Product: OpenSolaris

Multiple security vulnerabilities with varying impacts affect Firefox (see firefox(1)) versions prior to 3.5.3 as shipped with OpenSolaris. These vulnerabilities may allow an unprivileged remote user to crash the Firefox application or possibly execute arbitrary code on the system where Firefox is being run, resulting in a Denial of service (DoS). Further vulnerabilities may allow a remote user to mislead a Firefox user into incorrectly trusting a site by providing a URL in the location bar which may appear to be another URL, or to compromise the cryptography features that are active within the browser application.

The following Mozilla advisories describe the vulnerabilities:


The following are the CVE identifiers that pertain to these security issues:

CVE-2009-3069 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3069
CVE-2009-3070 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3070
CVE-2009-3071 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3071
CVE-2009-3072 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3072
CVE-2009-3073 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3073
CVE-2009-3074 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3074
CVE-2009-3075 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3075
CVE-2009-3076 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3076
CVE-2009-3077 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3077
CVE-2009-3078 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3078
CVE-2009-3079 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3079

State: Resolved
First released: 30-Sep-2009
Permalink |

Comments:

Post a Comment:

Comments are closed for this entry.