<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="25e7dd0fd151df757435e02aa7061252"!-->
<patch
    xmlns="http://novell.com/package/metadata/suse/patch"
    xmlns:yum="http://linux.duke.edu/metadata/common"
    xmlns:rpm="http://linux.duke.edu/metadata/rpm"
    xmlns:suse="http://novell.com/package/metadata/suse/common"
    patchid="sdkp2-MozillaFirefox-6433"
    timestamp="1250243441"
    engine="1.0">
  <yum:name>sdkp2-MozillaFirefox</yum:name>
  <summary lang="en">Security update for Mozilla Firefox</summary>
  <summary lang="de">Security update for Mozilla Firefox</summary>
  <description lang="en">MozillaFirefox was updated to the 3.0.13 release, fixing
some security issues and bugs:

MFSA 2009-44 / CVE-2009-2654: Security researcher Juan
Pablo Lopez Yacubian reported that an attacker could call
window.open() on an invalid URL which looks similar to a
legitimate URL and then use document.write() to place
content within the new document, appearing to have come
from the spoofed location. Additionally, if the spoofed
document was created by a document with a valid SSL
certificate, the SSL indicators would be carried over into
the spoofed document. An attacker could use these issues to
display misleading location and SSL information for a
malicious web page.

MFSA 2009-45 / CVE-2009-2662:The browser engine in Mozilla
Firefox before 3.0.13, and 3.5.x before 3.5.2, allows
remote attackers to cause a denial of service (memory
corruption and application crash) or possibly execute
arbitrary code via vectors related to the
TraceRecorder::snapshot function in js/src/jstracer.cpp,
and unspecified other vectors.

CVE-2009-2663 / MFSA 2009-45: libvorbis before r16182, as
used in Mozilla Firefox before 3.0.13 and 3.5.x before
3.5.2 and other products, allows context-dependent
attackers to cause a denial of service (memory corruption
and application crash) or possibly execute arbitrary code
via a crafted .ogg file.

CVE-2009-2664 / MFSA 2009-45: The js_watch_set function in
js/src/jsdbgapi.cpp in the JavaScript engine in Mozilla
Firefox before 3.0.13, and 3.5.x before 3.5.2, allows
remote attackers to cause a denial of service (assertion
failure and application exit) or possibly execute arbitrary
code via a crafted .js file, related to a &quot;memory safety
bug.&quot;
</description>
  <description lang="de">MozillaFirefox was updated to the 3.0.13 release, fixing
some security issues and bugs:

MFSA 2009-44 / CVE-2009-2654: Security researcher Juan
Pablo Lopez Yacubian reported that an attacker could call
window.open() on an invalid URL which looks similar to a
legitimate URL and then use document.write() to place
content within the new document, appearing to have come
from the spoofed location. Additionally, if the spoofed
document was created by a document with a valid SSL
certificate, the SSL indicators would be carried over into
the spoofed document. An attacker could use these issues to
display misleading location and SSL information for a
malicious web page.

MFSA 2009-45 / CVE-2009-2662:The browser engine in Mozilla
Firefox before 3.0.13, and 3.5.x before 3.5.2, allows
remote attackers to cause a denial of service (memory
corruption and application crash) or possibly execute
arbitrary code via vectors related to the
TraceRecorder::snapshot function in js/src/jstracer.cpp,
and unspecified other vectors.

CVE-2009-2663 / MFSA 2009-45: libvorbis before r16182, as
used in Mozilla Firefox before 3.0.13 and 3.5.x before
3.5.2 and other products, allows context-dependent
attackers to cause a denial of service (memory corruption
and application crash) or possibly execute arbitrary code
via a crafted .ogg file.

