<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="25e7dd0fd151df757435e02aa7061252"!-->
<patch
    xmlns="http://novell.com/package/metadata/suse/patch"
    xmlns:yum="http://linux.duke.edu/metadata/common"
    xmlns:rpm="http://linux.duke.edu/metadata/rpm"
    xmlns:suse="http://novell.com/package/metadata/suse/common"
    patchid="slesp2-MozillaFirefox-6433"
    timestamp="1250243441"
    engine="1.0">
  <yum:name>slesp2-MozillaFirefox</yum:name>
  <summary lang="en">Security update for Mozilla Firefox</summary>
  <summary lang="de">Security update for Mozilla Firefox</summary>
  <description lang="en">MozillaFirefox was updated to the 3.0.13 release, fixing
some security issues and bugs:

MFSA 2009-44 / CVE-2009-2654: Security researcher Juan
Pablo Lopez Yacubian reported that an attacker could call
window.open() on an invalid URL which looks similar to a
legitimate URL and then use document.write() to place
content within the new document, appearing to have come
from the spoofed location. Additionally, if the spoofed
document was created by a document with a valid SSL
certificate, the SSL indicators would be carried over into
the spoofed document. An attacker could use these issues to
display misleading location and SSL information for a
malicious web page.

MFSA 2009-45 / CVE-2009-2662:The browser engine in Mozilla
Firefox before 3.0.13, and 3.5.x before 3.5.2, allows
remote attackers to cause a denial of service (memory
corruption and application crash) or possibly execute
arbitrary code via vectors related to the
TraceRecorder::snapshot function in js/src/jstracer.cpp,
and unspecified other vectors.

CVE-2009-2663 / MFSA 2009-45: libvorbis before r16182, as
used in Mozilla Firefox before 3.0.13 and 3.5.x before
3.5.2 and other products, allows context-dependent
attackers to cause a denial of service (memory corruption
and application crash) or possibly execute arbitrary code
via a crafted .ogg file.

CVE-2009-2664 / MFSA 2009-45: The js_watch_set function in
js/src/jsdbgapi.cpp in the JavaScript engine in Mozilla
Firefox before 3.0.13, and 3.5.x before 3.5.2, allows
remote attackers to cause a denial of service (assertion
failure and application exit) or possibly execute arbitrary
code via a crafted .js file, related to a &quot;memory safety
bug.&quot;
</description>
  <description lang="de">MozillaFirefox was updated to the 3.0.13 release, fixing
some security issues and bugs:

MFSA 2009-44 / CVE-2009-2654: Security researcher Juan
Pablo Lopez Yacubian reported that an attacker could call
window.open() on an invalid URL which looks similar to a
legitimate URL and then use document.write() to place
content within the new document, appearing to have come
from the spoofed location. Additionally, if the spoofed
document was created by a document with a valid SSL
certificate, the SSL indicators would be carried over into
the spoofed document. An attacker could use these issues to
display misleading location and SSL information for a
malicious web page.

MFSA 2009-45 / CVE-2009-2662:The browser engine in Mozilla
Firefox before 3.0.13, and 3.5.x before 3.5.2, allows
remote attackers to cause a denial of service (memory
corruption and application crash) or possibly execute
arbitrary code via vectors related to the
TraceRecorder::snapshot function in js/src/jstracer.cpp,
and unspecified other vectors.

CVE-2009-2663 / MFSA 2009-45: libvorbis before r16182, as
used in Mozilla Firefox before 3.0.13 and 3.5.x before
3.5.2 and other products, allows context-dependent
attackers to cause a denial of service (memory corruption
and application crash) or possibly execute arbitrary code
via a crafted .ogg file.

