Mailinglist Archive: opensuse-security-announce (8 mails)

< Previous Next >
[security-announce] SUSE Security Announcement: Mozilla (SUSE-SA:2007:049)
  • From: Marcus Meissner <meissner@xxxxxxx>
  • Date: Thu, 02 Aug 2007 16:31:06 +0200
  • Message-id: <46b1eaaa.lKaZAISW0bSzdWGV%meissner@xxxxxxx>

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

______________________________________________________________________________

                        SUSE Security Announcement

        Package:                MozillaFirefox,MozillaThunderbird,Seamonkey
        Announcement ID:        SUSE-SA:2007:049
        Date:                   Thu, 02 Aug 2007 16:00:00 +0000
        Affected Products:      SUSE LINUX 10.0
                                SUSE LINUX 10.1
                                openSUSE 10.2
                                UnitedLinux 1.0
                                SuSE Linux Enterprise Server 8
                                SuSE Linux Openexchange Server 4
                                SuSE Linux Standard Server 8
                                SuSE Linux School Server
                                SUSE LINUX Retail Solution 8
                                SUSE SLES 9
                                Novell Linux Desktop 9
                                Open Enterprise Server
                                Novell Linux POS 9
                                SUSE Linux Enterprise Desktop 10 SP1
                                SUSE Linux Enterprise Server 10 SP1
        Vulnerability Type:     remote code execution
        Severity (1-10):        8
        SUSE Default Package:   yes
        Cross-References:       CVE-2007-3089, CVE-2007-3285, CVE-2007-3656
                                CVE-2007-3670, CVE-2007-3734, CVE-2007-3735
                                CVE-2007-3736, CVE-2007-3737, CVE-2007-3738
                                MFSA 2007-18, MFSA 2007-19, MFSA 2007-20
                                MFSA 2007-21, MFSA 2007-22, MFSA 2007-23
                                MFSA 2007-24, MFSA 2007-25

    Content of This Advisory:
        1) Security Vulnerability Resolved:
             Mozilla security update
           Problem Description
        2) Solution or Work-Around
        3) Special Instructions and Notes
        4) Package Location and Checksums
        5) Pending Vulnerabilities, Solutions, and Work-Arounds:
            See SUSE Security Summary Report.
        6) Authenticity Verification and Additional Information

______________________________________________________________________________

1) Problem Description and Brief Discussion

   Various security problems were found and fixed
   in Mozilla Firefox, Thunderbird and Seamonkey.

   Some of them received version updates,  but the Firefox and Thunderbird
   1.5.0.12 versions received backports.

   The updates have been released over the last 10 days and the last
   were released today.

   Following security problems were fixed:
   - MFSA 2007-18: Crashes with evidence of memory corruption

     The usual collection of stability fixes for crashes that look suspicious but
     haven't been proven to be exploitable.

     25 were in the browser engine, reported by  Mozilla developers and community
     members Bernd Mielke, Boris Zbarsky,  David Baron, Daniel Veditz, Jesse
     Ruderman, Lukas Loehrer, Martijn Wargers, Mats Palmgren, Olli Pettay, Paul
     Nickerson,and  Vladimir Sukhoy (CVE-2007-3734)

     7 were in the JavaScript engine reported by Asaf Romano, Jesse Ruderman, Igor
     Bukanov (CVE-2007-3735)

   - MFSA 2007-19 / CVE-2007-3736: XSS using addEventListener and setTimeout

     moz_bug_r_a4 reported that scripts could be injected into another site's
     context by exploiting a timing issue using addEventLstener or setTimeout.

   - MFSA 2007-20 / CVE-2007-3089: frame spoofing

     Ronen Zilberman and Michal Zalewski both reported that it was possible to
     exploit a timing issue to inject content into about:blank frames in a page.

   - MFSA 2007-21 / CVE-2007-3737:  Privilege escalation using an event
     handler attached to an element not in the document

     Reported by moz_bug_r_a4.

   - MFSA 2007-22 / CVE-2007-3285: File type confusion due to %00 in name

     Ronald van den Heetkamp reported that a filename URL containing %00 (encoded
     null) can cause Firefox to interpret the file extension differently than the
     underlying Windows operating system potentially leading to unsafe actions such
     as running a program.

   - MFSA 2007-23 / CVE-2007-3670: Remote code execution by launching Firefox from Internet Explorer

     Greg MacManus of iDefense and Billy Rios of Verisign independently reported
     that links containing a quote (") character could be used in Internet Explorer
     to launch registered URL Protocol handlers with extra command-line parameters.
     Firefox and Thunderbird are among those which can be launched, and both support
     a "-chrome" option that could be used to run malware.

     This problem does not affect Linux.

   - MFSA 2007-24 / CVE-2007-3656: unauthorized access to wyciwyg:// documents

     Michal Zalewski reported that it was possible to bypass the same-origin checks
     and read from cached (wyciwyg) documents

   - MFSA 2007-25 / CVE-2007-3738: XPCNativeWrapper pollution

     shutdown and moz_bug_r_a4 reported two separate ways to modify an
     XPCNativeWrapper such that subsequent access by the browser would result in
     executing user-supplied code.
2) Solution or Work-Around

   There is no known workaround, please install the update packages.

