~ubuntu-branches/ubuntu/intrepid/xulrunner/intrepid-security

  • Committer: Bazaar Package Importer
  • Author(s): Alexander Sack
  • Date: 2009-03-31 19:26:56 UTC
  • mfrom: (1.2.1 upstream)
  • Revision ID: james.westby@ubuntu.com-20090331192656-4b18f1r30ri0poud
Tags: 1.8.1.18+nobinonly.b308.cvs20090331t155113-0ubuntu0.8.10.1
* New security upstream release - backports for ffox 3.0.8
  + Fixed on Firefox EOL branch
    - MFSA 2009-13 Arbitrary code execution through XUL <tree> element
    - MFSA 2009-12 XSL Transformation vulnerability
    - MFSA 2009-10 Upgrade PNG library to fix memory safety hazards
    - MFSA 2009-09 XML data theft via RDFXMLDataSource and cross-domain redirect
    - MFSA 2009-07 Crashes with evidence of memory corruption (rv:1.9.0.7)
    - MFSA 2009-05 XMLHttpRequest allows reading HTTPOnly cookies
    - MFSA 2009-03 Local file stealing with SessionStore
    - MFSA 2009-01 Crashes with evidence of memory corruption (rv:1.9.0.6)
  + Fixed in Firefox 2.0.0.20
    - MFSA 2008-65 Cross-domain data theft via script redirect error message (Windows)
  + Fixed in Firefox 2.0.0.19
    - MFSA 2008-69 XSS vulnerabilities in SessionStore
    - MFSA 2008-68 XSS and JavaScript privilege escalation
    - MFSA 2008-67 Escaped null characters ignored by CSS parser
    - MFSA 2008-66 Errors parsing URLs with leading whitespace and control characters
    - MFSA 2008-65 Cross-domain data theft via script redirect error message
    - MFSA 2008-64 XMLHttpRequest 302 response disclosure
    - MFSA 2008-62 Additional XSS attack vectors in feed preview
    - MFSA 2008-61 Information stealing via loadBindingDocument
    - MFSA 2008-60 Crashes with evidence of memory corruption (rv:1.9.0.5/1.8.1.19)
  + Fixed in Firefox 2.0.0.18
    - MFSA 2008-58 Parsing error in E4X default namespace
    - MFSA 2008-57 -moz-binding property bypasses security checks on codebase principals
    - MFSA 2008-56 nsXMLHttpRequest::NotifyEventListeners() same-origin violation
    - MFSA 2008-55 Crash and remote code execution in nsFrameManager
    - MFSA 2008-54 Buffer overflow in http-index-format parser
    - MFSA 2008-53 XSS and JavaScript privilege escalation via session restore
    - MFSA 2008-52 Crashes with evidence of memory corruption (rv:1.9.0.4/1.8.1.18)
    - MFSA 2008-50 Crash and remote code execution via __proto__ tampering
    - MFSA 2008-49 Arbitrary code execution via Flash Player dynamic module unloading
    - MFSA 2008-48 Image stealing via canvas and HTTP redirect
    - MFSA 2008-47 Information stealing via local shortcut files
  + Fixed in Firefox 2.0.0.17
    - MFSA 2008-45 XBM image uninitialized memory reading
    - MFSA 2008-44 resource: traversal vulnerabilities
    - MFSA 2008-43 BOM characters stripped from JavaScript before execution
    - MFSA 2008-42 Crashes with evidence of memory corruption (rv:1.9.0.2/1.8.1.17)
    - MFSA 2008-41 Privilege escalation via XPCnativeWrapper pollution
    - MFSA 2008-40 Forced mouse drag
    - MFSA 2008-39 Privilege escalation using feed preview page and XSS flaw
    - MFSA 2008-38 nsXMLDocument::OnChannelRedirect() same-origin violation
    - MFSA 2008-37 UTF-8 URL stack buffer overflow
Filename Latest Rev Last Changed Committer Comment Size
..
accessible 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 Diff
browser 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 Diff
build 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 Diff
calendar 1.1.7 17 years ago Bazaar Package Importer Import upstream version 1.8.1.4 Diff
caps 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 Diff
chrome 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 Diff
config 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 Diff
content 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 Diff
db 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 Diff
dbm 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 Diff
debian 2 18 years ago Bazaar Package Importer * The "finally a new upstream" release. * Fixes th Diff
directory 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 Diff
docshell 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 Diff
dom 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 Diff
editor 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 Diff
embedding 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 Diff
extensions 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 Diff
gc 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 Diff
gfx 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 Diff
intl 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 Diff
ipc 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 Diff
jpeg 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 Diff
js 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 Diff
l10n 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 Diff
layout 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 Diff
lib 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 Diff
mail 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 Diff
mailnews 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 Diff
modules 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 Diff
netwerk 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 Diff
nsprpub 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 Diff
parser 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 Diff
plugin 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 Diff
profile 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 Diff
rdf 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 Diff
README 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 Diff
security 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 Diff
storage 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 Diff
sun-java 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 Diff
themes 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 Diff
toolkit 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 Diff
tools 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 Diff
uriloader 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 Diff
view 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 Diff
webshell 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 Diff
widget 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 Diff
xpcom 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 Diff
xpfe 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 Diff
xpinstall 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 Diff
xulrunner 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 Diff
.mozconfig.mk 27 15 years ago Bazaar Package Importer * New security upstream release - backports for ff 326 bytes Diff Download File
.mozconfig.out 27 15 years ago Bazaar Package Importer * New security upstream release - backports for ff Empty Diff Download File
aclocal.m4 1.1.7 17 years ago Bazaar Package Importer Import upstream version 1.8.1.4 687 bytes Diff Download File
File allmakefiles.sh 27 15 years ago Bazaar Package Importer * New security upstream release - backports for ff 465 KB Diff Download File
client.mak 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 1.7 KB Diff Download File
client.mk 27 15 years ago Bazaar Package Importer * New security upstream release - backports for ff 33 KB Diff Download File
File configure 27 15 years ago Bazaar Package Importer * New security upstream release - backports for ff 610 KB Diff Download File
configure.in 27 15 years ago Bazaar Package Importer * New security upstream release - backports for ff 244 KB Diff Download File
LEGAL 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 2.5 KB Diff Download File
LICENSE 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 30.1 KB Diff Download File
Makefile.in 1.1.7 17 years ago Bazaar Package Importer Import upstream version 1.8.1.4 11.9 KB Diff Download File
makefile.win 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 1.7 KB Diff Download File
nglayout.mk 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 95 bytes Diff Download File
README.txt 1 18 years ago Bazaar Package Importer Import upstream version 1.8.0.4 9.3 KB Diff Download File