mozilla-xulrunner: Mozilla Runtime Environment ---------------------------------------------------------------------- File: mozilla-xulrunner-1.8.0.14eol-0.5.i586.rpm Patchrpm: mozilla-xulrunner-1.8.0.14eol-0.5.i586.patch.rpm Version: 1.8.0.14eol-0.5 Size: 7067 kB Patchsize: 7069 kB Date: Fri 11 Apr 2008 1:30:20 CEST Source: mozilla-xulrunner-1.8.0.14eol-0.5.src.rpm Security: Yes ---------------------------------------------------------------------- Description: This update brings the Mozilla XULRunner engine to security update version level 1.1.9 Following security problems were fixed: - MFSA 2008-19/CVE-2008-1241: XUL popup spoofing variant (cross-tab popups) - MFSA 2008-18/CVE-2008-1195 and CVE-2008-1240: Java socket connection to any local port via LiveConnect - MFSA 2008-17/CVE-2007-4879: Privacy issue with SSL Client Authentication - MFSA 2008-16/CVE-2008-1238: HTTP Referrer spoofing with malformed URLs - MFSA 2008-15/CVE-2008-1236 and CVE-2008-1237: Crashes with evidence of memory corruption (rv:1.8.1.13) - MFSA 2008-14/CVE-2008-1233, CVE-2008-1234, and CVE-2008-1235: JavaScript privilege escalation and arbitrary code execution.