3) Special Instructions and Notes

   Please close and restart all running instances of Mozilla after the update.

4) Package Location and Checksums

   The preferred method for installing security updates is to use the YaST
   Online Update (YOU) tool. YOU detects which updates are required and
   automatically performs the necessary steps to verify and install them.
   Alternatively, download the update packages for your distribution manually
   and verify their integrity by the methods listed in Section 6 of this
   announcement. Then install the packages using the command

     rpm -Fhv <file.rpm>

   to apply the update, replacing <file.rpm> with the filename of the
   downloaded RPM package.


   x86 Platform:

   openSUSE 10.2:
   ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/MozillaFirefox-2.0.0.5-1.1.i586.rpm
          600db4d96816a290038d625f6e8ed6c6
   ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/MozillaFirefox-translations-2.0.0.5-1.1.i586.rpm
          90aea5380a49655399523f54c4551e69
   ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/MozillaThunderbird-1.5.0.12-3.4.i586.rpm
          e0f8f7b159a2988551f23b7b5b560b3a
   ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/MozillaThunderbird-translations-1.5.0.12-3.4.i586.rpm
          72bb5fa1f29903c83549ebb8203aaed6
   ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/seamonkey-1.1.3-0.1.i586.rpm
          bf8cbf970d08f8ef0c727ca79229efbc
   ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/seamonkey-dom-inspector-1.1.3-0.1.i586.rpm
          a22a745748fcedf9582e59da8e6efea5
   ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/seamonkey-irc-1.1.3-0.1.i586.rpm
          e1cd82fc818a1dbaff7d015a5d9b2ea8
   ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/seamonkey-mail-1.1.3-0.1.i586.rpm
          fabce4275caa83f79319eaea12613ec1
   ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/seamonkey-spellchecker-1.1.3-0.1.i586.rpm
          dd1cfb362e80d66977797cb44b7b44b4
   ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/seamonkey-venkman-1.1.3-0.1.i586.rpm
          1c47e6f77f7e7f60c40f6fb23475aa18

   SUSE LINUX 10.1:
   ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/MozillaFirefox-2.0.0.5-1.2.i586.rpm
          6fe7be0137419b7b78f6e1a1f6a0a4f1
   ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/MozillaFirefox-translations-2.0.0.5-1.2.i586.rpm
          1778646c89276ed2162f77c3da13d046
   ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/seamonkey-1.0.9-1.3.i586.rpm
          b89299ed308dfe59948b2b1afac2f6ef
   ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/seamonkey-calendar-1.0.9-1.3.i586.rpm
          2cf0ee532fbf4c802081dbd1dd4c6d8b
   ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/seamonkey-dom-inspector-1.0.9-1.3.i586.rpm
          2ce4340a93502632ea6d3f20befd4dad
   ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/seamonkey-irc-1.0.9-1.3.i586.rpm
          b301b9572704121c9d172e18886d503e
   ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/seamonkey-mail-1.0.9-1.3.i586.rpm
          d31d58fb662d7f68307c699669b72e33
   ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/seamonkey-spellchecker-1.0.9-1.3.i586.rpm
          198c766f1b32ecfb70e23fc393cab50a
   ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/seamonkey-venkman-1.0.9-1.3.i586.rpm
          e721026c5d410ea0481feed548a6743a

   SUSE LINUX 10.0:
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/MozillaFirefox-2.0.0.5-1.1.i586.rpm
          67b16e7a091997b3d9cd1620982304fe
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/MozillaFirefox-translations-2.0.0.5-1.1.i586.rpm
          1248d3bcbfa5ac7dfdd049e65a68446d
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/MozillaThunderbird-1.5.0.12-1.4.i586.rpm
          6cf2bb6abe7fa60656ed421b6141c6d8
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/mozilla-1.8_seamonkey_1.0.9-2.5.i586.rpm
          2480690fbb55acc8c326c8ff7853647f
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/mozilla-calendar-1.8_seamonkey_1.0.9-2.5.i586.rpm
          e1601d069c0baf24983b383bd6158a69
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/mozilla-devel-1.8_seamonkey_1.0.9-2.5.i586.rpm
          aa48fafdef426a754a99fca4bae76614
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/mozilla-dom-inspector-1.8_seamonkey_1.0.9-2.5.i586.rpm
          7be3a6df9818ffd2d855f833a93cbe91
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/mozilla-irc-1.8_seamonkey_1.0.9-2.5.i586.rpm
          1547a8c884c721888878b16ff2767ad4
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/mozilla-ko-1.75-3.4.i586.rpm
          7d345e1b6605b8ea0e04ad3d8ec77e43
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/mozilla-mail-1.8_seamonkey_1.0.9-2.5.i586.rpm
          8ac98b84ae4bfbd97aae569037171911
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/mozilla-spellchecker-1.8_seamonkey_1.0.9-2.5.i586.rpm
          e258b620ac3cae7731f8857c0699d947
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/mozilla-venkman-1.8_seamonkey_1.0.9-2.5.i586.rpm
          6eb456359ec22b6e02f8e8f534f331d8
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/mozilla-zh-CN-1.7-6.4.i586.rpm
          8bb3aa98e7724a2b50277a0368954b82
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/mozilla-zh-TW-1.7-6.4.i586.rpm
          4a8c81c5c915cd3c996b479a3d21679d

