<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="6a9fbe7e71158bafe0f7569b24d2f568"!-->
<patch
    xmlns="http://novell.com/package/metadata/suse/patch"
    xmlns:yum="http://linux.duke.edu/metadata/common"
    xmlns:rpm="http://linux.duke.edu/metadata/rpm"
    xmlns:suse="http://novell.com/package/metadata/suse/common"
    patchid="MozillaFirefox-5449"
    timestamp="1216303762"
    engine="1.0">
  <yum:name>MozillaFirefox</yum:name>
  <summary lang="en">MozillaFirefox: Update to 2.0.0.16</summary>
  <summary lang="de">MozillaFirefox: Update auf 2.0.0.16</summary>
  <description lang="en">MozillaFirefox was updated to version 2.0.0.16, which fixes
various bugs and following security issues:

MFSA 2008-34 CVE-2008-2785: An anonymous researcher, via
TippingPoint's Zero Day Initiative program, reported a
vulnerability in Mozilla CSS reference counting code. The
vulnerability was caused by an insufficiently sized
variable being used as a reference counter for CSS objects.
By creating a very large number of references to a common
CSS object, this counter could be overflowed which could
cause a crash when the browser attempts to free the CSS
object while still in use. An attacker could use this crash
to run arbitrary code on the victim's computer.

MFSA 2008-35 CVE-2008-2933: Security researcher Billy Rios
reported that if Firefox is not already running, passing it
a command-line URI with pipe symbols will open multiple
tabs. This URI splitting could be used to launch privileged
chrome: URIs from the command-line, a partial bypass of the
fix for MFSA 2005-53 which blocks external applications
from loading such URIs. This vulnerability could also be
used by an attacker to launch a file: URI from the command
line opening a malicious local file which could exfiltrate
data from the local filesystem. Combined with a
vulnerability which allows an attacker to inject code into
a chrome document, the above issue could be used to run
arbitrary code on a victim's computer. Such a chrome
injection vulnerability was reported by Mozilla developers
Ben Turner and Dan Veditz who showed that a XUL based SSL
error page was not properly sanitizing inputs and could be
used to run arbitrary code with chrome privileges.
</description>
  <description lang="de">MozillaFirefox wurde auf Version 2.0.0.16 gebracht, die
mehrere Fehler und folgende Sicherheitsprobleme behebt:

MFSA 2008-34 CVE-2008-2785: An anonymous researcher, via
TippingPoint's Zero Day Initiative program, reported a
vulnerability in Mozilla CSS reference counting code. The
vulnerability was caused by an insufficiently sized
variable being used as a reference counter for CSS objects.
By creating a very large number of references to a common
CSS object, this counter could be overflowed which could
cause a crash when the browser attempts to free the CSS
object while still in use. An attacker could use this crash
to run arbitrary code on the victim's computer.

MFSA 2008-35 CVE-2008-2933: Security researcher Billy Rios
reported that if Firefox is not already running, passing it
a command-line URI with pipe symbols will open multiple
tabs. This URI splitting could be used to launch privileged
chrome: URIs from the command-line, a partial bypass of the
fix for MFSA 2005-53 which blocks external applications
from loading such URIs. This vulnerability could also be
used by an attacker to launch a file: URI from the command
line opening a malicious local file which could exfiltrate
data from the local filesystem. Combined with a
vulnerability which allows an attacker to inject code into
a chrome document, the above issue could be used to run
arbitrary code on a victim's computer. Such a chrome
injection vulnerability was reported by Mozilla developers
Ben Turner and Dan Veditz who showed that a XUL based SSL
error page was not properly sanitizing inputs and could be
used to run arbitrary code with chrome privileges.
