<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="8bfc1676fcec027a90fa59b4d99cefda"!-->
<patch
    xmlns="http://novell.com/package/metadata/suse/patch"
    xmlns:yum="http://linux.duke.edu/metadata/common"
    xmlns:rpm="http://linux.duke.edu/metadata/rpm"
    xmlns:suse="http://novell.com/package/metadata/suse/common"
    patchid="slesp2-MozillaFirefox-5450"
    timestamp="1216291970"
    engine="1.0">
  <yum:name>slesp2-MozillaFirefox</yum:name>
  <summary lang="en">Security update for MozillaFirefox</summary>
  <summary lang="de">Security update for MozillaFirefox</summary>
  <description lang="en">MozillaFirefox was updated to version 2.0.0.16, which fixes
various bugs and following security issues:

MFSA 2008-34 CVE-2008-2785: An anonymous researcher, via
TippingPoint's Zero Day Initiative program, reported a
vulnerability in Mozilla CSS reference counting code. The
vulnerability was caused by an insufficiently sized
variable being used as a reference counter for CSS objects.
By creating a very large number of references to a common
CSS object, this counter could be overflowed which could
cause a crash when the browser attempts to free the CSS
object while still in use. An attacker could use this crash
to run arbitrary code on the victim's computer.

MFSA 2008-35 CVE-2008-2933: Security researcher Billy Rios
reported that if Firefox is not already running, passing it
a command-line URI with pipe symbols will open multiple
tabs. This URI splitting could be used to launch privileged
chrome: URIs from the command-line, a partial bypass of the
fix for MFSA 2005-53 which blocks external applications
from loading such URIs. This vulnerability could also be
used by an attacker to launch a file: URI from the command
line opening a malicious local file which could exfiltrate
data from the local filesystem. Combined with a
vulnerability which allows an attacker to inject code into
a chrome document, the above issue could be used to run
arbitrary code on a victim's computer. Such a chrome
injection vulnerability was reported by Mozilla developers
Ben Turner and Dan Veditz who showed that a XUL based SSL
error page was not properly sanitizing inputs and could be
used to run arbitrary code with chrome privileges.
</description>
  <description lang="de">MozillaFirefox was updated to version 2.0.0.16, which fixes
various bugs and following security issues:

MFSA 2008-34 CVE-2008-2785: An anonymous researcher, via
TippingPoint's Zero Day Initiative program, reported a
vulnerability in Mozilla CSS reference counting code. The
vulnerability was caused by an insufficiently sized
variable being used as a reference counter for CSS objects.
By creating a very large number of references to a common
CSS object, this counter could be overflowed which could
cause a crash when the browser attempts to free the CSS
object while still in use. An attacker could use this crash
to run arbitrary code on the victim's computer.

MFSA 2008-35 CVE-2008-2933: Security researcher Billy Rios
reported that if Firefox is not already running, passing it
a command-line URI with pipe symbols will open multiple
tabs. This URI splitting could be used to launch privileged
chrome: URIs from the command-line, a partial bypass of the
fix for MFSA 2005-53 which blocks external applications
from loading such URIs. This vulnerability could also be
used by an attacker to launch a file: URI from the command
line opening a malicious local file which could exfiltrate
data from the local filesystem. Combined with a
vulnerability which allows an attacker to inject code into
a chrome document, the above issue could be used to run
arbitrary code on a victim's computer. Such a chrome
injection vulnerability was reported by Mozilla developers
Ben Turner and Dan Veditz who showed that a XUL based SSL
error page was not properly sanitizing inputs and could be
used to run arbitrary code with chrome privileges.
</description>
  <yum:version ver="5450" rel="0"/>
  <rpm:requires>
    <rpm:entry kind="atom" name="MozillaFirefox" epoch="0" ver="2.0.0.16" rel="0.4" flags="EQ"/>
    <rpm:entry kind="atom" name="MozillaFirefox-translations" epoch="0" ver="2.0.0.16" rel="0.4" flags="EQ"/>
  </rpm:requires>
  <category>security</category>
  <atoms>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>MozillaFirefox</name>
      <arch>i586</arch>
      <version epoch="0" ver="2.0.0.16" rel="0.4"/>
      <checksum type="sha" pkgid="YES">a1bb4fa77e9b7a925b3877e67c454f8eab672b04</checksum>
      <time file="1216312051" build="1216291970"/>
      <size package="9327362" installed="24090995" archive="24074608"/>
      <location xml:base="media://#1" href="suse/i586/MozillaFirefox-3.0.13-0.4.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="MozillaFirefox" epoch="0" ver="2.0.0.16" rel="0.4" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="MozillaFirefox"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>MozillaFirefox-translations</name>
      <arch>i586</arch>
      <version epoch="0" ver="2.0.0.16" rel="0.4"/>
      <checksum type="sha" pkgid="YES">f46019fddf72c5f0a2fd18f7c537ff5239d042d8</checksum>
      <time file="1216312055" build="1216291970"/>
      <size package="3747062" installed="20478787" archive="20488392"/>
      <location xml:base="media://#1" href="suse/i586/MozillaFirefox-translations-3.0.13-0.4.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="MozillaFirefox-translations" epoch="0" ver="2.0.0.16" rel="0.4" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="MozillaFirefox-translations"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
  </atoms>
</patch>