   Power PC Platform:

   openSUSE 10.2:
   ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/MozillaFirefox-2.0.0.5-1.1.ppc.rpm
          848db6f3d85c9e67e5b5200e33f0a6d1
   ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/MozillaFirefox-translations-2.0.0.5-1.1.ppc.rpm
          8914c2e4a9966df51d04e157e84e57b2
   ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/MozillaThunderbird-1.5.0.12-3.4.ppc.rpm
          7d18527f3fe14e6e029b1a368cd3c38e
   ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/MozillaThunderbird-translations-1.5.0.12-3.4.ppc.rpm
          caf0278404575b739b407a88d4925f6f
   ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/seamonkey-1.1.3-0.1.ppc.rpm
          f7b2db2b6a7fa63457a7a1c208bedf65
   ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/seamonkey-dom-inspector-1.1.3-0.1.ppc.rpm
          a59274e07212e90ffc5c55f6cc5d2258
   ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/seamonkey-irc-1.1.3-0.1.ppc.rpm
          b7d25744316faecda6bef7a612643418
   ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/seamonkey-mail-1.1.3-0.1.ppc.rpm
          23f457b57f234798336011e1beec7815
   ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/seamonkey-spellchecker-1.1.3-0.1.ppc.rpm
          29e40bf7466e6c981bf797be0f9e538d
   ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/seamonkey-venkman-1.1.3-0.1.ppc.rpm
          988a2aec600e3bee231f340662b66099

   SUSE LINUX 10.1:
   ftp://ftp.suse.com/pub/suse/update/10.1/rpm/ppc/MozillaFirefox-2.0.0.5-1.2.ppc.rpm
          fdfc4e535397aa715ff0244ce6aca689
   ftp://ftp.suse.com/pub/suse/update/10.1/rpm/ppc/MozillaFirefox-translations-2.0.0.5-1.2.ppc.rpm
          f182603e0d0c59e5f53ffc54a7a1909f
   ftp://ftp.suse.com/pub/suse/update/10.1/rpm/ppc/seamonkey-1.0.9-1.3.ppc.rpm
          579ea0954a79767797119f817fb0e568
   ftp://ftp.suse.com/pub/suse/update/10.1/rpm/ppc/seamonkey-calendar-1.0.9-1.3.ppc.rpm
          9716ccd6033c1ae6dd25cc738b42c416
   ftp://ftp.suse.com/pub/suse/update/10.1/rpm/ppc/seamonkey-dom-inspector-1.0.9-1.3.ppc.rpm
          34d8894a54126c49fcd37565dd9d8423
   ftp://ftp.suse.com/pub/suse/update/10.1/rpm/ppc/seamonkey-irc-1.0.9-1.3.ppc.rpm
          794736b6dde797426856fd69972368eb
   ftp://ftp.suse.com/pub/suse/update/10.1/rpm/ppc/seamonkey-mail-1.0.9-1.3.ppc.rpm
          828c1b007154f62a05f9b2d240861399
   ftp://ftp.suse.com/pub/suse/update/10.1/rpm/ppc/seamonkey-spellchecker-1.0.9-1.3.ppc.rpm
          6bd4b8725bf4463fbc47428a21220338
   ftp://ftp.suse.com/pub/suse/update/10.1/rpm/ppc/seamonkey-venkman-1.0.9-1.3.ppc.rpm
          9bf6d61c1d02281770661aae26eb036d

   SUSE LINUX 10.0:
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/MozillaFirefox-2.0.0.5-1.1.ppc.rpm
          b250aa03a4d0c687e4531a2b3fee05c2
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/MozillaFirefox-translations-2.0.0.5-1.1.ppc.rpm
          c3905c8b330c72dd15fad257146273df
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/MozillaThunderbird-1.5.0.12-1.4.ppc.rpm
          e70b13d3436d6fe143388adf88b26a1d
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/mozilla-1.8_seamonkey_1.0.9-2.5.ppc.rpm
          600f48a27f8086c03e8e690fd2cd4a40
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/mozilla-calendar-1.8_seamonkey_1.0.9-2.5.ppc.rpm
          f7a67fed3884aeaf723599780e509a67
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/mozilla-devel-1.8_seamonkey_1.0.9-2.5.ppc.rpm
          ae39fe07a1dbf1e39471382e1ebb686f
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/mozilla-dom-inspector-1.8_seamonkey_1.0.9-2.5.ppc.rpm
          d71c42e5d6a8ff88a73774589cae6a5e
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/mozilla-irc-1.8_seamonkey_1.0.9-2.5.ppc.rpm
          951cb64dc71e202cea56d59fc4a6931f
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/mozilla-ko-1.75-3.4.ppc.rpm
          ef441debe59e1f76c36e546ae8409b99
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/mozilla-mail-1.8_seamonkey_1.0.9-2.5.ppc.rpm
          59cc7e6bdf993bfb1abf31692a040679
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/mozilla-spellchecker-1.8_seamonkey_1.0.9-2.5.ppc.rpm
          65422388e67d6870dda291a29d4ca098
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/mozilla-venkman-1.8_seamonkey_1.0.9-2.5.ppc.rpm
          69b76e684d82dc7ff6c843d1e82bd44a
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/mozilla-zh-CN-1.7-6.4.ppc.rpm
          8d031f11619a177114917ea7ec993e19
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/mozilla-zh-TW-1.7-6.4.ppc.rpm
          c006ab0fc51caf97b59e01006a16fbb9