</description>
  <yum:version ver="5449" rel="0"/>
  <rpm:requires>
    <rpm:entry kind="atom" name="MozillaFirefox" epoch="0" ver="2.0.0.16" rel="0.1" flags="EQ"/>
    <rpm:entry kind="atom" name="MozillaFirefox-translations" epoch="0" ver="2.0.0.16" rel="0.1" flags="EQ"/>
  </rpm:requires>
  <category>security</category>
  <atoms>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>MozillaFirefox</name>
      <arch>i586</arch>
      <version epoch="0" ver="2.0.0.16" rel="0.1"/>
      <checksum type="sha" pkgid="YES">fdcf9d9821375e0bdbf41da5dddbd5917b240540</checksum>
      <time file="1216312056" build="1216303762"/>
      <size package="7972312" installed="21632743" archive="21658520"/>
      <location href="rpm/i586/MozillaFirefox-2.0.0.16-0.1.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="MozillaFirefox" epoch="0" ver="2.0.0.16" rel="0.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="MozillaFirefox"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <deltarpm>
          <location href="rpm/i586/MozillaFirefox-2.0.0.6_2.0.0.16-25_0.1.i586.delta.rpm"/>
          <checksum type="sha">5ec472d1cb004aa5b5d6bf26dc67ac13eada5b3d</checksum>
          <time file="1216312495" build="1216303762"/>
          <size package="1034218" archive="0"/>
          <base-version epoch="0" ver="2.0.0.6" rel="25" md5sum="2ab95788f1feb7e51204a7e3a31138f2" buildtime="1190660015" sequence_info="MozillaFirefox-2.0.0.6-25-f459e7ac7ff1e77f1b783975cf23c93bf11cc11c5151d26511111a20c9310a83109831088310fc210ce110"/>
        </deltarpm>
        <deltarpm>
          <location href="rpm/i586/MozillaFirefox-2.0.0.15_2.0.0.16-0.1.i586.delta.rpm"/>
          <checksum type="sha">61d15e0c31e64520c09e555dbd5edc0303bd456b</checksum>
          <time file="1216312508" build="1216303762"/>
          <size package="350702" archive="0"/>
          <base-version epoch="0" ver="2.0.0.15" rel="0.1" md5sum="5bef2d39d7992cded00cacddaa47682b" buildtime="1215598736" sequence_info="MozillaFirefox-2.0.0.15-0.1-3322c399aaeca5413044a34a706ff2b7f11cc11c5151d265111c20a9310a83109831088310fc210ce110"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>MozillaFirefox</name>
      <arch>ppc</arch>
      <version epoch="0" ver="2.0.0.16" rel="0.1"/>
      <checksum type="sha" pkgid="YES">e70080f72bce11dab9605af9e52fdaec4df9cc15</checksum>
      <time file="1216312026" build="1216294659"/>
      <size package="8127556" installed="24551319" archive="24577096"/>
      <location href="rpm/ppc/MozillaFirefox-2.0.0.16-0.1.ppc.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="MozillaFirefox" epoch="0" ver="2.0.0.16" rel="0.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="MozillaFirefox"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <deltarpm>
          <location href="rpm/ppc/MozillaFirefox-2.0.0.6_2.0.0.16-25_0.1.ppc.delta.rpm"/>
          <checksum type="sha">48c5c6e5235d5fff6663ca5e091e63cd9a9cd771</checksum>
          <time file="1216312533" build="1216294659"/>
          <size package="972402" archive="0"/>
          <base-version epoch="0" ver="2.0.0.6" rel="25" md5sum="4bb2c608237e6bae49ea37faf28dec3c" buildtime="1190656513" sequence_info="MozillaFirefox-2.0.0.6-25-22e8e93a2ad8238bbdcd8e2be2640a12f11cc11c5151d26511111a20c9310a83109831088310fc210ce110"/>
        </deltarpm>
        <deltarpm>
          <location href="rpm/ppc/MozillaFirefox-2.0.0.15_2.0.0.16-0.1.ppc.delta.rpm"/>
          <checksum type="sha">16237f28b0500a6b9fb4b92359ca391712eed41c</checksum>
          <time file="1216312547" build="1216294659"/>
          <size package="314441" archive="0"/>