CVE-2009-2664 / MFSA 2009-45: The js_watch_set function in
js/src/jsdbgapi.cpp in the JavaScript engine in Mozilla
Firefox before 3.0.13, and 3.5.x before 3.5.2, allows
remote attackers to cause a denial of service (assertion
failure and application exit) or possibly execute arbitrary
code via a crafted .js file, related to a &quot;memory safety
bug.&quot;
</description>
  <yum:version ver="6433" rel="0"/>
  <rpm:requires>
    <rpm:entry kind="atom" name="MozillaFirefox-branding-upstream" epoch="0" ver="3.0.13" rel="0.4" flags="EQ"/>
    <rpm:entry kind="atom" name="firefox3-atk-devel" epoch="0" ver="1.12.3" rel="0.4.3" flags="EQ"/>
    <rpm:entry kind="atom" name="firefox3-atk-doc" epoch="0" ver="1.12.3" rel="0.4.3" flags="EQ"/>
    <rpm:entry kind="atom" name="firefox3-cairo-devel" epoch="0" ver="1.2.4" rel="0.4.3" flags="EQ"/>
    <rpm:entry kind="atom" name="firefox3-cairo-doc" epoch="0" ver="1.2.4" rel="0.4.3" flags="EQ"/>
    <rpm:entry kind="atom" name="firefox3-glib2-devel" epoch="0" ver="2.12.4" rel="0.4.3" flags="EQ"/>
    <rpm:entry kind="atom" name="firefox3-glib2-doc" epoch="0" ver="2.12.4" rel="0.4.3" flags="EQ"/>
    <rpm:entry kind="atom" name="firefox3-gtk2-devel" epoch="0" ver="2.10.6" rel="0.4.3" flags="EQ"/>
    <rpm:entry kind="atom" name="firefox3-gtk2-doc" epoch="0" ver="2.10.6" rel="0.4.3" flags="EQ"/>
    <rpm:entry kind="atom" name="firefox3-pango-devel" epoch="0" ver="1.14.5" rel="0.4.3" flags="EQ"/>
    <rpm:entry kind="atom" name="firefox3-pango-doc" epoch="0" ver="1.14.5" rel="0.4.3" flags="EQ"/>
    <rpm:entry kind="atom" name="mozilla-xulrunner190-devel" epoch="0" ver="1.9.0.13" rel="1.4" flags="EQ"/>
    <rpm:entry kind="atom" name="python-xpcom190" epoch="0" ver="1.9.0.13" rel="1.4" flags="EQ"/>
  </rpm:requires>
  <category>security</category>
  <atoms>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>MozillaFirefox-branding-upstream</name>
      <arch>i586</arch>
      <version epoch="0" ver="3.0.13" rel="0.4"/>
      <checksum type="sha" pkgid="YES">926c78b70abdc96d0d63277ad16b19f63d324f83</checksum>
      <time file="1250256103" build="1250243441"/>
      <size package="50635" installed="7371" archive="7812"/>
      <location xml:base="media://#1" href="suse/i586/MozillaFirefox-branding-upstream-3.0.13-0.4.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="MozillaFirefox-branding-upstream" epoch="0" ver="3.0.13" rel="0.4" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="MozillaFirefox-branding-upstream"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>firefox3-atk-devel</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="1.12.3" rel="0.4.3"/>
      <checksum type="sha" pkgid="YES">46513b47ef321e7d0af37c4ad82c2e53776d64b5</checksum>
      <time file="1250256020" build="1249656118"/>
      <size package="27740" installed="153888" archive="159356"/>
      <location xml:base="media://#1" href="suse/x86_64/firefox3-atk-devel-1.12.3-0.4.3.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="firefox3-atk-devel" epoch="0" ver="1.12.3" rel="0.4.3" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="firefox3-atk-devel"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>firefox3-atk-doc</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="1.12.3" rel="0.4.3"/>
      <checksum type="sha" pkgid="YES">c3d11d8c59fb044befcf01f08ad6f2886444bbfd</checksum>
      <time file="1250256020" build="1249656118"/>
      <size package="60363" installed="755254" archive="762828"/>
      <location xml:base="media://#1" href="suse/x86_64/firefox3-atk-doc-1.12.3-0.4.3.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="firefox3-atk-doc" epoch="0" ver="1.12.3" rel="0.4.3" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="firefox3-atk-doc"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>firefox3-cairo-devel</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="1.2.4" rel="0.4.3"/>
      <checksum type="sha" pkgid="YES">c0ff9ddb0564b3b61483a11b9a831dab5464b3b1</checksum>
      <time file="1250256019" build="1249656055"/>
      <size package="227666" installed="882919" archive="886524"/>
      <location xml:base="media://#1" href="suse/x86_64/firefox3-cairo-devel-1.2.4-0.4.3.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="firefox3-cairo-devel" epoch="0" ver="1.2.4" rel="0.4.3" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="firefox3-cairo-devel"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>firefox3-cairo-doc</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="1.2.4" rel="0.4.3"/>
      <checksum type="sha" pkgid="YES">f2f9b404ebebdab688bfc86acc6297e9f211d7a5</checksum>
      <time file="1250256019" build="1249656055"/>
      <size package="70271" installed="770048" archive="779468"/>
      <location xml:base="media://#1" href="suse/x86_64/firefox3-cairo-doc-1.2.4-0.4.3.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="firefox3-cairo-doc" epoch="0" ver="1.2.4" rel="0.4.3" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="firefox3-cairo-doc"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>firefox3-glib2-devel</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="2.12.4" rel="0.4.3"/>