   x86-64 Platform:

   openSUSE 10.2:
   ftp://ftp.suse.com/pub/suse/update/10.2/rpm/x86_64/MozillaFirefox-2.0.0.5-1.1.x86_64.rpm
          b89e249c9b3fdf84dd34d38c5578e9d4
   ftp://ftp.suse.com/pub/suse/update/10.2/rpm/x86_64/MozillaFirefox-translations-2.0.0.5-1.1.x86_64.rpm
          6387403a327a3d0a14887888064b8fc9
   ftp://ftp.suse.com/pub/suse/update/10.2/rpm/x86_64/MozillaThunderbird-1.5.0.12-3.4.x86_64.rpm
          290e06b8f9f0b07f7876f06b014503a0
   ftp://ftp.suse.com/pub/suse/update/10.2/rpm/x86_64/MozillaThunderbird-translations-1.5.0.12-3.4.x86_64.rpm
          37e6c95d17265191db93996058c3b5db
   ftp://ftp.suse.com/pub/suse/update/10.2/rpm/x86_64/seamonkey-1.1.3-0.1.x86_64.rpm
          f0ab710e1610e03b4385c3ccc7d931e1
   ftp://ftp.suse.com/pub/suse/update/10.2/rpm/x86_64/seamonkey-dom-inspector-1.1.3-0.1.x86_64.rpm
          b416e3c9a7bd15e0d5bb200c1fd502b1
   ftp://ftp.suse.com/pub/suse/update/10.2/rpm/x86_64/seamonkey-irc-1.1.3-0.1.x86_64.rpm
          6ac2728f862636b5feb9a46ccf0fbdbb
   ftp://ftp.suse.com/pub/suse/update/10.2/rpm/x86_64/seamonkey-mail-1.1.3-0.1.x86_64.rpm
          e276291b08f5b04a51bfba5520c80a71
   ftp://ftp.suse.com/pub/suse/update/10.2/rpm/x86_64/seamonkey-spellchecker-1.1.3-0.1.x86_64.rpm
          f4333a2ad2dd3a7a4c0b15737ad27dda
   ftp://ftp.suse.com/pub/suse/update/10.2/rpm/x86_64/seamonkey-venkman-1.1.3-0.1.x86_64.rpm
          df66fd57450833bdf2fb2b9e13f568ad

   SUSE LINUX 10.1:
   ftp://ftp.suse.com/pub/suse/update/10.1/rpm/x86_64/seamonkey-1.0.9-1.3.x86_64.rpm
          ffaca4596d941b7a616c4bc67d8e4e41
   ftp://ftp.suse.com/pub/suse/update/10.1/rpm/x86_64/seamonkey-calendar-1.0.9-1.3.x86_64.rpm
          ee1e750a083e1ee5f6bbfcd74d6e21e6
   ftp://ftp.suse.com/pub/suse/update/10.1/rpm/x86_64/seamonkey-dom-inspector-1.0.9-1.3.x86_64.rpm
          5d162787d99fa8c80d8da650da163796
   ftp://ftp.suse.com/pub/suse/update/10.1/rpm/x86_64/seamonkey-irc-1.0.9-1.3.x86_64.rpm
          67d70bd2ac236283699eb8e93ef0e040
   ftp://ftp.suse.com/pub/suse/update/10.1/rpm/x86_64/seamonkey-mail-1.0.9-1.3.x86_64.rpm
          fc01c6515926efad9a02b0da03227ce4
   ftp://ftp.suse.com/pub/suse/update/10.1/rpm/x86_64/seamonkey-spellchecker-1.0.9-1.3.x86_64.rpm
          0f9cd3209adeb65d8511a71f94e52898
   ftp://ftp.suse.com/pub/suse/update/10.1/rpm/x86_64/seamonkey-venkman-1.0.9-1.3.x86_64.rpm
          e3d237b834b59032d3bbe5f121d88188

