[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[BSA-034] Security Update for iceweasel

Mike Hommey uploaded new packages for iceweasel which fixed the
following security problems:

CVE-2011-0069 CVE-2011-0070 CVE-2011-0072 CVE-2011-0074 CVE-2011-0075 CVE-2011-0077 CVE-2011-0078 CVE-2011-0080 CVE-2011-0081

   "Scoobidiver", Ian Beer Bob Clary, Henri Sivonen, Marco Bonardo,
   Mats Palmgren, Jesse Ruderman, Aki Kelin and Martin Barbella 
   discovered memory corruption bugs, which may lead to the execution
   of arbitrary code.

CVE-2011-0065 CVE-2011-0066 CVE-2011-0073

   "regenrecht" discovered several dangling pointer vulnerabilities,
   which may lead to the execution of arbitrary code.


   Paul Stone discovered that Java applets could steal information
   from the autocompletion history.


   Soroush Dalili discovered a directory traversal vulnerability in
   handling resource URIs.

For the lenny-backports distribution the problems have been fixed in
version 3.5.16-7~bpo50+1.

For the oldstable distribution (lenny), this problem will be fixed soon
with updated packages of the xulrunner source package.
For the stable distribution (squeeze), this problem has been fixed in
version 3.5.16-7.

For the unstable distribution (sid), this problem has been fixed in
version 3.5.19-1.

Upgrade instructions

If you don't use pinning (see [1]) you have to update the package
manually via "apt-get -t lenny-backports install <packagelist>" with
the packagelist of your installed packages affected by this update.
[1] <http://backports.debian.org/Instructions>

We recommend to pin (in /etc/apt/preferences) the backports repository
to 200 so that new versions of installed  backports will be installed

  Package: *
  Pin: release a=lenny-backports
  Pin-Priority: 200

Attachment: signature.asc
Description: Digital signature

Reply to: