[SECURITY] Fedora 8 Update: galeon-2.0.4-1.fc8.3
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2008-2682
2008-03-26 16:46:54
--------------------------------------------------------------------------------
Name : galeon
Product : Fedora 8
Version : 2.0.4
Release : 1.fc8.3
URL : http://galeon.sourceforge.net/
Summary : GNOME2 Web browser based on Mozilla
Description :
Galeon is a web browser built around Gecko (Mozilla's rendering
engine) and Necko (Mozilla's networking engine). It's a GNOME web
browser, designed to take advantage of as many GNOME technologies as
makes sense. Galeon was written to do just one thing - browse the web.
--------------------------------------------------------------------------------
Update Information:
Mozilla Firefox is an open source Web browser. Several flaws were found in
the processing of some malformed web content. A web page containing such
malicious content could cause Firefox to crash or, potentially, execute
arbitrary code as the user running Firefox. (CVE-2008-1233, CVE-2008-1235,
CVE-2008-1236, CVE-2008-1237) Several flaws were found in the display of
malformed web content. A web page containing specially-crafted content could,
potentially, trick a Firefox user into surrendering sensitive information.
(CVE-2008-1234, CVE-2008-1238, CVE-2008-1241) All Firefox users should
upgrade to these updated packages, which correct these issues, and are rebuilt
against the update Firefox packages.
--------------------------------------------------------------------------------
ChangeLog:
* Tue Mar 25 2008 Christopher Aillon <caillon(a)redhat.com> - 2.0.4-1.3
- Rebuild against newer gecko
* Fri Feb 8 2008 Christopher Aillon <caillon(a)redhat.com> - 2.0.4-1.2
- Rebuild against newer gecko
* Sun Jan 6 2008 Denis Leroy <denis(a)poolshark.org> - 2.0.4-1.1
- Fixed plugin-wrapper patch
* Sat Dec 15 2007 Denis Leroy <denis(a)poolshark.org> - 2.0.4-1
- Update to upstream 2.0.4
- Some patches integrated upstream, plugin-wrapper patch ported
* Thu Nov 29 2007 Martin Stransky <stransky(a)redhat.com> - 2.0.3-17
- Updated patch for wrapped plugins
* Tue Nov 27 2007 Denis Leroy <denis(a)poolshark.org> - 2.0.3-16
- Rebuild with gecko lib 1.8.1.10
* Mon Nov 19 2007 Martin Stransky <stransky(a)redhat.com> - 2.0.3-15
- Added support for wrapped plugins
* Tue Nov 6 2007 Denis Leroy <denis(a)poolshark.org> - 2.0.3-14
- Rebuild with gecko lib 1.8.1.9
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #438721 - CVE-2008-1237 javascript crashes
https://bugzilla.redhat.com/show_bug.cgi?id=438721
[ 2 ] Bug #438713 - CVE-2008-1233 Mozilla products XPCNativeWrapper pollution
https://bugzilla.redhat.com/show_bug.cgi?id=438713
[ 3 ] Bug #438717 - CVE-2008-1235 chrome privilege via wrong principal
https://bugzilla.redhat.com/show_bug.cgi?id=438717
[ 4 ] Bug #438715 - CVE-2008-1234 universal XSS using event handlers
https://bugzilla.redhat.com/show_bug.cgi?id=438715
[ 5 ] Bug #438718 - CVE-2008-1236 browser engine crashes
https://bugzilla.redhat.com/show_bug.cgi?id=438718
[ 6 ] Bug #438724 - CVE-2008-1238 Referrer spoofing bug
https://bugzilla.redhat.com/show_bug.cgi?id=438724
[ 7 ] Bug #438730 - CVE-2008-1241 XUL popup spoofing
https://bugzilla.redhat.com/show_bug.cgi?id=438730
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update galeon' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
http://fedoraproject.org/keys
--------------------------------------------------------------------------------
16 years, 1 month
[SECURITY] Fedora 8 Update: liferea-1.4.13-2.fc8
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2008-2682
2008-03-26 16:46:54
--------------------------------------------------------------------------------
Name : liferea
Product : Fedora 8
Version : 1.4.13
Release : 2.fc8
URL : http://liferea.sourceforge.net/
Summary : An RSS/RDF feed reader
Description :
Liferea (Linux Feed Reader) is an RSS/RDF feed reader.