   SUSE LINUX 10.0:
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/x86_64/MozillaThunderbird-1.5.0.12-1.4.x86_64.rpm
          bd6f9c49b021f9f1094179d04d821aa4
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/x86_64/mozilla-1.8_seamonkey_1.0.9-2.5.x86_64.rpm
          1c31c1d2d8f1da4b0d03b94547524117
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/x86_64/mozilla-calendar-1.8_seamonkey_1.0.9-2.5.x86_64.rpm
          119fb5eed3f33b4c2d796f9615d6e6ab
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/x86_64/mozilla-devel-1.8_seamonkey_1.0.9-2.5.x86_64.rpm
          27066ea084991741108c8da61bc2edbf
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/x86_64/mozilla-dom-inspector-1.8_seamonkey_1.0.9-2.5.x86_64.rpm
          1fc21b32c219d3a271dbea37d35d2151
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/x86_64/mozilla-irc-1.8_seamonkey_1.0.9-2.5.x86_64.rpm
          98023c8651c6d5b256970af2a599f351
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/x86_64/mozilla-ko-1.75-3.4.x86_64.rpm
          e7bc7409b88899e19f66627ed206b398
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/x86_64/mozilla-mail-1.8_seamonkey_1.0.9-2.5.x86_64.rpm
          8c6308bf5de41dd7ebf049fa0c012f86
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/x86_64/mozilla-spellchecker-1.8_seamonkey_1.0.9-2.5.x86_64.rpm
          26e29edac4dd784e773d73ce35880235
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/x86_64/mozilla-venkman-1.8_seamonkey_1.0.9-2.5.x86_64.rpm
          57fc71c0136c18cf0ef5b62764e3be04
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/x86_64/mozilla-zh-CN-1.7-6.4.x86_64.rpm
          a6383cc4e41c27be2ccf03ecffecf121
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/x86_64/mozilla-zh-TW-1.7-6.4.x86_64.rpm
          3ec067da3be6af2cd0a0e450c3e402f6

   Sources:

   openSUSE 10.2:
   ftp://ftp.suse.com/pub/suse/update/10.2/rpm/src/MozillaFirefox-2.0.0.5-1.1.src.rpm
          d0dc64ff492bc94a160a912785dd2c8c
   ftp://ftp.suse.com/pub/suse/update/10.2/rpm/src/MozillaThunderbird-1.5.0.12-3.4.src.rpm
          b26b4a68fb6a5d06dac7f03ba791b41a
   ftp://ftp.suse.com/pub/suse/update/10.2/rpm/src/seamonkey-1.1.3-0.1.src.rpm
          943073a9f25683ef62b9ce5225124a12

   SUSE LINUX 10.1:
   ftp://ftp.suse.com/pub/suse/update/10.1/rpm/src/MozillaFirefox-2.0.0.5-1.2.src.rpm
          8f2931d2d6442f8026a58aa6e5e6891d
   ftp://ftp.suse.com/pub/suse/update/10.1/rpm/src/seamonkey-1.0.9-1.3.src.rpm
          88610e7df3d5c0f879643e4bc28ce750

   SUSE LINUX 10.0:
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/src/MozillaFirefox-2.0.0.5-1.1.src.rpm
          d85a04bfda146cf80723bf77b6672ffa
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/src/MozillaThunderbird-1.5.0.12-1.4.src.rpm
          a143552cdbb2ec14f23a4b25ce7bab7b
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/src/mozilla-1.8_seamonkey_1.0.9-2.5.src.rpm
          d907294656dfa9e97190d47a8103437e
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/src/mozilla-ko-1.75-3.4.src.rpm
          eb91a1a9b17caaa4778d5b3af33bb20c
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/src/mozilla-zh-CN-1.7-6.4.src.rpm
          9457510c15dae059a72d5dbc5f33466c
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/src/mozilla-zh-TW-1.7-6.4.src.rpm
          214ac000b6eedc9557883e5de6b68503

   Our maintenance customers are notified individually. The packages are
   offered for installation from the maintenance web:

   Open Enterprise Server
     http://support.novell.com/techcenter/psdb/d91b73c3c1e2666666b5dd6d36be8cbf.html

   Novell Linux POS 9
     http://support.novell.com/techcenter/psdb/d91b73c3c1e2666666b5dd6d36be8cbf.html

   SUSE SLES 9
     http://support.novell.com/techcenter/psdb/d91b73c3c1e2666666b5dd6d36be8cbf.html

   UnitedLinux 1.0
     http://support.novell.com/techcenter/psdb/e40adef97bd42789da250e4cc9e1d01d.html

   SuSE Linux Openexchange Server 4
     http://support.novell.com/techcenter/psdb/e40adef97bd42789da250e4cc9e1d01d.html

   SuSE Linux Enterprise Server 8
     http://support.novell.com/techcenter/psdb/e40adef97bd42789da250e4cc9e1d01d.html

   SuSE Linux Standard Server 8
     http://support.novell.com/techcenter/psdb/e40adef97bd42789da250e4cc9e1d01d.html

   SuSE Linux School Server
     http://support.novell.com/techcenter/psdb/e40adef97bd42789da250e4cc9e1d01d.html

