.0.0.2+0dfsg-0ubuntu0.6.10
Distribution: edgy-security
Urgency: low
Maintainer: Eric Dorland <eric at debian.org>
Changed-By: Alexander Sack <asac at ubuntu.com>
Description:
firefox - lightweight web browser based on Mozilla
firefox-dbg - debugging symbols for firefox
firefox-dev - Development files for Mozilla Firefox
firefox-dom-inspector - tool for inspecting the DOM of pages in Mozilla Firefox
firefox-gnome-support - Support for Gnome in Mozilla Firefox
libnspr-dev - Netscape Portable Runtime library - development files
libnspr4 - Netscape Portable Runtime Library
libnss-dev - Network Security Service Libraries - development
libnss3 - Network Security Service Libraries - runtime
mozilla-firefox - Transition package for firefox rename
mozilla-firefox-dev - dummy transitional package
mozilla-firefox-dom-inspector - Transition package for firefox rename
mozilla-firefox-gnome-support - Transition package for firefox rename
Changes:
firefox (2.0.0.2+0dfsg-0ubuntu0.6.10) edgy-security; urgency=low
.
* New upstream security update:
* MFSA2007-01 - Crashes with evidence of memory corruption
(rv:1.8.0.10/1.8.1.2):
- CVE-2007-0775 - layout engine crashes
- CVE-2007-0776 - SVG
- CVE-2007-0777 - javascript engine corruption
* MFSA2007-02 - Improvements to help protect against Cross-Site
Scripting attacks:
- CVE-2007-0995 - Invalid trailing characters in HTML tag attributes
- CVE-2007-0996 - Child frame character set inheritance
- CVE-2006-6077 - Injected password forms
* MFSA2007-03 aka CVE-2007-0778: Information disclosure through cache
collisions
* MFSA2007-04 aka CVE-2007-0779: Spoofing using custom cursor and CSS3
hotspot
* MFSA2007-05 aka CVE-2007-0780, CVE-2007-0800: XSS and local file access
by opening blocked popups
* MFSA2007-06 aka CVE-2007-0008, CVE-2007-0009: Mozilla Network Security
Services (NSS) SSLv2 buffer overflow
* MFSA2007-07 aka CVE-2007-0981: Embedded nulls in location.hostname
confuse same-domain checks
* browser/app/profile/firefox.js: resolved merge conflict
Files:
c6708c7c771a995e0ec709cc022ce61a 1218 web optional firefox_2.0.0.2+0dfsg-0ubuntu0.6.10.dsc
f6dad051f9995ebba310e8cd6497ae9f 46466665 web optional firefox_2.0.0.2+0dfsg.orig.tar.gz
4d8894d022833e46c25d5e6ce269ee5b 322293 web optional firefox_2.0.0.2+0dfsg-0ubuntu0.6.10.diff.gz
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iD8DBQFF4wr7DecnbV4Fd/IRAmtsAKCwxWqzB10sqBsaXDNoiZN8bM5FbgCfQZtQ
rNG9D3hnsusJp1gqbdQCb3s=
=iuWO
-----END PGP SIGNATURE-----
More information about the edgy-changes
mailing list