It's intended to be a clone of the Windows-only FeedReader.
It can be used to maintain a list of subscribed feeds,
browse through their items, and show their contents.
--------------------------------------------------------------------------------
Update Information:
Mozilla Firefox is an open source Web browser. Several flaws were found in
the processing of some malformed web content. A web page containing such
malicious content could cause Firefox to crash or, potentially, execute
arbitrary code as the user running Firefox. (CVE-2008-1233, CVE-2008-1235,
CVE-2008-1236, CVE-2008-1237) Several flaws were found in the display of
malformed web content. A web page containing specially-crafted content could,
potentially, trick a Firefox user into surrendering sensitive information.
(CVE-2008-1234, CVE-2008-1238, CVE-2008-1241) All Firefox users should
upgrade to these updated packages, which correct these issues, and are rebuilt
against the update Firefox packages.
--------------------------------------------------------------------------------
ChangeLog:
* Tue Mar 25 2008 Christopher Aillon <caillon(a)redhat.com> - 1.4.13-2
- Rebuild against newer gecko
* Mon Mar 17 2008 Marc Wiriadisastra <marc(a)mwiriadi.id.au> - 1.4.13-1
- Updated to latest stable version
* Sat Feb 23 2008 Marc Wiriadisastra <marc(a)mwiriadi.id.au> - 1.4.12-2
- Fixed fedora feed for fedora weekly news
* Wed Feb 20 2008 Marc Wiriadisastra <marc(a)mwiriadi.id.au> - 1.4.12-1
- new version
- builds with gcc4.3
- added firefox-devel and xulrunner-devel for different fedora's
* Fri Feb 8 2008 Christopher Aillon <caillon(a)redhat.com> - 1.4.11-2
- Rebuild against newer gecko
* Thu Jan 17 2008 Brian Pepple <bpepple(a)fedoraproject.org> - 1.4.11-1
- Update to 1.4.11. release fixes news bin crasher. (#429021)
* Wed Dec 19 2007 Brian Pepple <bpepple(a)fedoraproject.org> - 1.4.10-1
- Update to 1.4.10.
- Update feed patch.
* Sun Dec 2 2007 Brian Pepple <bpepple(a)fedoraproject.org> - 1.4.9-1
- Update to 1.4.9.
- Update feed patch.
* Tue Nov 27 2007 Christopher Aillon <caillon(a)redhat.com> - 1.4.8-2
- Rebuild against newer gecko
* Thu Nov 22 2007 Brian Pepple <bpepple(a)fedoraproject.org> - 1.4.8-1
- Update to 1.4.8.
- fixes LD_LIBRARY_PATH security bug. CVE-2006-4791
* Thu Nov 15 2007 Brian Pepple <bpepple(a)fedoraproject.org> - 1.4.7-1
- Update to 1.4.7.
- Drop opml & nm patches. fixed upstream.
- Update fedora feed patch for 1.4.x.
- add BR on sqlite-devel, dbus-devel, dbus-glib-devel, libglade2-devel.
- Don't build gtkhtml2 plugin for now.
* Tue Nov 6 2007 Brian Pepple <bpepple(a)fedoraproject.org> - 1.2.23-6
- Rebuild for new gecko libs.
