-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2010-14362 2010-09-09 00:33:36 --------------------------------------------------------------------------------
Name : galeon Product : Fedora 12 Version : 2.0.7 Release : 25.fc12 URL : http://galeon.sourceforge.net/ Summary : GNOME2 Web browser based on Mozilla Description : Galeon is a web browser built around Gecko (Mozilla's rendering engine) and Necko (Mozilla's networking engine). It's a GNOME web browser, designed to take advantage of as many GNOME technologies as makes sense. Galeon was written to do just one thing - browse the web. -------------------------------------------------------------------------------- Update Information: Update to new upstream Firefox version 3.5.12, fixing multiple security issues detailed in the upstream advisories: http://www.mozilla.org/security/known- vulnerabilities/firefox35.html#firefox3.5.12 Update also includes packages depending on gecko-libs rebuilt against new version of Firefox / XULRunner. -------------------------------------------------------------------------------- ChangeLog: * Wed Sep 8 2010 Jan Horak <[email protected]> - 2.0.7-25 - Rebuild against newer gecko * Tue Jul 20 2010 Jan Horak <[email protected]> - 2.0.7-24 - Rebuild against newer gecko * Wed Jun 23 2010 Jan Horak <[email protected]> - 2.0.7-23 - Rebuild against newer gecko * Tue Mar 30 2010 Jan Horak <[email protected]> - 2.0.7-22 - Rebuild against newer gecko * Mon Mar 29 2010 Yanko Kaneti <[email protected]> - 2.0.7-21 - Avoid crashing (#577604), gnome bug 418439 - http://start.fedoraproject.org/ as default homepage * Thu Feb 18 2010 Jan Horak <[email protected]> - 2.0.7-20 - Rebuild against newer gecko * Wed Dec 16 2009 Jan Horak <[email protected]> - 2.0.7-19 - Rebuild against newer gecko * Thu Nov 5 2009 Jan Horak <[email protected]> - 2.0.7-18 - Rebuild against newer gecko -------------------------------------------------------------------------------- References: [ 1 ] Bug #630055 - CVE-2010-3169 Mozilla Miscellaneous memory safety hazards https://bugzilla.redhat.com/show_bug.cgi?id=630055 [ 2 ] Bug #630056 - CVE-2010-2765 Mozilla Frameset integer overflow vulnerability (MFSA 2010-50) https://bugzilla.redhat.com/show_bug.cgi?id=630056 [ 3 ] Bug #630059 - CVE-2010-2767 Mozilla Dangling pointer vulnerability using DOM plugin array (MFSA 2010-51) https://bugzilla.redhat.com/show_bug.cgi?id=630059 [ 4 ] Bug #630061 - CVE-2010-3166 Mozilla Heap buffer overflow in nsTextFrameUtils::TransformText (MFSA 2010-53) https://bugzilla.redhat.com/show_bug.cgi?id=630061 [ 5 ] Bug #630062 - CVE-2010-2760 Mozilla Dangling pointer vulnerability in nsTreeSelection (MFSA 2010-54) https://bugzilla.redhat.com/show_bug.cgi?id=630062 [ 6 ] Bug #630064 - CVE-2010-3168 Mozilla XUL tree removal crash and remote code execution (MFSA 2010-55) https://bugzilla.redhat.com/show_bug.cgi?id=630064 [ 7 ] Bug #630067 - CVE-2010-3167 Mozilla Dangling pointer vulnerability in nsTreeContentView (MFSA 2010-56) https://bugzilla.redhat.com/show_bug.cgi?id=630067 [ 8 ] Bug #630069 - CVE-2010-2766 Mozilla Crash and remote code execution in normalizeDocument (MFSA 2010-57) https://bugzilla.redhat.com/show_bug.cgi?id=630069 [ 9 ] Bug #631725 - CVE-2010-2763 Mozilla XSS using SJOW scripted function (MFSA 2010-60) https://bugzilla.redhat.com/show_bug.cgi?id=631725 [ 10 ] Bug #630074 - CVE-2010-2768 Mozilla UTF-7 XSS by overriding document charset using <object> type attribute (MFSA 2010-61) https://bugzilla.redhat.com/show_bug.cgi?id=630074 [ 11 ] Bug #630075 - CVE-2010-2769 Mozilla Copy-and-paste or drag-and-drop into designMode document allows XSS (MFSA 2010-62) https://bugzilla.redhat.com/show_bug.cgi?id=630075 [ 12 ] Bug #630078 - CVE-2010-2764 Mozilla Information leak via XMLHttpRequest statusText (MFSA 2010-63) https://bugzilla.redhat.com/show_bug.cgi?id=630078 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update galeon' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list [email protected] https://admin.fedoraproject.org/mailman/listinfo/package-announce
