From 0a28894d82938443f35eb1fd018a11f6f4d602c3 Mon Sep 17 00:00:00 2001 From: Joey Hess Date: Tue, 13 Sep 2005 18:16:29 +0000 Subject: releasing dtsa 14 git-svn-id: svn+ssh://svn.debian.org/svn/secure-testing@1957 e39458fd-73e7-0310-bf30-c45bca0a0e42 --- website/DTSA/DTSA-14-1.html | 149 ++++++++++++++++++++++++++++++++++++++++++++ website/list.html | 2 + 2 files changed, 151 insertions(+) create mode 100644 website/DTSA/DTSA-14-1.html (limited to 'website') diff --git a/website/DTSA/DTSA-14-1.html b/website/DTSA/DTSA-14-1.html new file mode 100644 index 0000000000..28c847c0cf --- /dev/null +++ b/website/DTSA/DTSA-14-1.html @@ -0,0 +1,149 @@ + + + Debian testing security team - Advisory + + + + +
+ + + + + Debian Project +
+
+ + + + + + + + + + + +
+ Debian testing security team - Advisory +
+ + +
+ + +

DTSA-14-1

+
+
Date Reported:
+
September 13th, 2005
+
Affected Package:
+
mozilla
+
Vulnerability:
+
several
+
Problem-Scope:
+
remote
+
Debian-specific:
+
No
+
CVE:
+
+CAN-2004-0718 +CAN-2005-1937 +CAN-2005-2260 +CAN-2005-2261 +CAN-2005-2263 +CAN-2005-2265 +CAN-2005-2266 +CAN-2005-2268 +CAN-2005-2269 +CAN-2005-2270 +
+
More information:
+
Several problems have been discovered in Mozilla. Since the usual praxis of 
+backporting apparently does not work for this package, this update is 
+basically version 1.7.10 with the version number rolled back, and hence still 
+named 1.7.8. The Common Vulnerabilities and Exposures project identifies the 
+following problems: 

+CAN-2004-0718, CAN-2005-1937 

+A vulnerability has been discovered in Mozilla that allows remote 
+attackers to inject arbitrary Javascript from one page into the 
+frameset of another site. 

+CAN-2005-2260 

+The browser user interface does not properly distinguish between 
+user-generated events and untrusted synthetic events, which makes 
+it easier for remote attackers to perform dangerous actions that 
+normally could only be performed manually by the user. 

+CAN-2005-2261 

+XML scripts ran even when Javascript disabled. 

+CAN-2005-2263 

+It is possible for a remote attacker to execute a callback 
+function in the context of another domain (i.e. frame). 

+CAN-2005-2265 

+Missing input sanitising of InstallVersion.compareTo() can cause 
+the application to crash. 

+CAN-2005-2266 

+Remote attackers could steal sensitive information such as cookies 
+and passwords from web sites by accessing data in alien frames. 

+CAN-2005-2268 

+It is possible for a Javascript dialog box to spoof a dialog box 
+from a trusted site and facilitates phishing attacks. 

+CAN-2005-2269 

+Remote attackers could modify certain tag properties of DOM nodes 
+that could lead to the execution of arbitrary script or code. 

+CAN-2005-2270 

+The Mozilla browser family does not properly clone base objects, 
+which allows remote attackers to execute arbitrary code. 

+Note that this is the same update contained in DSA-810-1 for Debian stable. 
+
+
For the testing distribution (etch) this is fixed in version 1.7.8-1sarge2
+
For the unstable distribution (sid) this is fixed in version 1.7.10-1
+
This upgrade is recommended if you use mozilla.
+
If you have the secure testing lines in your sources.list, you can update by running this command as root:
+ +
apt-get update && apt-get install mozilla
+
+ +
+
To use the Debian testing security archive, add the following lines to your /etc/apt/sources.list:
+
+
deb http://secure-testing-mirrors.debian.net/debian-secure-testing etch-proposed-updates/security-updates main contrib non-free
+
deb-src http://secure-testing-mirrors.debian.net/debian-secure-testing etch-proposed-updates/security-updates main contrib non-free
+
+
The archive signing key can be downloaded from
+
http://secure-testing.debian.net/ziyi-2005-7.asc
+ +
+ + +
+ + Valid HTML 4.01! + + Valid CSS! + + + + diff --git a/website/list.html b/website/list.html index f848faea16..3ccdcd5c84 100644 --- a/website/list.html +++ b/website/list.html @@ -63,6 +63,8 @@
modeline exploits
[September 8th, 2005] DTSA-13-1 evolution
format string vulnerabilities
+
[September 13th, 2005] DTSA-14-1 mozilla
+
several

-- cgit v1.2.3