* Wed Oct 31 2007 Brian Pepple <bpepple(a)fedoraproject.org> - 1.2.23-5
- Add patch to fix opml security bug: CVE-2007-5751. (#360641)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #438721 - CVE-2008-1237 javascript crashes
https://bugzilla.redhat.com/show_bug.cgi?id=438721
[ 2 ] Bug #438713 - CVE-2008-1233 Mozilla products XPCNativeWrapper pollution
https://bugzilla.redhat.com/show_bug.cgi?id=438713
[ 3 ] Bug #438717 - CVE-2008-1235 chrome privilege via wrong principal
https://bugzilla.redhat.com/show_bug.cgi?id=438717
[ 4 ] Bug #438715 - CVE-2008-1234 universal XSS using event handlers
https://bugzilla.redhat.com/show_bug.cgi?id=438715
[ 5 ] Bug #438718 - CVE-2008-1236 browser engine crashes
https://bugzilla.redhat.com/show_bug.cgi?id=438718
[ 6 ] Bug #438724 - CVE-2008-1238 Referrer spoofing bug
https://bugzilla.redhat.com/show_bug.cgi?id=438724
[ 7 ] Bug #438730 - CVE-2008-1241 XUL popup spoofing
https://bugzilla.redhat.com/show_bug.cgi?id=438730
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update liferea' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
http://fedoraproject.org/keys
--------------------------------------------------------------------------------
16 years, 1 month
[SECURITY] Fedora 8 Update: epiphany-extensions-2.20.1-6.fc8
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2008-2682
2008-03-26 16:46:54
--------------------------------------------------------------------------------
Name : epiphany-extensions
Product : Fedora 8
Version : 2.20.1
Release : 6.fc8
URL : http://www.gnome.org/projects/epiphany/extensions
Summary : Extensions for Epiphany, the GNOME web browser
Description :
Epiphany Extensions is a collection of extensions for Epiphany, the
GNOME web browser.
--------------------------------------------------------------------------------
Update Information:
Mozilla Firefox is an open source Web browser. Several flaws were found in
the processing of some malformed web content. A web page containing such
malicious content could cause Firefox to crash or, potentially, execute
arbitrary code as the user running Firefox. (CVE-2008-1233, CVE-2008-1235,
CVE-2008-1236, CVE-2008-1237) Several flaws were found in the display of
malformed web content. A web page containing specially-crafted content could,
potentially, trick a Firefox user into surrendering sensitive information.
(CVE-2008-1234, CVE-2008-1238, CVE-2008-1241) All Firefox users should
upgrade to these updated packages, which correct these issues, and are rebuilt
against the update Firefox packages.
--------------------------------------------------------------------------------
ChangeLog:
* Tue Mar 25 2008 Christopher Aillon <caillon(a)redhat.com> - 2.20.1-6
- Rebuild against newer gecko
* Fri Feb 8 2008 Christopher Aillon <caillon(a)redhat.com> - 2.20.1-5
- Rebuild against newer gecko
* Tue Nov 27 2007 Christopher Aillon <caillon(a)redhat.com> - 2.20.1-3
- Rebuild against newer gecko
* Tue Nov 6 2007 Peter Gordon <peter(a)thecodergeek.com> - 2.20.1-2
- Rebuild for new Gecko (Firefox 2.0.0.9)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #438721 - CVE-2008-1237 javascript crashes
https://bugzilla.redhat.com/show_bug.cgi?id=438721
[ 2 ] Bug #438713 - CVE-2008-1233 Mozilla products XPCNativeWrapper pollution
https://bugzilla.redhat.com/show_bug.cgi?id=438713
[ 3 ] Bug #438717 - CVE-2008-1235 chrome privilege via wrong principal
https://bugzilla.redhat.com/show_bug.cgi?id=438717
[ 4 ] Bug #438715 - CVE-2008-1234 universal XSS using event handlers
https://bugzilla.redhat.com/show_bug.cgi?id=438715
[ 5 ] Bug #438718 - CVE-2008-1236 browser engine crashes
https://bugzilla.redhat.com/show_bug.cgi?id=438718
[ 6 ] Bug #438724 - CVE-2008-1238 Referrer spoofing bug
https://bugzilla.redhat.com/show_bug.cgi?id=438724
[ 7 ] Bug #438730 - CVE-2008-1241 XUL popup spoofing
https://bugzilla.redhat.com/show_bug.cgi?id=438730
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update epiphany-extensions' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
http://fedoraproject.org/keys
--------------------------------------------------------------------------------
16 years, 1 month
[SECURITY] Fedora 8 Update: gtkmozembedmm-1.4.2.cvs20060817-19.fc8
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2008-2682
2008-03-26 16:46:54
--------------------------------------------------------------------------------
Name : gtkmozembedmm
Product : Fedora 8
Version : 1.4.2.cvs20060817
Release : 19.fc8
URL : http://gtkmm.sourceforge.net/
Summary : C++ wrapper for GtkMozembed
Description :
This package provides a C++/gtkmm wrapper for GtkMozEmbed
from Mozilla 1.4.x to 1.7.x.
