<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="6a9fbe7e71158bafe0f7569b24d2f568"!-->
<patch
    xmlns="http://novell.com/package/metadata/suse/patch"
    xmlns:yum="http://linux.duke.edu/metadata/common"
    xmlns:rpm="http://linux.duke.edu/metadata/rpm"
    xmlns:suse="http://novell.com/package/metadata/suse/common"
    patchid="MozillaFirefox-5449"
    timestamp="1216300621"
    engine="1.0">
  <yum:name>MozillaFirefox</yum:name>
  <summary lang="en">MozillaFirefox: Update to 2.0.0.16</summary>
  <summary lang="de">MozillaFirefox: Update auf 2.0.0.16</summary>
  <description lang="en">MozillaFirefox was updated to version 2.0.0.16, which fixes
various bugs and following security issues:

MFSA 2008-34 CVE-2008-2785: An anonymous researcher, via
TippingPoint's Zero Day Initiative program, reported a
vulnerability in Mozilla CSS reference counting code. The
vulnerability was caused by an insufficiently sized
variable being used as a reference counter for CSS objects.
By creating a very large number of references to a common
CSS object, this counter could be overflowed which could
cause a crash when the browser attempts to free the CSS
object while still in use. An attacker could use this crash
to run arbitrary code on the victim's computer.

MFSA 2008-35 CVE-2008-2933: Security researcher Billy Rios
reported that if Firefox is not already running, passing it
a command-line URI with pipe symbols will open multiple
tabs. This URI splitting could be used to launch privileged
chrome: URIs from the command-line, a partial bypass of the
fix for MFSA 2005-53 which blocks external applications
from loading such URIs. This vulnerability could also be
used by an attacker to launch a file: URI from the command
line opening a malicious local file which could exfiltrate
data from the local filesystem. Combined with a
vulnerability which allows an attacker to inject code into
a chrome document, the above issue could be used to run
arbitrary code on a victim's computer. Such a chrome
injection vulnerability was reported by Mozilla developers
Ben Turner and Dan Veditz who showed that a XUL based SSL
error page was not properly sanitizing inputs and could be
used to run arbitrary code with chrome privileges.
</description>
  <description lang="de">MozillaFirefox wurde auf Version 2.0.0.16 gebracht, die
mehrere Fehler und folgende Sicherheitsprobleme behebt:

MFSA 2008-34 CVE-2008-2785: An anonymous researcher, via
TippingPoint's Zero Day Initiative program, reported a
vulnerability in Mozilla CSS reference counting code. The
vulnerability was caused by an insufficiently sized
variable being used as a reference counter for CSS objects.
By creating a very large number of references to a common
CSS object, this counter could be overflowed which could
cause a crash when the browser attempts to free the CSS
object while still in use. An attacker could use this crash
to run arbitrary code on the victim's computer.

MFSA 2008-35 CVE-2008-2933: Security researcher Billy Rios
reported that if Firefox is not already running, passing it
a command-line URI with pipe symbols will open multiple
tabs. This URI splitting could be used to launch privileged
chrome: URIs from the command-line, a partial bypass of the
fix for MFSA 2005-53 which blocks external applications
from loading such URIs. This vulnerability could also be
used by an attacker to launch a file: URI from the command
line opening a malicious local file which could exfiltrate
data from the local filesystem. Combined with a
vulnerability which allows an attacker to inject code into
a chrome document, the above issue could be used to run
arbitrary code on a victim's computer. Such a chrome
injection vulnerability was reported by Mozilla developers
Ben Turner and Dan Veditz who showed that a XUL based SSL
error page was not properly sanitizing inputs and could be
used to run arbitrary code with chrome privileges.
