<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="9d4bf02682deca951672e43797f7cba1"!-->
<update status="stable" from="maint-coord@suse.de" type="security" version="233">
  <id>MozillaFirefox</id>
  <title>MozillaFirefox: Update to 3.0.3</title>
  <release>openSUSE 11.0</release>
  <issued date="1222987244"/>
  <references>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=429179" id="429179" title="bug number 429179" type="bugzilla"/>
  </references>
  <description>This update brings MozillaFirefox to version 3.0.3, fixing
a number of bugs and security problems:

MFSA 2008-44 / CVE-2008-4067 / CVE-2008-4068: resource:
traversal vulnerabilities

MFSA 2008-43: BOM characters stripped from JavaScript
before execution CVE-2008-4065: Stripped BOM characters bug
CVE-2008-4066: HTML escaped low surrogates bug

MFSA 2008-42 Crashes with evidence of memory corruption
(rv:1.9.0.2/1.8.1.17): CVE-2008-4061: Jesse Ruderman
reported a crash in the layout engine. CVE-2008-4062: Igor
Bukanov, Philip Taylor, Georgi Guninski, and Antoine Labour
reported crashes in the JavaScript engine. CVE-2008-4063:
Jesse Ruderman, Bob Clary, and Martijn Wargers reported
crashes in the layout engine which only affected Firefox 3.
CVE-2008-4064: David Maciejak and Drew Yao reported crashes
in graphics rendering which only affected Firefox 3.

MFSA 2008-41 Privilege escalation via XPCnativeWrapper
pollution CVE-2008-4058: XPCnativeWrapper pollution bugs
CVE-2008-4059: XPCnativeWrapper pollution (Firefox 2)
CVE-2008-4060: Documents without script handling objects

MFSA 2008-40 / CVE-2008-3837: Forced mouse drag
</description>
  <pkglist>
    <collection>
        <package name="MozillaFirefox" arch="i586" version="3.0.3" release="1.1">
          <filename>MozillaFirefox-3.0.3-1.1.i586.rpm</filename>
        </package>
        <package name="MozillaFirefox" arch="ppc" version="3.0.3" release="1.1">
          <filename>MozillaFirefox-3.0.3-1.1.ppc.rpm</filename>
        </package>
        <package name="MozillaFirefox" arch="x86_64" version="3.0.3" release="1.1">
          <filename>MozillaFirefox-3.0.3-1.1.x86_64.rpm</filename>
        </package>
        <package name="MozillaFirefox-translations" arch="i586" version="3.0.3" release="1.1">
          <filename>MozillaFirefox-translations-3.0.3-1.1.i586.rpm</filename>
        </package>
        <package name="MozillaFirefox-translations" arch="ppc" version="3.0.3" release="1.1">
          <filename>MozillaFirefox-translations-3.0.3-1.1.ppc.rpm</filename>
        </package>
        <package name="MozillaFirefox-translations" arch="x86_64" version="3.0.3" release="1.1">
          <filename>MozillaFirefox-translations-3.0.3-1.1.x86_64.rpm</filename>
        </package>
    </collection>
  </pkglist>
</update>
