<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="eb29e246d47ad02c74de06d48db89df2"!-->
<patch
    xmlns="http://novell.com/package/metadata/suse/patch"
    xmlns:yum="http://linux.duke.edu/metadata/common"
    xmlns:rpm="http://linux.duke.edu/metadata/rpm"
    xmlns:suse="http://novell.com/package/metadata/suse/common"
    patchid="MozillaFirefox-2258"
    timestamp="1163385956"
    engine="1.0">
  <yum:name>MozillaFirefox</yum:name>
  <summary lang="en">Security update for Mozilla Firefox</summary>
  <summary lang="de">Security update for Mozilla Firefox</summary>
  <description lang="en">This update brings MozillaFirefox to the security update
release 1.5.0.8,  including the following security fixes.

Full details can be found on:
http://www.mozilla.org/projects/security/known-vulnerabiliti
es.html

MFSA2006-65: Is split into 3 sub-entries, for ongoing
stability improvements in the Mozilla browsers:
CVE-2006-5464: Layout engine flaws were fixed.
CVE-2006-5747: A xml.prototype.hasOwnProperty flaw was
fixed. CVE-2006-5748: Fixes were applied to the Javascript
engine.

MFSA2006-66/CVE-2006-5462: MFSA 2006-60 reported that RSA
digital signatures with a low exponent (typically 3) could
be forged. Firefox and Thunderbird 1.5.0.7, which
incorporated NSS version 3.10.2, were incompletely patched
and remained vulnerable to a variant of this attack.

MFSA2006-67/CVE-2006-5463: shutdown demonstrated that it
was possible to modify a Script object while it was
executing, potentially leading to the execution of
arbitrary JavaScript bytecode.
</description>
  <description lang="de">This update brings MozillaFirefox to the security update
release 1.5.0.8,  including the following security fixes.

Full details can be found on:
http://www.mozilla.org/projects/security/known-vulnerabiliti
es.html

MFSA2006-65: Is split into 3 sub-entries, for ongoing
stability improvements in the Mozilla browsers:
CVE-2006-5464: Layout engine flaws were fixed.
CVE-2006-5747: A xml.prototype.hasOwnProperty flaw was
fixed. CVE-2006-5748: Fixes were applied to the Javascript
engine.

MFSA2006-66/CVE-2006-5462: MFSA 2006-60 reported that RSA
digital signatures with a low exponent (typically 3) could
be forged. Firefox and Thunderbird 1.5.0.7, which
incorporated NSS version 3.10.2, were incompletely patched
and remained vulnerable to a variant of this attack.

MFSA2006-67/CVE-2006-5463: shutdown demonstrated that it
was possible to modify a Script object while it was
executing, potentially leading to the execution of
arbitrary JavaScript bytecode.
</description>
  <yum:version ver="2258" rel="0"/>
  <rpm:requires>
    <rpm:entry kind="atom" name="MozillaFirefox" epoch="0" ver="1.5.0.8" rel="0.2" flags="EQ"/>
    <rpm:entry kind="atom" name="MozillaFirefox-translations" epoch="0" ver="1.5.0.8" rel="0.2" flags="EQ"/>
  </rpm:requires>
  <category>security</category>
  <atoms>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>MozillaFirefox</name>
      <arch>i586</arch>
      <version epoch="0" ver="1.5.0.8" rel="0.2"/>
      <checksum type="sha" pkgid="YES">ca169cc9c7b1e1d4e06db9c513a6d4354aad2c47</checksum>
      <time file="1163433000" build="1163385956"/>
      <size package="7230580" installed="18798348" archive="18832980"/>
      <location xml:base="media://#1" href="suse/i586/MozillaFirefox-1.5.0.10-0.2.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="MozillaFirefox" epoch="0" ver="1.5.0.8" rel="0.2" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="MozillaFirefox"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>MozillaFirefox-translations</name>
      <arch>i586</arch>
      <version epoch="0" ver="1.5.0.8" rel="0.2"/>
      <checksum type="sha" pkgid="YES">8e6cda774bcb3d40aa42fd1a7cfdac088417a1d8</checksum>
      <time file="1163433008" build="1163385956"/>
      <size package="3754842" installed="20862964" archive="20872868"/>
      <location xml:base="media://#1" href="suse/i586/MozillaFirefox-translations-1.5.0.10-0.2.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="MozillaFirefox-translations" epoch="0" ver="1.5.0.8" rel="0.2" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="MozillaFirefox-translations"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
  </atoms>
</patch>