</description>
  <yum:version ver="5449" rel="0"/>
  <rpm:requires>
    <rpm:entry kind="atom" name="MozillaFirefox" epoch="0" ver="2.0.0.16" rel="0.1" flags="EQ"/>
    <rpm:entry kind="atom" name="MozillaFirefox-translations" epoch="0" ver="2.0.0.16" rel="0.1" flags="EQ"/>
  </rpm:requires>
  <category>security</category>
  <atoms>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>MozillaFirefox</name>
      <arch>i586</arch>
      <version epoch="0" ver="2.0.0.16" rel="0.1"/>
      <checksum type="sha" pkgid="YES">4fc4a43a5e05567eda5e4d8bcbba6f01fb102ad2</checksum>
      <time file="1216312002" build="1216300621"/>
      <size package="8011907" installed="21839453" archive="21874812"/>
      <location href="rpm/i586/MozillaFirefox-2.0.0.16-0.1.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="MozillaFirefox" epoch="0" ver="2.0.0.16" rel="0.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="MozillaFirefox"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/i586/MozillaFirefox-2.0.0.16-0.1.i586.patch.rpm"/>
          <checksum type="sha">28fdfc2684876a590ed3ff14b372136f71a6caa6</checksum>
          <time file="1216312225" build="1216300621"/>
          <size package="6793472" archive="19516424"/>
          <base-version epoch="0" ver="2.0" rel="30"/>
          <base-version epoch="0" ver="2.0.0.1" rel="0.1"/>
          <base-version epoch="0" ver="2.0.0.10" rel="0.1"/>
          <base-version epoch="0" ver="2.0.0.12" rel="0.1"/>
          <base-version epoch="0" ver="2.0.0.13" rel="0.1"/>
          <base-version epoch="0" ver="2.0.0.14" rel="0.1"/>
          <base-version epoch="0" ver="2.0.0.15" rel="0.1"/>
          <base-version epoch="0" ver="2.0.0.2" rel="1.1"/>
          <base-version epoch="0" ver="2.0.0.4" rel="1.1"/>
          <base-version epoch="0" ver="2.0.0.5" rel="1.1"/>
          <base-version epoch="0" ver="2.0.0.8" rel="1.1"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/i586/MozillaFirefox-2.0_2.0.0.16-30_0.1.i586.delta.rpm"/>
          <checksum type="sha">0386efc47592363ead325f73feaefda4a3ad0c39</checksum>
          <time file="1216312241" build="1216300621"/>
          <size package="1439460" archive="0"/>
          <base-version epoch="0" ver="2.0" rel="30" md5sum="b8a897973110e47260a34fb3b409f3e3" buildtime="1164967895" sequence_info="MozillaFirefox-2.0-30-2ce7a3efa05a6751a7cc4c532f93eacfeb30"/>
        </deltarpm>
        <deltarpm>
          <location href="rpm/i586/MozillaFirefox-2.0.0.15_2.0.0.16-0.1.i586.delta.rpm"/>
          <checksum type="sha">98e0674c5b7002936f26c15167803469ae30ca59</checksum>
          <time file="1216312255" build="1216300621"/>
          <size package="299533" archive="0"/>
          <base-version epoch="0" ver="2.0.0.15" rel="0.1" md5sum="cd4a9264d54d137c5acc0cd499c5eff6" buildtime="1215526951" sequence_info="MozillaFirefox-2.0.0.15-0.1-68315bb064ab8c9f0c13e19e113d68c8fb30"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>MozillaFirefox</name>
      <arch>ppc</arch>
      <version epoch="0" ver="2.0.0.16" rel="0.1"/>
      <checksum type="sha" pkgid="YES">8cfd8f028bd753908e2b1f64a8d5b57ffffd9f96</checksum>
      <time file="1216312010" build="1216294961"/>
      <size package="8141797" installed="24587617" archive="24622976"/>
      <location href="rpm/ppc/MozillaFirefox-2.0.0.16-0.1.ppc.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="MozillaFirefox" epoch="0" ver="2.0.0.16" rel="0.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="MozillaFirefox"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/ppc/MozillaFirefox-2.0.0.16-0.1.ppc.patch.rpm"/>
          <checksum type="sha">f5c21babd8b3506f2268a6f44e15c9e71309ec08</checksum>
          <time file="1216312289" build="1216294961"/>
          <size package="6929147" archive="22249112"/>