      <checksum type="sha" pkgid="YES">df73a00a3dd24bcfe38daffc515d68079f8b8dbf</checksum>
      <time file="1250256017" build="1249655399"/>
      <size package="509377" installed="2184692" archive="2204292"/>
      <location xml:base="media://#1" href="suse/x86_64/firefox3-glib2-devel-2.12.4-0.4.3.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="firefox3-glib2-devel" epoch="0" ver="2.12.4" rel="0.4.3" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="firefox3-glib2-devel"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>firefox3-glib2-doc</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="2.12.4" rel="0.4.3"/>
      <checksum type="sha" pkgid="YES">8da2275eecdfc9554c99df65720a024c28cc7379</checksum>
      <time file="1250256017" build="1249655399"/>
      <size package="496487" installed="5521969" archive="5551724"/>
      <location xml:base="media://#1" href="suse/x86_64/firefox3-glib2-doc-2.12.4-0.4.3.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="firefox3-glib2-doc" epoch="0" ver="2.12.4" rel="0.4.3" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="firefox3-glib2-doc"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>firefox3-gtk2-devel</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="2.10.6" rel="0.4.3"/>
      <checksum type="sha" pkgid="YES">bd8785f7d5cd6d231c4510b88f59500242846a64</checksum>
      <time file="1250256023" build="1249659218"/>
      <size package="412941" installed="2003214" archive="2057088"/>
      <location xml:base="media://#1" href="suse/x86_64/firefox3-gtk2-devel-2.10.6-0.4.3.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="firefox3-gtk2-devel" epoch="0" ver="2.10.6" rel="0.4.3" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="firefox3-gtk2-devel"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>firefox3-gtk2-doc</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="2.10.6" rel="0.4.3"/>
      <checksum type="sha" pkgid="YES">fdcfad5836df7d5f3de58eca3a5af0d2495e5288</checksum>
      <time file="1250256024" build="1249659218"/>
      <size package="1686829" installed="14754043" archive="14857944"/>
      <location xml:base="media://#1" href="suse/x86_64/firefox3-gtk2-doc-2.10.6-0.4.3.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="firefox3-gtk2-doc" epoch="0" ver="2.10.6" rel="0.4.3" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="firefox3-gtk2-doc"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>firefox3-pango-devel</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="1.14.5" rel="0.4.3"/>
      <checksum type="sha" pkgid="YES">b2ca77798ca2d3c1f78f435a24c382c2d7ed43d1</checksum>
      <time file="1250256020" build="1249656615"/>
      <size package="31974" installed="157789" archive="165704"/>
      <location xml:base="media://#1" href="suse/x86_64/firefox3-pango-devel-1.14.5-0.4.3.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="firefox3-pango-devel" epoch="0" ver="1.14.5" rel="0.4.3" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="firefox3-pango-devel"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>firefox3-pango-doc</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="1.14.5" rel="0.4.3"/>
      <checksum type="sha" pkgid="YES">47e804965bf7344727d2e14a42d2f1d1c0cefccd</checksum>
      <time file="1250256020" build="1249656615"/>
      <size package="154081" installed="1521458" archive="1530996"/>
      <location xml:base="media://#1" href="suse/x86_64/firefox3-pango-doc-1.14.5-0.4.3.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="firefox3-pango-doc" epoch="0" ver="1.14.5" rel="0.4.3" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="firefox3-pango-doc"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>mozilla-xulrunner190-devel</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="1.9.0.13" rel="1.4"/>
      <checksum type="sha" pkgid="YES">ae786b19043096c1bf6375e0cdac64488e0903e4</checksum>
      <time file="1250256054" build="1250242082"/>
      <size package="4017186" installed="30012490" archive="30678452"/>
      <location xml:base="media://#1" href="suse/x86_64/mozilla-xulrunner190-devel-1.9.0.13-1.4.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="mozilla-xulrunner190-devel" epoch="0" ver="1.9.0.13" rel="1.4" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="mozilla-xulrunner190-devel"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>python-xpcom190</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="1.9.0.13" rel="1.4"/>
      <checksum type="sha" pkgid="YES">6f03d5ae34cc4cf125885eb59dbd3efefaf54c3f</checksum>
      <time file="1250256054" build="1250242082"/>
      <size package="135453" installed="407196" archive="412320"/>
      <location xml:base="media://#1" href="suse/x86_64/python-xpcom190-1.9.0.13-1.4.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="python-xpcom190" epoch="0" ver="1.9.0.13" rel="1.4" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="python-xpcom190"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
  </atoms>
</patch>