The wrapper provides a convenient interface for C++ programmers
to use the Gtkmozembed HTML-rendering widget inside their software.
--------------------------------------------------------------------------------
Update Information:
Mozilla Firefox is an open source Web browser. Several flaws were found in
the processing of some malformed web content. A web page containing such
malicious content could cause Firefox to crash or, potentially, execute
arbitrary code as the user running Firefox. (CVE-2008-1233, CVE-2008-1235,
CVE-2008-1236, CVE-2008-1237) Several flaws were found in the display of
malformed web content. A web page containing specially-crafted content could,
potentially, trick a Firefox user into surrendering sensitive information.
(CVE-2008-1234, CVE-2008-1238, CVE-2008-1241) All Firefox users should
upgrade to these updated packages, which correct these issues, and are rebuilt
against the update Firefox packages.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #438721 - CVE-2008-1237 javascript crashes
https://bugzilla.redhat.com/show_bug.cgi?id=438721
[ 2 ] Bug #438713 - CVE-2008-1233 Mozilla products XPCNativeWrapper pollution
https://bugzilla.redhat.com/show_bug.cgi?id=438713
[ 3 ] Bug #438717 - CVE-2008-1235 chrome privilege via wrong principal
https://bugzilla.redhat.com/show_bug.cgi?id=438717
[ 4 ] Bug #438715 - CVE-2008-1234 universal XSS using event handlers
https://bugzilla.redhat.com/show_bug.cgi?id=438715
[ 5 ] Bug #438718 - CVE-2008-1236 browser engine crashes
https://bugzilla.redhat.com/show_bug.cgi?id=438718
[ 6 ] Bug #438724 - CVE-2008-1238 Referrer spoofing bug
https://bugzilla.redhat.com/show_bug.cgi?id=438724
[ 7 ] Bug #438730 - CVE-2008-1241 XUL popup spoofing
https://bugzilla.redhat.com/show_bug.cgi?id=438730
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update gtkmozembedmm' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
http://fedoraproject.org/keys
--------------------------------------------------------------------------------
16 years, 1 month
[SECURITY] Fedora 8 Update: epiphany-2.20.3-2.fc8
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2008-2682
2008-03-26 16:46:54
--------------------------------------------------------------------------------
Name : epiphany
Product : Fedora 8
Version : 2.20.3
Release : 2.fc8
URL : http://www.gnome.org/projects/epiphany/
Summary : GNOME web browser based on the Mozilla rendering engine
Description :
epiphany is a simple GNOME web browser based on the Mozilla rendering
engine.
--------------------------------------------------------------------------------
Update Information:
Mozilla Firefox is an open source Web browser. Several flaws were found in
the processing of some malformed web content. A web page containing such
malicious content could cause Firefox to crash or, potentially, execute
arbitrary code as the user running Firefox. (CVE-2008-1233, CVE-2008-1235,
CVE-2008-1236, CVE-2008-1237) Several flaws were found in the display of
malformed web content. A web page containing specially-crafted content could,
potentially, trick a Firefox user into surrendering sensitive information.