          <base-version epoch="0" ver="2.0" rel="30"/>
          <base-version epoch="0" ver="2.0.0.1" rel="0.1"/>
          <base-version epoch="0" ver="2.0.0.10" rel="0.1"/>
          <base-version epoch="0" ver="2.0.0.12" rel="0.1"/>
          <base-version epoch="0" ver="2.0.0.13" rel="0.1"/>
          <base-version epoch="0" ver="2.0.0.14" rel="0.1"/>
          <base-version epoch="0" ver="2.0.0.15" rel="0.1"/>
          <base-version epoch="0" ver="2.0.0.2" rel="1.1"/>
          <base-version epoch="0" ver="2.0.0.4" rel="1.1"/>
          <base-version epoch="0" ver="2.0.0.5" rel="1.1"/>
          <base-version epoch="0" ver="2.0.0.8" rel="1.1"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/ppc/MozillaFirefox-2.0_2.0.0.16-30_0.1.ppc.delta.rpm"/>
          <checksum type="sha">4f66c8b887418de0a16391cfec2aa6d90c0de1b8</checksum>
          <time file="1216312306" build="1216294961"/>
          <size package="1364092" archive="0"/>
          <base-version epoch="0" ver="2.0" rel="30" md5sum="ec22c7aae3d3c8879b1d08d1ba8df947" buildtime="1164968665" sequence_info="MozillaFirefox-2.0-30-4681a93335e6f8e1d6d64711d1c3ee26eb30"/>
        </deltarpm>
        <deltarpm>
          <location href="rpm/ppc/MozillaFirefox-2.0.0.15_2.0.0.16-0.1.ppc.delta.rpm"/>
          <checksum type="sha">cc5824a2e9c63fc8ddc40290058deb09d006630d</checksum>
          <time file="1216312320" build="1216294961"/>
          <size package="921443" archive="0"/>
          <base-version epoch="0" ver="2.0.0.15" rel="0.1" md5sum="1702b56d463ba26caaa4218106e442d8" buildtime="1215528562" sequence_info="MozillaFirefox-2.0.0.15-0.1-572afac8f73a142facba94c85bff9934d118119a11be1120"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>MozillaFirefox</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="2.0.0.16" rel="0.1"/>
      <checksum type="sha" pkgid="YES">efa04f3de9570059ce58e9bb069060f5b7c3a0c5</checksum>
      <time file="1216311877" build="1216292106"/>
      <size package="9072130" installed="25696764" archive="25732572"/>
      <location href="rpm/x86_64/MozillaFirefox-2.0.0.16-0.1.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="MozillaFirefox" epoch="0" ver="2.0.0.16" rel="0.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="MozillaFirefox"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/x86_64/MozillaFirefox-2.0.0.16-0.1.x86_64.patch.rpm"/>
          <checksum type="sha">7949e4d04afee178d46ee4c5848cf81522794039</checksum>
          <time file="1216312346" build="1216292106"/>
          <size package="7821720" archive="23321116"/>
          <base-version epoch="0" ver="2.0" rel="30"/>
          <base-version epoch="0" ver="2.0.0.1" rel="0.1"/>
          <base-version epoch="0" ver="2.0.0.10" rel="0.1"/>
          <base-version epoch="0" ver="2.0.0.12" rel="0.1"/>
          <base-version epoch="0" ver="2.0.0.13" rel="0.1"/>
          <base-version epoch="0" ver="2.0.0.14" rel="0.1"/>
          <base-version epoch="0" ver="2.0.0.15" rel="0.1"/>
          <base-version epoch="0" ver="2.0.0.2" rel="1.1"/>
          <base-version epoch="0" ver="2.0.0.4" rel="1.1"/>
          <base-version epoch="0" ver="2.0.0.5" rel="1.1"/>
          <base-version epoch="0" ver="2.0.0.8" rel="1.1"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/x86_64/MozillaFirefox-2.0.0.15_2.0.0.16-0.1.x86_64.delta.rpm"/>
          <checksum type="sha">70ef7c968882bbbd2a49cebb0534658368a313a6</checksum>
          <time file="1216312370" build="1216292106"/>
          <size package="1021409" archive="0"/>
          <base-version epoch="0" ver="2.0.0.15" rel="0.1" md5sum="a6b6629eac56ce6e9beef081e78baf84" buildtime="1215527364" sequence_info="MozillaFirefox-2.0.0.15-0.1-d35a4b9f3e22c6a34f1fd53dd889d198d118119a11be1120"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>MozillaFirefox-translations</name>
