Summary
The remote host is missing updates announced in
advisory GLSA 200501-03.
Solution
All Mozilla users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose '>=net-www/mozilla-1.7.5'
All Mozilla binary users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose '>=net-www/mozilla-bin-1.7.5'
All Firefox users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose '>=net-www/mozilla-firefox-1.0'
All Firefox binary users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose '>=net-www/mozilla-firefox-bin-1.0'
All Thunderbird users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose
'>=mail-client/mozilla-thunderbird-0.9'
All Thunderbird binary users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose
'>=mail-client/mozilla-thunderbird-bin-0.9'
http://www.securityspace.com/smysecure/catid.html?in=GLSA%20200501-03 http://bugs.gentoo.org/show_bug.cgi?id=76112
http://bugs.gentoo.org/show_bug.cgi?id=68976
http://bugs.gentoo.org/show_bug.cgi?id=70749
http://isec.pl/vulnerabilities/isec-0020-mozilla.txt http://broadcast.ptraced.net/advisories/008-firefox.thunderbird.txt http://secunia.com/advisories/13144/
Insight
Various vulnerabilities were found and fixed in Mozilla-based products, ranging from a potential buffer overflow and temporary files disclosure to anti-spoofing issues.
Severity
Classification
-
CVE CVE-2004-2227, CVE-2004-2228 -
CVSS Base Score: 7.2
AV:L/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities