<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="f0eb860364b6216eff0dd043fb12bf75"!-->
<update status="stable" from="maint-coord@suse.de" type="security" version="125">
  <id>MozillaFirefox</id>
  <title>MozillaFirefox 3.0.1 security and bugfix update.</title>
  <release>openSUSE 11.0</release>
  <issued date="1217506301"/>
  <references>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=407573" id="407573" title="bug number 407573" type="bugzilla"/>
  </references>
  <description>This update brings Mozilla Firefox to version 3.0.1. It
fixes various bugs and also following security problems:

MFSA 2008-34 / CVE-2008-2785: An anonymous researcher, via
TippingPoint's Zero Day Initiative program, reported a
vulnerability in Mozilla CSS reference counting code. The
vulnerability was caused by an insufficiently sized
variable being used as a reference counter for CSS objects.
By creating a very large number of references to a common
CSS object, this counter could be overflowed which could
cause a crash when the browser attempts to free the CSS
object while still in use. An attacker could use this crash
to run arbitrary code on the victim's computer

MFSA 2008-35 / CVE-2008-2933: Security researcher Billy
Rios reported that if Firefox is not already running,
passing it a command-line URI with pipe symbols will open
multiple tabs. This URI splitting could be used to launch
privileged chrome: URIs from the command-line, a partial
bypass of the fix for MFSA 2005-53 which blocks external
applications from loading such URIs.

This vulnerability could also be used by an attacker to
launch a file: URI from the command line opening a
malicious local file which could exfiltrate data from the
local filesystem.

Combined with a vulnerability which allows an attacker to
inject code into a chrome document, the above issue could
be used to run arbitrary code on a victim's computer. Such
a chrome injection vulnerability was reported by Mozilla
developers Ben Turner and Dan Veditz who showed that a XUL
based SSL error page was not properly sanitizing inputs and
could be used to run arbitrary code with chrome privileges.