      <arch>i586</arch>
      <version epoch="0" ver="2.0.0.16" rel="0.1"/>
      <checksum type="sha" pkgid="YES">38bbf6ccd113bb6e7d3b00cc83179ec4e6d0f38d</checksum>
      <time file="1216312003" build="1216300621"/>
      <size package="4797381" installed="26937822" archive="26950120"/>
      <location href="rpm/i586/MozillaFirefox-translations-2.0.0.16-0.1.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="MozillaFirefox-translations" epoch="0" ver="2.0.0.16" rel="0.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="MozillaFirefox-translations"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/i586/MozillaFirefox-translations-2.0.0.16-0.1.i586.patch.rpm"/>
          <checksum type="sha">cd21eb5dc18fdff4cbb34a2ab6dbb8c8ffb37d18</checksum>
          <time file="1216312393" build="1216300621"/>
          <size package="4795640" archive="26912548"/>
          <base-version epoch="0" ver="2.0" rel="30"/>
          <base-version epoch="0" ver="2.0.0.1" rel="0.1"/>
          <base-version epoch="0" ver="2.0.0.10" rel="0.1"/>
          <base-version epoch="0" ver="2.0.0.12" rel="0.1"/>
          <base-version epoch="0" ver="2.0.0.13" rel="0.1"/>
          <base-version epoch="0" ver="2.0.0.14" rel="0.1"/>
          <base-version epoch="0" ver="2.0.0.15" rel="0.1"/>
          <base-version epoch="0" ver="2.0.0.2" rel="1.1"/>
          <base-version epoch="0" ver="2.0.0.4" rel="1.1"/>
          <base-version epoch="0" ver="2.0.0.5" rel="1.1"/>
          <base-version epoch="0" ver="2.0.0.8" rel="1.1"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/i586/MozillaFirefox-translations-2.0_2.0.0.16-30_0.1.i586.delta.rpm"/>
          <checksum type="sha">7ded8baab65b512ed41a49290226cf83be2a622c</checksum>
          <time file="1216312402" build="1216300621"/>
          <size package="283547" archive="0"/>
          <base-version epoch="0" ver="2.0" rel="30" md5sum="bb512f3cdb578d99cc83fe0030cf6402" buildtime="1164967895" sequence_info="MozillaFirefox-translations-2.0-30-3c325acd5789eb73819ade6be6f59bbbcc10"/>
        </deltarpm>
        <deltarpm>
          <location href="rpm/i586/MozillaFirefox-translations-2.0.0.15_2.0.0.16-0.1.i586.delta.rpm"/>
          <checksum type="sha">83c2b76e9f37735a5aa2c6f1f71df098cad8f91e</checksum>
          <time file="1216312410" build="1216300621"/>
          <size package="47035" archive="0"/>
          <base-version epoch="0" ver="2.0.0.15" rel="0.1" md5sum="090b62a3d45faa87341cdf4cb9b52fff" buildtime="1215526951" sequence_info="MozillaFirefox-translations-2.0.0.15-0.1-f3ca90b07b24901ae7f82d38c4bd284baa10"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>MozillaFirefox-translations</name>
      <arch>ppc</arch>
      <version epoch="0" ver="2.0.0.16" rel="0.1"/>
      <checksum type="sha" pkgid="YES">d2bf04d8458748a4409a6b72dc934aecc44eac0f</checksum>
      <time file="1216312014" build="1216294961"/>
      <size package="4796833" installed="26937822" archive="26950120"/>
      <location href="rpm/ppc/MozillaFirefox-translations-2.0.0.16-0.1.ppc.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="MozillaFirefox-translations" epoch="0" ver="2.0.0.16" rel="0.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="MozillaFirefox-translations"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/ppc/MozillaFirefox-translations-2.0.0.16-0.1.ppc.patch.rpm"/>
          <checksum type="sha">6deb7061467f19f4fbec8c0f52d01cfa70fd03ff</checksum>
          <time file="1216312432" build="1216294961"/>
          <size package="4794415" archive="26912548"/>
          <base-version epoch="0" ver="2.0" rel="30"/>
          <base-version epoch="0" ver="2.0.0.1" rel="0.1"/>
          <base-version epoch="0" ver="2.0.0.10" rel="0.1"/>