          <base-version epoch="0" ver="2.0.0.15" rel="0.1" md5sum="3c5645d7b03bbd0fb05acb3fa1e05fad" buildtime="1215603065" sequence_info="MozillaFirefox-2.0.0.15-0.1-2b04c5c60644cef760b840ec6dbbabb5f11cc11c5151d265111c20a9310a83109831088310fc210ce110"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>MozillaFirefox</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="2.0.0.16" rel="0.1"/>
      <checksum type="sha" pkgid="YES">f98353cfcec14ae1e80609375a10b890ad2eed34</checksum>
      <time file="1216312107" build="1216304017"/>
      <size package="9032255" installed="25546546" archive="25572772"/>
      <location href="rpm/x86_64/MozillaFirefox-2.0.0.16-0.1.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="MozillaFirefox" epoch="0" ver="2.0.0.16" rel="0.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="MozillaFirefox"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <deltarpm>
          <location href="rpm/x86_64/MozillaFirefox-2.0.0.6_2.0.0.16-25_0.1.x86_64.delta.rpm"/>
          <checksum type="sha">7e119b6f0c6176cdecb5ca87e043662cecfa14a9</checksum>
          <time file="1216312570" build="1216304017"/>
          <size package="1615532" archive="0"/>
          <base-version epoch="0" ver="2.0.0.6" rel="25" md5sum="473712165c9a5d6203f546c7a7c48d72" buildtime="1190657167" sequence_info="MozillaFirefox-2.0.0.6-25-3eb86dd2a3df9c82deb68bf4bd120e1df11cc11c5151d26511111a20c9310a83109831088310fc210ce110"/>
        </deltarpm>
        <deltarpm>
          <location href="rpm/x86_64/MozillaFirefox-2.0.0.15_2.0.0.16-0.1.x86_64.delta.rpm"/>
          <checksum type="sha">2a0a87db413d287512a5a69046580d71bd493e81</checksum>
          <time file="1216312586" build="1216304017"/>
          <size package="383057" archive="0"/>
          <base-version epoch="0" ver="2.0.0.15" rel="0.1" md5sum="28549dced494b0435fe8199f5c22b9b7" buildtime="1215598491" sequence_info="MozillaFirefox-2.0.0.15-0.1-e48b30e51dec1ed4c05cf77185aea811f11cc11c5151d265111c20a9310a83109831088310fc210ce110"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>MozillaFirefox-translations</name>
      <arch>i586</arch>
      <version epoch="0" ver="2.0.0.16" rel="0.1"/>
      <checksum type="sha" pkgid="YES">aa0c867ee6d4ffb8c681d9985ef53f5f480a215d</checksum>
      <time file="1216312062" build="1216303762"/>
      <size package="5114066" installed="28899156" archive="28912336"/>
      <location href="rpm/i586/MozillaFirefox-translations-2.0.0.16-0.1.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="MozillaFirefox-translations" epoch="0" ver="2.0.0.16" rel="0.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="MozillaFirefox-translations"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <deltarpm>
          <location href="rpm/i586/MozillaFirefox-translations-2.0.0.6_2.0.0.16-25_0.1.i586.delta.rpm"/>
          <checksum type="sha">5f191b664208100b9b06e0ab3702ed00f5df84cd</checksum>
          <time file="1216312601" build="1216303762"/>
          <size package="168496" archive="0"/>
          <base-version epoch="0" ver="2.0.0.6" rel="25" md5sum="90b2b7f1cde9c9efdb5f9367ee5af48f" buildtime="1190660015" sequence_info="MozillaFirefox-translations-2.0.0.6-25-a41a8377a06c920ae5b02b8ffdae2e12ea10"/>
        </deltarpm>
        <deltarpm>
          <location href="rpm/i586/MozillaFirefox-translations-2.0.0.15_2.0.0.16-0.1.i586.delta.rpm"/>
          <checksum type="sha">901b076b748509e3bdd5993a656b19b8c7e9cd53</checksum>
          <time file="1216312611" build="1216303762"/>
          <size package="52147" archive="0"/>
          <base-version epoch="0" ver="2.0.0.15" rel="0.1" md5sum="80c7c05d827dd3a2c547dcc5387ef74d" buildtime="1215598736" sequence_info="MozillaFirefox-translations-2.0.0.15-0.1-da1f4eaac0bbac0c8eebdb3740acff3a8b10"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>MozillaFirefox-translations</name>