   SUSE LINUX Retail Solution 8
     http://support.novell.com/techcenter/psdb/e40adef97bd42789da250e4cc9e1d01d.html

   Novell Linux Desktop 9
     http://support.novell.com/techcenter/psdb/d91b73c3c1e2666666b5dd6d36be8cbf.html
     http://support.novell.com/techcenter/psdb/975911e840a1ef54b4b939009daa4a70.html

   Novell Linux Desktop 9 for x86
     http://support.novell.com/techcenter/psdb/975911e840a1ef54b4b939009daa4a70.html

   SUSE Linux Enterprise Server 10 SP1
     http://support.novell.com/techcenter/psdb/07d098f99c9fe6956523beae37f32fda.html

   SUSE Linux Enterprise Desktop 10 SP1
     http://support.novell.com/techcenter/psdb/07d098f99c9fe6956523beae37f32fda.html

______________________________________________________________________________

5) Pending Vulnerabilities, Solutions, and Work-Arounds:

   See SUSE Security Summary Report.
______________________________________________________________________________

6) Authenticity Verification and Additional Information

  - Announcement authenticity verification:

    SUSE security announcements are published via mailing lists and on Web
    sites. The authenticity and integrity of a SUSE security announcement is
    guaranteed by a cryptographic signature in each announcement. All SUSE
    security announcements are published with a valid signature.

    To verify the signature of the announcement, save it as text into a file
    and run the command

      gpg --verify <file>

    replacing <file> with the name of the file where you saved the
    announcement. The output for a valid signature looks like:

      gpg: Signature made <DATE> using RSA key ID 3D25D3D9
      gpg: Good signature from "SuSE Security Team <security@xxxxxxx>"

    where <DATE> is replaced by the date the document was signed.

    If the security team's key is not contained in your key ring, you can
    import it from the first installation CD. To import the key, use the
    command

      gpg --import gpg-pubkey-3d25d3d9-36e12d04.asc

  - Package authenticity verification:

    SUSE update packages are available on many mirror FTP servers all over the
    world. While this service is considered valuable and important to the free
    and open source software community, the authenticity and the integrity of
    a package needs to be verified to ensure that it has not been tampered
    with.

    There are two verification methods that can be used independently from
    each other to prove the authenticity of a downloaded file or RPM package:

    1) Using the internal gpg signatures of the rpm package
    2) MD5 checksums as provided in this announcement

    1) The internal rpm package signatures provide an easy way to verify the
       authenticity of an RPM package. Use the command

        rpm -v --checksig <file.rpm>

       to verify the signature of the package, replacing <file.rpm> with the
       filename of the RPM package downloaded. The package is unmodified if it
       contains a valid signature from build@xxxxxxx with the key ID 9C800ACA.

       This key is automatically imported into the RPM database (on
       RPMv4-based distributions) and the gpg key ring of 'root' during
       installation. You can also find it on the first installation CD and at
       the end of this announcement.

    2) If you need an alternative means of verification, use the md5sum
       command to verify the authenticity of the packages. Execute the command

         md5sum <filename.rpm>

       after you downloaded the file from a SUSE FTP server or its mirrors.
       Then compare the resulting md5sum with the one that is listed in the
       SUSE security announcement. Because the announcement containing the
       checksums is cryptographically signed (by security@xxxxxxx), the
       checksums show proof of the authenticity of the package if the
       signature of the announcement is valid. Note that the md5 sums
       published in the SUSE Security Announcements are valid for the
       respective packages only. Newer versions of these packages cannot be
       verified.

  - SUSE runs two security mailing lists to which any interested party may
    subscribe:

    opensuse-security@xxxxxxxxxxxx
        -   General Linux and SUSE security discussion.
            All SUSE security announcements are sent to this list.
            To subscribe, send an e-mail to
                <opensuse-security+subscribe@xxxxxxxxxxxx>.

    opensuse-security-announce@xxxxxxxxxxxx
        -   SUSE's announce-only mailing list.
            Only SUSE's security announcements are sent to this list.
            To subscribe, send an e-mail to
                <opensuse-security-announce+subscribe@xxxxxxxxxxxx>.

    =====================================================================
    SUSE's security contact is <security@xxxxxxxx> or <security@xxxxxxx>.
    The <security@xxxxxxx> public key is listed below.
    =====================================================================
______________________________________________________________________________

    The information in this advisory may be distributed or reproduced,
    provided that the advisory is not modified in any way. In particular, the
    clear text signature should show proof of the authenticity of the text.

    SUSE Linux Products GmbH provides no warranties of any kind whatsoever
    with respect to the information contained in this security advisory.

