<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="5f62b1276a8877510b3124f13b3c3b27"!-->
<patch
    xmlns="http://novell.com/package/metadata/suse/patch"
    xmlns:yum="http://linux.duke.edu/metadata/common"
    xmlns:rpm="http://linux.duke.edu/metadata/rpm"
    xmlns:suse="http://novell.com/package/metadata/suse/common"
    patchid="MozillaFirefox-2423"
    timestamp="1166619446"
    engine="1.0">
  <yum:name>MozillaFirefox</yum:name>
  <summary lang="en">Security update for Mozilla Firefox</summary>
  <summary lang="de">Security update for Mozilla Firefox</summary>
  <description lang="en">This update brings MozillaFirefox to the security update
release 1.5.0.9,  including the following security fixes.

http://www.mozilla.org/projects/security/known-vulnerabilities.html

CVE-2006-6497/MFSA2006-68: Crashes with evidence of memory
corruption were fixed in the layout engine.
CVE-2006-6498/MFSA2006-68: Crashes with evidence of memory
corruption were fixed in the javascript engine.
CVE-2006-6499/MFSA2006-68: Crashes regarding floating point
usage were fixed. CVE-2006-6500/MFSA2006-69: This issue
only affects Windows systems, Linux is not affected.
CVE-2006-6501/MFSA2006-70: A privilege escalation using a
watch point was fixed. CVE-2006-6502/MFSA2006-71: A
LiveConnect crash finalizing JS objects was fixed.
CVE-2006-6503/MFSA2006-72: A XSS problem caused by setting
img.src to javascript: URI was fixed.
CVE-2006-6504/MFSA2006-73: A Mozilla SVG Processing Remote
Code Execution was fixed. CVE-2006-6505/MFSA2006-74: Some
Mail header processing heap overflows were fixed.
CVE-2006-6506/MFSA2006-75: The RSS Feed-preview referrer
leak was fixed. CVE-2006-6507/MFSA2006-76: A XSS problem
using outer window's Function object was fixed.
</description>
  <description lang="de">This update brings MozillaFirefox to the security update
release 1.5.0.9,  including the following security fixes.

http://www.mozilla.org/projects/security/known-vulnerabilities.html

CVE-2006-6497/MFSA2006-68: Crashes with evidence of memory
corruption were fixed in the layout engine.
CVE-2006-6498/MFSA2006-68: Crashes with evidence of memory
corruption were fixed in the javascript engine.
CVE-2006-6499/MFSA2006-68: Crashes regarding floating point
usage were fixed. CVE-2006-6500/MFSA2006-69: This issue
only affects Windows systems, Linux is not affected.
CVE-2006-6501/MFSA2006-70: A privilege escalation using a
watch point was fixed. CVE-2006-6502/MFSA2006-71: A
LiveConnect crash finalizing JS objects was fixed.
CVE-2006-6503/MFSA2006-72: A XSS problem caused by setting
img.src to javascript: URI was fixed.
CVE-2006-6504/MFSA2006-73: A Mozilla SVG Processing Remote
Code Execution was fixed. CVE-2006-6505/MFSA2006-74: Some
Mail header processing heap overflows were fixed.
CVE-2006-6506/MFSA2006-75: The RSS Feed-preview referrer
leak was fixed. CVE-2006-6507/MFSA2006-76: A XSS problem
using outer window's Function object was fixed.
</description>
  <yum:version ver="2423" rel="0"/>
  <rpm:requires>
    <rpm:entry kind="atom" name="MozillaFirefox" epoch="0" ver="1.5.0.9" rel="0.2" flags="EQ"/>
    <rpm:entry kind="atom" name="MozillaFirefox-translations" epoch="0" ver="1.5.0.9" rel="0.2" flags="EQ"/>
  </rpm:requires>
  <category>security</category>
  <atoms>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>MozillaFirefox</name>
      <arch>i586</arch>
      <version epoch="0" ver="1.5.0.9" rel="0.2"/>
      <checksum type="sha" pkgid="YES">2e5d60aa4e02a74dc5074512c249ac21c3b95b2d</checksum>
      <time file="1166715900" build="1166619446"/>
      <size package="7234714" installed="18812317" archive="18846948"/>
      <location xml:base="media://#1" href="suse/i586/MozillaFirefox-1.5.0.10-0.2.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="MozillaFirefox" epoch="0" ver="1.5.0.9" rel="0.2" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="MozillaFirefox"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>MozillaFirefox-translations</name>
      <arch>i586</arch>
      <version epoch="0" ver="1.5.0.9" rel="0.2"/>
      <checksum type="sha" pkgid="YES">3a6ac100ced57c0f7530ab853fd762d24816ac6e</checksum>
      <time file="1166715904" build="1166619446"/>
      <size package="3754912" installed="20862964" archive="20872868"/>
      <location xml:base="media://#1" href="suse/i586/MozillaFirefox-translations-1.5.0.10-0.2.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="MozillaFirefox-translations" epoch="0" ver="1.5.0.9" rel="0.2" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="MozillaFirefox-translations"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
  </atoms>
</patch>