(CVE-2008-1234, CVE-2008-1238, CVE-2008-1241) All Firefox users should
upgrade to these updated packages, which correct these issues, and are rebuilt
against the update Firefox packages.
--------------------------------------------------------------------------------
ChangeLog:
* Tue Mar 25 2008 Christopher Aillon <caillon(a)redhat.com> - 2.20.3-2
- Rebuild against newer gecko
* Sat Mar 8 2008 Christopher Aillon <caillon(a)redhat.com> - 2.20.3-1
- Update to 2.20.3
* Sat Mar 8 2008 Christopher Aillon <caillon(a)redhat.com> - 2.20.2-4
- Update the useragent for Fedora
* Fri Feb 8 2008 Christopher Aillon <caillon(a)redhat.com> - 2.20.2-3
- Rebuild against newer gecko
* Thu Nov 29 2007 Martin Stransky <stransky(a)redhat.com> - 2.20.2-2
- Polished wrapper patch
* Tue Nov 27 2007 Matthias Clasen <mclasen(a)redhat.com> - 2.20.2-1
- Update to 2.20.2
* Tue Nov 27 2007 Christopher Aillon <caillon(a)redhat.com> - 2.20.1-6
- Rebuild against newer gecko
* Mon Nov 19 2007 Martin Stransky <stransky(a)redhat.com> - 2.20.1-5
- Updated wrapper patch
* Mon Nov 5 2007 Martin Stransky <stransky(a)redhat.com> - 2.20.1-4
- Rebuild against new firefox
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #438721 - CVE-2008-1237 javascript crashes
https://bugzilla.redhat.com/show_bug.cgi?id=438721
[ 2 ] Bug #438713 - CVE-2008-1233 Mozilla products XPCNativeWrapper pollution
https://bugzilla.redhat.com/show_bug.cgi?id=438713
[ 3 ] Bug #438717 - CVE-2008-1235 chrome privilege via wrong principal
https://bugzilla.redhat.com/show_bug.cgi?id=438717
[ 4 ] Bug #438715 - CVE-2008-1234 universal XSS using event handlers
https://bugzilla.redhat.com/show_bug.cgi?id=438715
[ 5 ] Bug #438718 - CVE-2008-1236 browser engine crashes
https://bugzilla.redhat.com/show_bug.cgi?id=438718
[ 6 ] Bug #438724 - CVE-2008-1238 Referrer spoofing bug
https://bugzilla.redhat.com/show_bug.cgi?id=438724
[ 7 ] Bug #438730 - CVE-2008-1241 XUL popup spoofing
https://bugzilla.redhat.com/show_bug.cgi?id=438730
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update epiphany' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
http://fedoraproject.org/keys
--------------------------------------------------------------------------------
16 years, 1 month
[SECURITY] Fedora 8 Update: yelp-2.20.0-8.fc8
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2008-2682
2008-03-26 16:46:54
--------------------------------------------------------------------------------
Name : yelp
Product : Fedora 8
Version : 2.20.0
Release : 8.fc8
URL : http://live.gnome.org/Yelp
Summary : A system documentation reader from the Gnome project
Description :
Yelp is the Gnome 2 help/documentation browser. It is designed
to help you browse all the documentation on your system in
one central tool.
--------------------------------------------------------------------------------
Update Information:
Mozilla Firefox is an open source Web browser. Several flaws were found in
the processing of some malformed web content. A web page containing such
malicious content could cause Firefox to crash or, potentially, execute
arbitrary code as the user running Firefox. (CVE-2008-1233, CVE-2008-1235,
CVE-2008-1236, CVE-2008-1237) Several flaws were found in the display of
malformed web content. A web page containing specially-crafted content could,
potentially, trick a Firefox user into surrendering sensitive information.
(CVE-2008-1234, CVE-2008-1238, CVE-2008-1241) All Firefox users should
upgrade to these updated packages, which correct these issues, and are rebuilt
against the update Firefox packages.