MFSA 2008-36 / CVE-2008-2934: Apple Security Researcher
Drew Yao reported a vulnerability in Mozilla graphics code
which handles GIF rendering in Mac OS X. He demonstrated
that a GIF file could be specially crafted to cause the
browser to free an uninitialized pointer. An attacker could
use this vulnerability to crash the browser and potentially
execute arbitrary code on the victim's computer.
</description>
  <pkglist>
    <collection>
        <package name="MozillaFirefox" arch="i586" version="3.0.1" release="0.1">
          <filename>MozillaFirefox-3.0.1-0.1.i586.rpm</filename>
        </package>
        <package name="MozillaFirefox" arch="ppc" version="3.0.1" release="0.1">
          <filename>MozillaFirefox-3.0.1-0.1.ppc.rpm</filename>
        </package>
        <package name="MozillaFirefox" arch="x86_64" version="3.0.1" release="0.1">
          <filename>MozillaFirefox-3.0.1-0.1.x86_64.rpm</filename>
        </package>
        <package name="MozillaFirefox-translations" arch="i586" version="3.0.1" release="0.1">
          <filename>MozillaFirefox-translations-3.0.1-0.1.i586.rpm</filename>
        </package>
        <package name="MozillaFirefox-translations" arch="ppc" version="3.0.1" release="0.1">
          <filename>MozillaFirefox-translations-3.0.1-0.1.ppc.rpm</filename>
        </package>
        <package name="MozillaFirefox-translations" arch="x86_64" version="3.0.1" release="0.1">
          <filename>MozillaFirefox-translations-3.0.1-0.1.x86_64.rpm</filename>
        </package>
        <package name="mozilla-xulrunner190" arch="i586" version="1.9.0.1" release="0.1">
          <filename>mozilla-xulrunner190-1.9.0.1-0.1.i586.rpm</filename>
        </package>
        <package name="mozilla-xulrunner190" arch="ppc" version="1.9.0.1" release="0.1">
          <filename>mozilla-xulrunner190-1.9.0.1-0.1.ppc.rpm</filename>
        </package>
        <package name="mozilla-xulrunner190" arch="x86_64" version="1.9.0.1" release="0.1">
          <filename>mozilla-xulrunner190-1.9.0.1-0.1.x86_64.rpm</filename>
        </package>
        <package name="mozilla-xulrunner190-32bit" arch="x86_64" version="1.9.0.1" release="0.1">
          <filename>mozilla-xulrunner190-32bit-1.9.0.1-0.1.x86_64.rpm</filename>
        </package>
        <package name="mozilla-xulrunner190-64bit" arch="ppc" version="1.9.0.1" release="0.1">
          <filename>mozilla-xulrunner190-64bit-1.9.0.1-0.1.ppc.rpm</filename>
        </package>
        <package name="mozilla-xulrunner190-devel" arch="i586" version="1.9.0.1" release="0.1">
          <filename>mozilla-xulrunner190-devel-1.9.0.1-0.1.i586.rpm</filename>
        </package>
        <package name="mozilla-xulrunner190-devel" arch="ppc" version="1.9.0.1" release="0.1">
          <filename>mozilla-xulrunner190-devel-1.9.0.1-0.1.ppc.rpm</filename>
        </package>
        <package name="mozilla-xulrunner190-devel" arch="x86_64" version="1.9.0.1" release="0.1">
          <filename>mozilla-xulrunner190-devel-1.9.0.1-0.1.x86_64.rpm</filename>
        </package>
        <package name="mozilla-xulrunner190-gnomevfs" arch="i586" version="1.9.0.1" release="0.1">
          <filename>mozilla-xulrunner190-gnomevfs-1.9.0.1-0.1.i586.rpm</filename>
        </package>
        <package name="mozilla-xulrunner190-gnomevfs" arch="ppc" version="1.9.0.1" release="0.1">
          <filename>mozilla-xulrunner190-gnomevfs-1.9.0.1-0.1.ppc.rpm</filename>
        </package>
        <package name="mozilla-xulrunner190-gnomevfs" arch="x86_64" version="1.9.0.1" release="0.1">
          <filename>mozilla-xulrunner190-gnomevfs-1.9.0.1-0.1.x86_64.rpm</filename>
        </package>
        <package name="mozilla-xulrunner190-gnomevfs-32bit" arch="x86_64" version="1.9.0.1" release="0.1">
          <filename>mozilla-xulrunner190-gnomevfs-32bit-1.9.0.1-0.1.x86_64.rpm</filename>
        </package>
        <package name="mozilla-xulrunner190-gnomevfs-64bit" arch="ppc" version="1.9.0.1" release="0.1">
          <filename>mozilla-xulrunner190-gnomevfs-64bit-1.9.0.1-0.1.ppc.rpm</filename>
        </package>
        <package name="mozilla-xulrunner190-translations" arch="i586" version="1.9.0.1" release="0.1">
          <filename>mozilla-xulrunner190-translations-1.9.0.1-0.1.i586.rpm</filename>
        </package>
        <package name="mozilla-xulrunner190-translations" arch="ppc" version="1.9.0.1" release="0.1">
          <filename>mozilla-xulrunner190-translations-1.9.0.1-0.1.ppc.rpm</filename>
        </package>
        <package name="mozilla-xulrunner190-translations" arch="x86_64" version="1.9.0.1" release="0.1">
          <filename>mozilla-xulrunner190-translations-1.9.0.1-0.1.x86_64.rpm</filename>
        </package>
        <package name="mozilla-xulrunner190-translations-32bit" arch="x86_64" version="1.9.0.1" release="0.1">
          <filename>mozilla-xulrunner190-translations-32bit-1.9.0.1-0.1.x86_64.rpm</filename>
        </package>
        <package name="mozilla-xulrunner190-translations-64bit" arch="ppc" version="1.9.0.1" release="0.1">
          <filename>mozilla-xulrunner190-translations-64bit-1.9.0.1-0.1.ppc.rpm</filename>
        </package>
    </collection>
  </pkglist>
</update>