CVE-2009-2664 / MFSA 2009-45: The js_watch_set function in
js/src/jsdbgapi.cpp in the JavaScript engine in Mozilla
Firefox before 3.0.13, and 3.5.x before 3.5.2, allows
remote attackers to cause a denial of service (assertion
failure and application exit) or possibly execute arbitrary
code via a crafted .js file, related to a &quot;memory safety
bug.&quot;
</description>
  <yum:version ver="6433" rel="0"/>
  <rpm:requires>
    <rpm:entry kind="atom" name="MozillaFirefox" epoch="0" ver="3.0.13" rel="0.4" flags="EQ"/>
    <rpm:entry kind="atom" name="MozillaFirefox-branding-SLED" epoch="0" ver="3.0.3" rel="7.4.3" flags="EQ"/>
    <rpm:entry kind="atom" name="MozillaFirefox-translations" epoch="0" ver="3.0.13" rel="0.4" flags="EQ"/>
    <rpm:entry kind="atom" name="firefox3-atk" epoch="0" ver="1.12.3" rel="0.4.3" flags="EQ"/>
    <rpm:entry kind="atom" name="firefox3-cairo" epoch="0" ver="1.2.4" rel="0.4.3" flags="EQ"/>
    <rpm:entry kind="atom" name="firefox3-glib2" epoch="0" ver="2.12.4" rel="0.4.3" flags="EQ"/>
    <rpm:entry kind="atom" name="firefox3-gtk2" epoch="0" ver="2.10.6" rel="0.4.3" flags="EQ"/>
    <rpm:entry kind="atom" name="firefox3-pango" epoch="0" ver="1.14.5" rel="0.4.3" flags="EQ"/>
    <rpm:entry kind="atom" name="mozilla-xulrunner190" epoch="0" ver="1.9.0.13" rel="1.4" flags="EQ"/>
    <rpm:entry kind="atom" name="mozilla-xulrunner190-gnomevfs" epoch="0" ver="1.9.0.13" rel="1.4" flags="EQ"/>
    <rpm:entry kind="atom" name="mozilla-xulrunner190-translations" epoch="0" ver="1.9.0.13" rel="1.4" flags="EQ"/>
  </rpm:requires>
  <category>security</category>
  <atoms>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>MozillaFirefox</name>
      <arch>i586</arch>
      <version epoch="0" ver="3.0.13" rel="0.4"/>
      <checksum type="sha" pkgid="YES">59e2ed04160ad9354cd5ab660c359a45e3770e95</checksum>
      <time file="1250256101" build="1250243441"/>
      <size package="949166" installed="3275234" archive="3247592"/>
      <location xml:base="media://#1" href="suse/i586/MozillaFirefox-3.0.13-0.4.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="MozillaFirefox" epoch="0" ver="3.0.13" rel="0.4" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="MozillaFirefox"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>MozillaFirefox-branding-SLED</name>
      <arch>i586</arch>
      <version epoch="0" ver="3.0.3" rel="7.4.3"/>
      <checksum type="sha" pkgid="YES">55ae4dff1ca3df883858c69318c0b4e611c044f1</checksum>
      <time file="1250256107" build="1250243740"/>
      <size package="15615" installed="34503" archive="36436"/>
      <location xml:base="media://#1" href="suse/i586/MozillaFirefox-branding-SLED-3.0.3-7.4.3.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="MozillaFirefox-branding-SLED" epoch="0" ver="3.0.3" rel="7.4.3" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="MozillaFirefox-branding-SLED"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>MozillaFirefox-translations</name>
      <arch>i586</arch>
      <version epoch="0" ver="3.0.13" rel="0.4"/>
      <checksum type="sha" pkgid="YES">fa30bc3a44af9f8441386d0f4d898e19d5af6d99</checksum>
      <time file="1250256105" build="1250243441"/>
      <size package="1556327" installed="9736819" archive="9755096"/>
      <location xml:base="media://#1" href="suse/i586/MozillaFirefox-translations-3.0.13-0.4.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="MozillaFirefox-translations" epoch="0" ver="3.0.13" rel="0.4" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="MozillaFirefox-translations"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>firefox3-atk</name>
      <arch>i586</arch>
      <version epoch="0" ver="1.12.3" rel="0.4.3"/>
      <checksum type="sha" pkgid="YES">52d691806a59efda4a1694c034ac08d8f2de4204</checksum>
      <time file="1250256058" build="1249656126"/>
      <size package="211623" installed="1578746" archive="952844"/>
      <location xml:base="media://#1" href="suse/i586/firefox3-atk-1.12.3-0.4.3.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="firefox3-atk" epoch="0" ver="1.12.3" rel="0.4.3" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="firefox3-atk"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>firefox3-cairo</name>
      <arch>i586</arch>
      <version epoch="0" ver="1.2.4" rel="0.4.3"/>
      <checksum type="sha" pkgid="YES">747c62639941ca156f520f1ef5cc881d4cfd8124</checksum>