Type Bits/KeyID     Date       User ID
pub  2048R/3D25D3D9 1999-03-06 SuSE Security Team <security@xxxxxxx>
pub  1024D/9C800ACA 2000-10-19 SuSE Package Signing Key <build@xxxxxxx>

- -----BEGIN PGP PUBLIC KEY BLOCK-----
Version: GnuPG v1.4.2 (GNU/Linux)

mQENAzbhLQQAAAEIAKAkXHe0lWRBXLpn38hMHy03F0I4Sszmoc8aaKJrhfhyMlOA
BqvklPLE2f9UrI4Xc860gH79ZREwAgPt0pi6+SleNFLNcNFAuuHMLQOOsaMFatbz
JR9i4m/lf6q929YROu5zB48rBAlcfTm+IBbijaEdnqpwGib45wE/Cfy6FAttBHQh
1Kp+r/jPbf1mYAvljUfHKuvbg8t2EIQz/5yGp+n5trn9pElfQO2cRBq8LFpf1l+U
P7EKjFmlOq+Gs/fF98/dP3DfniSd78LQPq5vp8RL8nr/o2i7jkAQ33m4f1wOBWd+
cZovrKXYlXiR+Bf7m2hpZo+/sAzhd7LmAD0l09kABRG0JVN1U0UgU2VjdXJpdHkg
VGVhbSA8c2VjdXJpdHlAc3VzZS5kZT6JARUDBRA24S1H5Fiyh7HKPEUBAVcOB/9b
yHYji1/+4Xc2GhvXK0FSJN0MGgeXgW47yxDL7gmR4mNgjlIOUHZj0PEpVjWepOJ7
tQS3L9oP6cpj1Fj/XxuLbkp5VCQ61hpt54coQAvYrnT9rtWEGN+xmwejT1WmYmDJ
xG+EGBXKr+XP69oIUl1E2JO3rXeklulgjqRKos4cdXKgyjWZ7CP9V9daRXDtje63
Om8gwSdU/nCvhdRIWp/Vwbf7Ia8iZr9OJ5YuQl0DBG4qmGDDrvImgPAFkYFzwlqo
choXFQ9y0YVCV41DnR+GYhwl2qBd81T8aXhihEGPIgaw3g8gd8B5o6mPVgl+nJqI
BkEYGBusiag2pS6qwznZiQEVAwUQNuEtBHey5gA9JdPZAQFtOAf+KVh939b0J94u
v/kpg4xs1LthlhquhbHcKNoVTNspugiC3qMPyvSX4XcBr2PC0cVkS4Z9PY9iCfT+
x9WM96g39dAF+le2CCx7XISk9XXJ4ApEy5g4AuK7NYgAJd39PPbERgWnxjxir9g0
Ix30dS30bW39D+3NPU5Ho9TD/B7UDFvYT5AWHl3MGwo3a1RhTs6sfgL7yQ3U+mvq
MkTExZb5mfN1FeaYKMopoI4VpzNVeGxQWIz67VjJHVyUlF20ekOz4kWVgsxkc8G2
saqZd6yv2EwqYTi8BDAduweP33KrQc4KDDommQNDOXxaKOeCoESIdM4p7Esdjq1o
L0oixF12CohGBBARAgAGBQI7HmHDAAoJEJ5A4xAACqukTlQAoI4QzP9yjPohY7OU
F7J3eKBTzp25AJ42BmtSd3pvm5ldmognWF3Trhp+GYkAlQMFEDe3O8IWkDf+zvyS
FQEBAfkD/3GG5UgJj18UhYmh1gfjIlDcPAeqMwSytEHDENmHC+vlZQ/p0mT9tPiW
tp34io54mwr+bLPN8l6B5GJNkbGvH6M+mO7R8Lj4nHL6pyAv3PQr83WyLHcaX7It
Klj371/4yzKV6qpz43SGRK4MacLo2rNZ/dNej7lwPCtzCcFYwqkiiEYEEBECAAYF
AjoaQqQACgkQx1KqMrDf94ArewCfWnTUDG5gNYkmHG4bYL8fQcizyA4An2eVo/n+
3J2KRWSOhpAMsnMxtPbBmQGiBDnu9IERBACT8Y35+2vv4MGVKiLEMOl9GdST6MCk
YS3yEKeueNWc+z/0Kvff4JctBsgs47tjmiI9sl0eHjm3gTR8rItXMN6sJEUHWzDP
+Y0PFPboMvKx0FXl/A0dM+HFrruCgBlWt6FA+okRySQiliuI5phwqkXefl9AhkwR
8xocQSVCFxcwvwCglVcOQliHu8jwRQHxlRE0tkwQQI0D+wfQwKdvhDplxHJ5nf7U
8c/yE/vdvpN6lF0tmFrKXBUX+K7u4ifrZlQvj/81M4INjtXreqDiJtr99Rs6xa0S
cZqITuZC4CWxJa9GynBED3+D2t1V/f8l0smsuYoFOF7Ib49IkTdbtwAThlZp8bEh
ELBeGaPdNCcmfZ66rKUdG5sRA/9ovnc1krSQF2+sqB9/o7w5/q2qiyzwOSTnkjtB
UVKn4zLUOf6aeBAoV6NMCC3Kj9aZHfA+ND0ehPaVGJgjaVNFhPi4x0e7BULdvgOo