--------------------------------------------------------------------------------
ChangeLog:
* Tue Mar 25 2008 Christopher Aillon <caillon(a)redhat.com> - 2.20.0-8
- Rebuild against newer gecko
* Fri Feb 8 2008 Christopher Aillon <caillon(a)redhat.com> - 2.20.0-7
- Rebuild against newer gecko
* Tue Nov 27 2007 Christopher Aillon <caillon(a)redhat.com> - 2.20.0-6
- Rebuild against newer gecko
* Mon Nov 5 2007 Matthias Clasen <mclasen(a)redhat.com> - 2.20.0-5
- Fix a crash in search (#361041)
* Mon Nov 5 2007 Martin Stransky <stransky(a)redhat.com> - 2.20.0-4
- Rebuild against new firefox
* Sun Nov 4 2007 Matthias Clasen <mclasen(a)redhat.com> - 2.20.0-3
- Fix a crash when loading the rarian docs
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #438721 - CVE-2008-1237 javascript crashes
https://bugzilla.redhat.com/show_bug.cgi?id=438721
[ 2 ] Bug #438713 - CVE-2008-1233 Mozilla products XPCNativeWrapper pollution
https://bugzilla.redhat.com/show_bug.cgi?id=438713
[ 3 ] Bug #438717 - CVE-2008-1235 chrome privilege via wrong principal
https://bugzilla.redhat.com/show_bug.cgi?id=438717
[ 4 ] Bug #438715 - CVE-2008-1234 universal XSS using event handlers
https://bugzilla.redhat.com/show_bug.cgi?id=438715
[ 5 ] Bug #438718 - CVE-2008-1236 browser engine crashes
https://bugzilla.redhat.com/show_bug.cgi?id=438718
[ 6 ] Bug #438724 - CVE-2008-1238 Referrer spoofing bug
https://bugzilla.redhat.com/show_bug.cgi?id=438724
[ 7 ] Bug #438730 - CVE-2008-1241 XUL popup spoofing
https://bugzilla.redhat.com/show_bug.cgi?id=438730
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update yelp' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
http://fedoraproject.org/keys
--------------------------------------------------------------------------------
16 years, 1 month
[SECURITY] Fedora 8 Update: Miro-1.1.2-2.fc8
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2008-2682
2008-03-26 16:46:54
--------------------------------------------------------------------------------
Name : Miro
Product : Fedora 8
Version : 1.1.2
Release : 2.fc8
URL : http://www.getmiro.com/
Summary : Miro - Internet TV Player
Description :
Miro is a free application that turns your computer into an
internet TV video player. This release is still a beta version, which means
that there are some bugs, but we're moving quickly to fix them and will be
releasing bug fixes on a regular basis.
--------------------------------------------------------------------------------
Update Information:
Mozilla Firefox is an open source Web browser. Several flaws were found in
the processing of some malformed web content. A web page containing such
malicious content could cause Firefox to crash or, potentially, execute
arbitrary code as the user running Firefox. (CVE-2008-1233, CVE-2008-1235,
CVE-2008-1236, CVE-2008-1237) Several flaws were found in the display of
malformed web content. A web page containing specially-crafted content could,
potentially, trick a Firefox user into surrendering sensitive information.
(CVE-2008-1234, CVE-2008-1238, CVE-2008-1241) All Firefox users should
upgrade to these updated packages, which correct these issues, and are rebuilt
against the update Firefox packages.