      <time file="1250256057" build="1249655921"/>
      <size package="335105" installed="1125513" archive="1127824"/>
      <location xml:base="media://#1" href="suse/i586/firefox3-cairo-1.2.4-0.4.3.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="firefox3-cairo" epoch="0" ver="1.2.4" rel="0.4.3" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="firefox3-cairo"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>firefox3-glib2</name>
      <arch>i586</arch>
      <version epoch="0" ver="2.12.4" rel="0.4.3"/>
      <checksum type="sha" pkgid="YES">fdadc0145691544b23f960fd08b546e4c9d13ecd</checksum>
      <time file="1250256050" build="1249655594"/>
      <size package="606832" installed="3871902" archive="2466804"/>
      <location xml:base="media://#1" href="suse/i586/firefox3-glib2-2.12.4-0.4.3.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="firefox3-glib2" epoch="0" ver="2.12.4" rel="0.4.3" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="firefox3-glib2"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>firefox3-gtk2</name>
      <arch>i586</arch>
      <version epoch="0" ver="2.10.6" rel="0.4.3"/>
      <checksum type="sha" pkgid="YES">ed61c3a74b623c9fba807f8df2b057763be65332</checksum>
      <time file="1250256064" build="1249658301"/>
      <size package="4735140" installed="32168357" archive="18746812"/>
      <location xml:base="media://#1" href="suse/i586/firefox3-gtk2-2.10.6-0.4.3.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="firefox3-gtk2" epoch="0" ver="2.10.6" rel="0.4.3" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="firefox3-gtk2"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>firefox3-pango</name>
      <arch>i586</arch>
      <version epoch="0" ver="1.14.5" rel="0.4.3"/>
      <checksum type="sha" pkgid="YES">eaa39dd59029fea6f871b21db47db93752e7451f</checksum>
      <time file="1250256059" build="1249656775"/>
      <size package="279756" installed="774668" archive="780660"/>
      <location xml:base="media://#1" href="suse/i586/firefox3-pango-1.14.5-0.4.3.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="firefox3-pango" epoch="0" ver="1.14.5" rel="0.4.3" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="firefox3-pango"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>mozilla-xulrunner190</name>
      <arch>i586</arch>
      <version epoch="0" ver="1.9.0.13" rel="1.4"/>
      <checksum type="sha" pkgid="YES">0ec0b25755cc536c889a5ec689b563d880aaaf98</checksum>
      <time file="1250256082" build="1250242643"/>
      <size package="8141627" installed="22343572" archive="22170640"/>
      <location xml:base="media://#1" href="suse/i586/mozilla-xulrunner190-1.9.0.13-1.4.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="mozilla-xulrunner190" epoch="0" ver="1.9.0.13" rel="1.4" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="mozilla-xulrunner190"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>mozilla-xulrunner190-gnomevfs</name>
      <arch>i586</arch>
      <version epoch="0" ver="1.9.0.13" rel="1.4"/>
      <checksum type="sha" pkgid="YES">f39235d43aefe2842718c3c0dfdc6206ad2fb5ef</checksum>
      <time file="1250256094" build="1250242643"/>
      <size package="42667" installed="66772" archive="67232"/>
      <location xml:base="media://#1" href="suse/i586/mozilla-xulrunner190-gnomevfs-1.9.0.13-1.4.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="mozilla-xulrunner190-gnomevfs" epoch="0" ver="1.9.0.13" rel="1.4" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="mozilla-xulrunner190-gnomevfs"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>mozilla-xulrunner190-translations</name>
      <arch>i586</arch>
      <version epoch="0" ver="1.9.0.13" rel="1.4"/>
      <checksum type="sha" pkgid="YES">cea7bea825b2900607ec91c13ed1c4764de5eb6e</checksum>
      <time file="1250256095" build="1250242643"/>
      <size package="3599387" installed="22618307" archive="22638036"/>
      <location xml:base="media://#1" href="suse/i586/mozilla-xulrunner190-translations-1.9.0.13-1.4.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="mozilla-xulrunner190-translations" epoch="0" ver="1.9.0.13" rel="1.4" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="mozilla-xulrunner190-translations"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
  </atoms>
</patch>