      <arch>ppc</arch>
      <version epoch="0" ver="2.0.0.16" rel="0.1"/>
      <checksum type="sha" pkgid="YES">e1865e6ab6b0b51d67a2d8fa81763c01c2a13cda</checksum>
      <time file="1216312031" build="1216294659"/>
      <size package="5112747" installed="28899156" archive="28912336"/>
      <location href="rpm/ppc/MozillaFirefox-translations-2.0.0.16-0.1.ppc.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="MozillaFirefox-translations" epoch="0" ver="2.0.0.16" rel="0.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="MozillaFirefox-translations"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <deltarpm>
          <location href="rpm/ppc/MozillaFirefox-translations-2.0.0.6_2.0.0.16-25_0.1.ppc.delta.rpm"/>
          <checksum type="sha">bad3020c7677514d8fafb1c853a3ddf8b6511d94</checksum>
          <time file="1216312621" build="1216294659"/>
          <size package="168100" archive="0"/>
          <base-version epoch="0" ver="2.0.0.6" rel="25" md5sum="adaa94071c494fb2191674a73f909786" buildtime="1190656513" sequence_info="MozillaFirefox-translations-2.0.0.6-25-a41a8377a06c920ae5b02b8ffdae2e12ea10"/>
        </deltarpm>
        <deltarpm>
          <location href="rpm/ppc/MozillaFirefox-translations-2.0.0.15_2.0.0.16-0.1.ppc.delta.rpm"/>
          <checksum type="sha">6b79e836c3bda1c7ffc0db8fc6820ffc198a1f7e</checksum>
          <time file="1216312629" build="1216294659"/>
          <size package="51814" archive="0"/>
          <base-version epoch="0" ver="2.0.0.15" rel="0.1" md5sum="850639ce1948f2c6eb12ed9997adfc04" buildtime="1215603065" sequence_info="MozillaFirefox-translations-2.0.0.15-0.1-da1f4eaac0bbac0c8eebdb3740acff3a8b10"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>MozillaFirefox-translations</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="2.0.0.16" rel="0.1"/>
      <checksum type="sha" pkgid="YES">eb2d00381d274369787662e99651d537fe6f5da1</checksum>
      <time file="1216312111" build="1216304017"/>
      <size package="5113806" installed="28899156" archive="28912456"/>
      <location href="rpm/x86_64/MozillaFirefox-translations-2.0.0.16-0.1.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="MozillaFirefox-translations" epoch="0" ver="2.0.0.16" rel="0.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="MozillaFirefox-translations"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <deltarpm>
          <location href="rpm/x86_64/MozillaFirefox-translations-2.0.0.6_2.0.0.16-25_0.1.x86_64.delta.rpm"/>
          <checksum type="sha">7def76c2f5fed87d4aecbd3cba7eeface3784a7b</checksum>
          <time file="1216312640" build="1216304017"/>
          <size package="168890" archive="0"/>
          <base-version epoch="0" ver="2.0.0.6" rel="25" md5sum="b8a1a406cbcff451d8e46de9c036cccc" buildtime="1190657167" sequence_info="MozillaFirefox-translations-2.0.0.6-25-fa5542ae21e82a506c6fe3d6a0e674caea10"/>
        </deltarpm>
        <deltarpm>
          <location href="rpm/x86_64/MozillaFirefox-translations-2.0.0.15_2.0.0.16-0.1.x86_64.delta.rpm"/>
          <checksum type="sha">36dc93004d88260dcdad43b5da10b7042ba17130</checksum>
          <time file="1216312648" build="1216304017"/>
          <size package="52099" archive="0"/>
          <base-version epoch="0" ver="2.0.0.15" rel="0.1" md5sum="66ac67c6e5081797d05692f4401423a9" buildtime="1215598491" sequence_info="MozillaFirefox-translations-2.0.0.15-0.1-e7aa4062f40e772c62e5c159d4402eb78b10"/>
        </deltarpm>
      </pkgfiles>
    </package>
  </atoms>
</patch>