--------------------------------------------------------------------------------
ChangeLog:
* Tue Mar 25 2008 Christopher Aillon <caillon(a)redhat.com> 1.1.2-2
- Rebuild against newer gecko
* Tue Mar 11 2008 Alex Lancaster <alexlan[AT]fedoraproject org> - 1.1.2-1
- Update to upstream 1.1.2 release
* Fri Feb 8 2008 Christopher Aillon <caillon(a)redhat.com> 1.1-3
- Rebuild against newer gecko
* Fri Jan 25 2008 Michel Salim <michel.sylvan(a)gmail.com> - 1.1-2
- Fix charset mismatch in download window
- Remove shebangs from scripts
- Sanitize end-of-line markers
* Thu Jan 17 2008 Alex Lancaster <alexlan[AT]fedoraproject org> - 1.1-1
- Update to upstream 1.1 release
- Add BuildRequires: openssl-devel
* Mon Nov 26 2007 Alex Lancaster <alexlan[AT]fedoraproject org> 1.0-2
- Build against gecko-libs 1.8.1.10 (firefox 2.0.0.10)
* Fri Nov 16 2007 Alex Lancaster <alexlan[AT]fedoraproject org> 1.0-1
- Update to latest upstream (1.0).
* Fri Nov 9 2007 Alex Lancaster <alexlan[AT]fedoraproject org> 0.9.9.9-1
- Update to latest upstream (0.9.9.9)
- Build against gecko-libs 1.8.1.9 (firefox 2.0.0.9)
- Include xine_extractor in package (thanks to Jason Farrell)
- Drop Miro-setup.py.patch
* Thu Nov 1 2007 Alex Lancaster <alexlan[AT]fedoraproject org> 0.9.9.1-6
- Update patch with workaround suggested on:
http://bugzilla.pculture.org/show_bug.cgi?id=8579
* Wed Oct 31 2007 Alex Lancaster <alexlan[AT]fedoraproject org> 0.9.9.1-5
- Add setup.py patch to ignore call to svn.
* Tue Oct 30 2007 Alex Lancaster <alexlan[AT]fedoraproject org> 0.9.9.1-3
- Add BuildRequires: libXv-devel
- Drop dbus patch
* Sun Oct 28 2007 Alex Lancaster <alexlan[AT]fedoraproject org> 0.9.9.1-1
- Update to latest upstream (0.9.9.1)
* Fri Oct 26 2007 Alex Lancaster <alexlan[AT]fedoraproject org> 0.9.8.1-8
- Replace Requires and BuildRequires for firefox with gecko to
smooth eventual xulrunner transition
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #438721 - CVE-2008-1237 javascript crashes
https://bugzilla.redhat.com/show_bug.cgi?id=438721
[ 2 ] Bug #438713 - CVE-2008-1233 Mozilla products XPCNativeWrapper pollution
https://bugzilla.redhat.com/show_bug.cgi?id=438713
[ 3 ] Bug #438717 - CVE-2008-1235 chrome privilege via wrong principal
https://bugzilla.redhat.com/show_bug.cgi?id=438717
[ 4 ] Bug #438715 - CVE-2008-1234 universal XSS using event handlers
https://bugzilla.redhat.com/show_bug.cgi?id=438715
[ 5 ] Bug #438718 - CVE-2008-1236 browser engine crashes
https://bugzilla.redhat.com/show_bug.cgi?id=438718
[ 6 ] Bug #438724 - CVE-2008-1238 Referrer spoofing bug
https://bugzilla.redhat.com/show_bug.cgi?id=438724
[ 7 ] Bug #438730 - CVE-2008-1241 XUL popup spoofing
https://bugzilla.redhat.com/show_bug.cgi?id=438730
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update Miro' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
http://fedoraproject.org/keys
--------------------------------------------------------------------------------
16 years, 1 month
[SECURITY] Fedora 8 Update: gnome-python2-extras-2.19.1-13.fc8
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2008-2682
2008-03-26 16:46:54
--------------------------------------------------------------------------------
Name : gnome-python2-extras
Product : Fedora 8
Version : 2.19.1
Release : 13.fc8
URL : http://www.pygtk.org/
Summary : The sources for additional. PyGNOME Python extension modules.
Description :
The gnome-python-extra package contains the source packages for additional
Python bindings for GNOME. It should be used together with gnome-python.