AqajLfvkURHAeSsxXIoEmyW/xC1sBbDkDUIBSx5oej73XCZgnj/inphRqGpsb+1n
KFvF+rQoU3VTRSBQYWNrYWdlIFNpZ25pbmcgS2V5IDxidWlsZEBzdXNlLmRlPohi
BBMRAgAiBQJA2AY+AhsDBQkObd+9BAsHAwIDFQIDAxYCAQIeAQIXgAAKCRCoTtro
nIAKypCfAJ9RuZ6ZSV7QW4pTgTIxQ+ABPp0sIwCffG9bCNnrETPlgOn+dGEkAWeg
KL+IRgQQEQIABgUCOnBeUgAKCRCeQOMQAAqrpNzOAKCL512FZvv4VZx94TpbA9lx
yoAejACeOO1HIbActAevk5MUBhNeLZa/qM2JARUDBRA6cGBvd7LmAD0l09kBATWn
B/9An5vfiUUE1VQnt+T/EYklES3tXXaJJp9pHMa4fzFa8jPVtv5UBHGee3XoUNDV
wM2OgSEISZxbzdXGnqIlcT08TzBUD9i579uifklLsnr35SJDZ6ram51/CWOnnaVh
UzneOA9gTPSr+/fT3WeVnwJiQCQ30kNLWVXWATMnsnT486eAOlT6UNBPYQLpUprF
5Yryk23pQUPAgJENDEqeU6iIO9Ot1ZPtB0lniw+/xCi13D360o1tZDYOp0hHHJN3
D3EN8C1yPqZd5CvvznYvB6bWBIpWcRgdn2DUVMmpU661jwqGlRz1F84JG/xe4jGu
zgpJt9IXSzyohEJB6XG5+D0BuQINBDnu9JIQCACEkdBN6Mxf5WvqDWkcMRy6wnrd
9DYJ8UUTmIT2iQf07tRUKJJ9v0JXfx2Z4d08IQSMNRaq4VgSe+PdYgIy0fbj23Vi
a5/gO7fJEpD2hd2f+pMnOWvH2rOOIbeYfuhzAc6BQjAKtmgR0ERUTafTM9Wb6F13
CNZZNZfDqnFDP6L12w3z3F7FFXkz07Rs3AIto1ZfYZd4sCSpMr/0S5nLrHbIvGLp
271hhQBeRmmoGEKO2JRelGgUJ2CUzOdtwDIKT0LbCpvaP8PVnYF5IFoYJIWRHqlE
t5ucTXstZy7vYjL6vTP4l5xs+LIOkNmPhqmfsgLzVo0UaLt80hOwc4NvDCOLAAMG
B/9g+9V3ORzw4LvO1pwRYJqfDKUq/EJ0rNMMD4N8RLpZRhKHKJUm9nNHLbksnlZw
rbSTM5LpC/U6sheLP+l0bLVoq0lmsCcUSyh+mY6PxWirLIWCn/IAZAGnXb6Zd6Tt
IJlGG6pqUN8QxGJYQnonl0uTJKHJENbI9sWHQdcTtBMc34gorHFCo1Bcvpnc1LFL
rWn7mfoGx6INQjf3HGQpMXAWuSBQhzkazY6vaWFpa8bBJ+gKbBuySWzNm3rFtT5H
RKMWpO+M9bHp4d+puY0L1YwN1OMatcMMpcWnZpiWiR83oi32+xtWUY2U7Ae38mMa
g8zFbpeqPQUsDv9V7CAJ1dbriEwEGBECAAwFAkDYBnoFCQ5t3+gACgkQqE7a6JyA
CspnpgCfRbYwxT3iq+9l/PgNTUNTZOlof2oAn25y0eGi0371jap9kOV6uq71sUuO
=ypVs
- -----END PGP PUBLIC KEY BLOCK-----

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (GNU/Linux)

iQEVAwUBRrHqkXey5gA9JdPZAQKQLggAhOQvnIDvEkm/hwhmCKa+rX/M+Fv032AK
UHDz2RjBURbMOGOzVr3Sdyw901Ux+CTgsdyh5DEDi4G2CITh7D+nactPq44LOT8J
Qhb09XbBT/WsDsRG6shB29v+5V+av8sE1o0eulRu15UBKzdg9Fzi+2Vjjoc5E0oh
VPoqsx3tGOi3Gio1FS4wd5dqY2vgyrzeUnaDe7cT8n33U99CHy7r3h4giyCd+xm8
uupfk2GHYfTq1XJ1MGif5zviS947fK3fJJIsVkfsQ6Elo6+vyUH0/djBJnEHIr3S
68Y8rYWkHTgFxyzOdpZyp9TGMcrQfmgxRyJA2/t0sDMSIBak9+eGww==
=HSGw
-----END PGP SIGNATURE-----
-- 
To unsubscribe, e-mail: opensuse-security-announce+unsubscribe@xxxxxxxxxxxx
For additional commands, e-mail: opensuse-security-announce+help@xxxxxxxxxxxx

< Previous Next >
This Thread
  • No further messages