<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="39ddcb62480cca4cc1867664cac5707c"!-->
<patch
    xmlns="http://novell.com/package/metadata/suse/patch"
    xmlns:yum="http://linux.duke.edu/metadata/common"
    xmlns:rpm="http://linux.duke.edu/metadata/rpm"
    xmlns:suse="http://novell.com/package/metadata/suse/common"
    patchid="sledp2-MozillaFirefox-5644"
    timestamp="1222702770"
    engine="1.0">
  <yum:name>sledp2-MozillaFirefox</yum:name>
  <summary lang="en">Security update for MozillaFirefox</summary>
  <summary lang="de">Security update for MozillaFirefox</summary>
  <description lang="en">This update brings MozillaFirefox to version 2.0.0.17 to
fix bugs and security issues:

MFSA 2008-45 / CVE-2008-4069: XBM image uninitialized
memory reading

MFSA 2008-44 / CVE-2008-4067 / CVE-2008-4068: resource:
traversal vulnerabilities

MFSA 2008-43: BOM characters stripped from JavaScript
before execution CVE-2008-4065: Stripped BOM characters bug
CVE-2008-4066: HTML escaped low surrogates bug

MFSA 2008-42 Crashes with evidence of memory corruption
(rv:1.9.0.2/1.8.1.17): CVE-2008-4061: Jesse Ruderman
reported a crash in the layout engine. CVE-2008-4062: Igor
Bukanov, Philip Taylor, Georgi Guninski, and Antoine Labour
reported crashes in the JavaScript engine. CVE-2008-4063:
Jesse Ruderman, Bob Clary, and Martijn Wargers reported
crashes in the layout engine which only affected Firefox 3.
CVE-2008-4064: David Maciejak and Drew Yao reported crashes
in graphics rendering which only affected Firefox 3.

MFSA 2008-41 Privilege escalation via XPCnativeWrapper
pollution CVE-2008-4058: XPCnativeWrapper pollution bugs
CVE-2008-4059: XPCnativeWrapper pollution (Firefox 2)
CVE-2008-4060: Documents without script handling objects

MFSA 2008-40 / CVE-2008-3837: Forced mouse drag

MFSA 2008-39 / CVE-2008-3836: Privilege escalation using
feed preview page and XSS flaw

MFSA 2008-38 / CVE-2008-3835:
nsXMLDocument::OnChannelRedirect() same-origin violation

MFSA 2008-37 / CVE-2008-0016: UTF-8 URL stack buffer
overflow

For more details:
http://www.mozilla.org/security/known-vulnerabilities/firefo
x20.html
</description>
  <description lang="de">This update brings MozillaFirefox to version 2.0.0.17 to
fix bugs and security issues:

MFSA 2008-45 / CVE-2008-4069: XBM image uninitialized
memory reading

MFSA 2008-44 / CVE-2008-4067 / CVE-2008-4068: resource:
traversal vulnerabilities

MFSA 2008-43: BOM characters stripped from JavaScript
before execution CVE-2008-4065: Stripped BOM characters bug
CVE-2008-4066: HTML escaped low surrogates bug

MFSA 2008-42 Crashes with evidence of memory corruption
(rv:1.9.0.2/1.8.1.17): CVE-2008-4061: Jesse Ruderman
reported a crash in the layout engine. CVE-2008-4062: Igor
Bukanov, Philip Taylor, Georgi Guninski, and Antoine Labour
reported crashes in the JavaScript engine. CVE-2008-4063:
Jesse Ruderman, Bob Clary, and Martijn Wargers reported
crashes in the layout engine which only affected Firefox 3.
CVE-2008-4064: David Maciejak and Drew Yao reported crashes
in graphics rendering which only affected Firefox 3.

MFSA 2008-41 Privilege escalation via XPCnativeWrapper
pollution CVE-2008-4058: XPCnativeWrapper pollution bugs
CVE-2008-4059: XPCnativeWrapper pollution (Firefox 2)
CVE-2008-4060: Documents without script handling objects

MFSA 2008-40 / CVE-2008-3837: Forced mouse drag

MFSA 2008-39 / CVE-2008-3836: Privilege escalation using
feed preview page and XSS flaw

MFSA 2008-38 / CVE-2008-3835:
nsXMLDocument::OnChannelRedirect() same-origin violation

MFSA 2008-37 / CVE-2008-0016: UTF-8 URL stack buffer
overflow

For more details:
http://www.mozilla.org/security/known-vulnerabilities/firefo
x20.html
</description>
  <yum:version ver="5644" rel="0"/>
  <rpm:requires>
    <rpm:entry kind="atom" name="MozillaFirefox" epoch="0" ver="2.0.0.17" rel="0.3" flags="EQ"/>
    <rpm:entry kind="atom" name="MozillaFirefox-translations" epoch="0" ver="2.0.0.17" rel="0.3" flags="EQ"/>
  </rpm:requires>
  <category>security</category>
  <atoms>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>MozillaFirefox</name>
      <arch>i586</arch>
      <version epoch="0" ver="2.0.0.17" rel="0.3"/>
      <checksum type="sha" pkgid="YES">f3dca860a1fdd53659b3b977f31404c04e4abf1b</checksum>
      <time file="1222703312" build="1222702770"/>
      <size package="9331780" installed="24098719" archive="24082332"/>
      <location xml:base="media://#1" href="suse/i586/MozillaFirefox-3.0.13-0.4.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="MozillaFirefox" epoch="0" ver="2.0.0.17" rel="0.3" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="MozillaFirefox"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>MozillaFirefox-translations</name>
      <arch>i586</arch>
      <version epoch="0" ver="2.0.0.17" rel="0.3"/>
      <checksum type="sha" pkgid="YES">f72828252167c7ee10cc1d42b3b79f713d0aea8a</checksum>
      <time file="1222703317" build="1222702770"/>
      <size package="3748826" installed="20478568" archive="20488172"/>
      <location xml:base="media://#1" href="suse/i586/MozillaFirefox-translations-3.0.13-0.4.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="MozillaFirefox-translations" epoch="0" ver="2.0.0.17" rel="0.3" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="MozillaFirefox-translations"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
  </atoms>
</patch>
