Multiple vulnerabilities have been fixed in Firefox.
------------------------------------------------------------------------
Pardus Linux Security Advisory 2010-47 security@pardus.org.tr
------------------------------------------------------------------------
Date: 2010-04-06
Severity: 3
Type: Remote
------------------------------------------------------------------------
Summary
======
Multiple vulnerabilities have been fixed in Firefox.
Description
==========
With the release of Firefox 3.5.9, the vulnerabilities below have been
fixed. Please go to mozilla advisory page to get more information about
the issues.
MFSA 2010-24 XMLDocument::load() doesn't check nsIContentPolicy
MFSA 2010-23 Image src redirect to mailto: URL opens email editor
MFSA 2010-22 Update NSS to support TLS renegotiation indication
MFSA 2010-20 Chrome privilege escalation via forced URL drag and drop
MFSA 2010-19 Dangling pointer vulnerability in nsPluginArray
MFSA 2010-18 Dangling pointer vulnerability in nsTreeContentView
MFSA 2010-17 Remote code execution with use-after-free in
nsTreeSelection
MFSA 2010-16 Crashes with evidence of memory corruption (rv:1.9.2.2/
1.9.1.9/ 1.9.0.19)
Affected packages:
Pardus 2009:
firefox, all before 3.5.9-123-26
xulrunner, all before 1.9.1.9-28-24
nss, all before 3.12.6.0-30-9
Resolution
=========
There are update(s) for firefox, xulrunner, nss. You can update them via
Package Manager or with a single command from console:
pisi up firefox xulrunner nss
References
=========
* http://www.mozilla.org/security/known-vulnerabilities/firefox35.html
------------------------------------------------------------------------