          <base-version epoch="0" ver="2.0.0.12" rel="0.1"/>
          <base-version epoch="0" ver="2.0.0.13" rel="0.1"/>
          <base-version epoch="0" ver="2.0.0.14" rel="0.1"/>
          <base-version epoch="0" ver="2.0.0.15" rel="0.1"/>
          <base-version epoch="0" ver="2.0.0.2" rel="1.1"/>
          <base-version epoch="0" ver="2.0.0.4" rel="1.1"/>
          <base-version epoch="0" ver="2.0.0.5" rel="1.1"/>
          <base-version epoch="0" ver="2.0.0.8" rel="1.1"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/ppc/MozillaFirefox-translations-2.0_2.0.0.16-30_0.1.ppc.delta.rpm"/>
          <checksum type="sha">441c5e6dbe0e46d0fab171a6fd5520a6c3f7ab57</checksum>
          <time file="1216312442" build="1216294961"/>
          <size package="283443" archive="0"/>
          <base-version epoch="0" ver="2.0" rel="30" md5sum="34d7847267488cc8c6a5473fc4e9833b" buildtime="1164968665" sequence_info="MozillaFirefox-translations-2.0-30-3c325acd5789eb73819ade6be6f59bbbcc10"/>
        </deltarpm>
        <deltarpm>
          <location href="rpm/ppc/MozillaFirefox-translations-2.0.0.15_2.0.0.16-0.1.ppc.delta.rpm"/>
          <checksum type="sha">d311d62dbed7dd3317e082d49ee33932c1a7a407</checksum>
          <time file="1216312450" build="1216294961"/>
          <size package="46852" archive="0"/>
          <base-version epoch="0" ver="2.0.0.15" rel="0.1" md5sum="f170e3aa87c80a1ba1d8d53a3640ba1d" buildtime="1215528562" sequence_info="MozillaFirefox-translations-2.0.0.15-0.1-f3ca90b07b24901ae7f82d38c4bd284baa10"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>MozillaFirefox-translations</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="2.0.0.16" rel="0.1"/>
      <checksum type="sha" pkgid="YES">8806b061dd7a232ccb02b4ea983c2a226ccd185e</checksum>
      <time file="1216311879" build="1216292106"/>
      <size package="4794483" installed="26937822" archive="26950228"/>
      <location href="rpm/x86_64/MozillaFirefox-translations-2.0.0.16-0.1.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="MozillaFirefox-translations" epoch="0" ver="2.0.0.16" rel="0.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="MozillaFirefox-translations"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/x86_64/MozillaFirefox-translations-2.0.0.16-0.1.x86_64.patch.rpm"/>
          <checksum type="sha">cd187cbebe7c609d02ca5be45e9b774554c8f5f9</checksum>
          <time file="1216312470" build="1216292106"/>
          <size package="4795633" archive="26912556"/>
          <base-version epoch="0" ver="2.0" rel="30"/>
          <base-version epoch="0" ver="2.0.0.1" rel="0.1"/>
          <base-version epoch="0" ver="2.0.0.10" rel="0.1"/>
          <base-version epoch="0" ver="2.0.0.12" rel="0.1"/>
          <base-version epoch="0" ver="2.0.0.13" rel="0.1"/>
          <base-version epoch="0" ver="2.0.0.14" rel="0.1"/>
          <base-version epoch="0" ver="2.0.0.15" rel="0.1"/>
          <base-version epoch="0" ver="2.0.0.2" rel="1.1"/>
          <base-version epoch="0" ver="2.0.0.4" rel="1.1"/>
          <base-version epoch="0" ver="2.0.0.5" rel="1.1"/>
          <base-version epoch="0" ver="2.0.0.8" rel="1.1"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/x86_64/MozillaFirefox-translations-2.0.0.15_2.0.0.16-0.1.x86_64.delta.rpm"/>
          <checksum type="sha">d1f6a4461a5d01b1039841c3a5d93392b9ed9db9</checksum>
          <time file="1216312478" build="1216292106"/>
          <size package="46891" archive="0"/>
          <base-version epoch="0" ver="2.0.0.15" rel="0.1" md5sum="2640c662ee9b15315381c7c3b38b708a" buildtime="1215527364" sequence_info="MozillaFirefox-translations-2.0.0.15-0.1-49958799ea21e224708f21a2a8f8e062aa10"/>
        </deltarpm>
      </pkgfiles>
    </package>
  </atoms>
</patch>