--------------------------------------------------------------------------------
Update Information:
Mozilla Firefox is an open source Web browser. Several flaws were found in
the processing of some malformed web content. A web page containing such
malicious content could cause Firefox to crash or, potentially, execute
arbitrary code as the user running Firefox. (CVE-2008-1233, CVE-2008-1235,
CVE-2008-1236, CVE-2008-1237) Several flaws were found in the display of
malformed web content. A web page containing specially-crafted content could,
potentially, trick a Firefox user into surrendering sensitive information.
(CVE-2008-1234, CVE-2008-1238, CVE-2008-1241) All Firefox users should
upgrade to these updated packages, which correct these issues, and are rebuilt
against the update Firefox packages.
--------------------------------------------------------------------------------
ChangeLog:
* Tue Mar 25 2008 Christopher Aillon <caillon(a)redhat.com> - 2.19.1-13
- Rebuild against newer gecko
* Fri Feb 8 2008 Christopher Aillon <caillon(a)redhat.com> - 2.19.1-12
- Rebuild against newer gecko
* Tue Nov 27 2007 Christopher Aillon <caillon(a)redhat.com> - 2.19.1-11
- Rebuild against newer gecko
* Sat Nov 10 2007 Alex Lancaster <alexl(a)users.sourceforge.net> - 2.19.1-10.fc8
- Rebuild against gecko-libs 1.8.1.9
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #438721 - CVE-2008-1237 javascript crashes
https://bugzilla.redhat.com/show_bug.cgi?id=438721
[ 2 ] Bug #438713 - CVE-2008-1233 Mozilla products XPCNativeWrapper pollution
https://bugzilla.redhat.com/show_bug.cgi?id=438713
[ 3 ] Bug #438717 - CVE-2008-1235 chrome privilege via wrong principal
https://bugzilla.redhat.com/show_bug.cgi?id=438717
[ 4 ] Bug #438715 - CVE-2008-1234 universal XSS using event handlers
https://bugzilla.redhat.com/show_bug.cgi?id=438715
[ 5 ] Bug #438718 - CVE-2008-1236 browser engine crashes
https://bugzilla.redhat.com/show_bug.cgi?id=438718
[ 6 ] Bug #438724 - CVE-2008-1238 Referrer spoofing bug
https://bugzilla.redhat.com/show_bug.cgi?id=438724
[ 7 ] Bug #438730 - CVE-2008-1241 XUL popup spoofing
https://bugzilla.redhat.com/show_bug.cgi?id=438730
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update gnome-python2-extras' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
http://fedoraproject.org/keys
--------------------------------------------------------------------------------
16 years, 1 month
[SECURITY] Fedora 8 Update: ruby-gnome2-0.16.0-21.fc8
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2008-2682
2008-03-26 16:46:54
--------------------------------------------------------------------------------
Name : ruby-gnome2
Product : Fedora 8
Version : 0.16.0
Release : 21.fc8
URL : http://ruby-gnome2.sourceforge.jp/
Summary : Ruby binding of libgnome/libgnomeui-2.x
Description :
This is a set of bindings for the GNOME-2.x libraries for use from Ruby.
--------------------------------------------------------------------------------
Update Information:
Mozilla Firefox is an open source Web browser. Several flaws were found in
the processing of some malformed web content. A web page containing such
malicious content could cause Firefox to crash or, potentially, execute
arbitrary code as the user running Firefox. (CVE-2008-1233, CVE-2008-1235,
CVE-2008-1236, CVE-2008-1237) Several flaws were found in the display of
malformed web content. A web page containing specially-crafted content could,
potentially, trick a Firefox user into surrendering sensitive information.
(CVE-2008-1234, CVE-2008-1238, CVE-2008-1241) All Firefox users should
upgrade to these updated packages, which correct these issues, and are rebuilt
against the update Firefox packages.
--------------------------------------------------------------------------------
ChangeLog:
* Tue Mar 25 2008 Christopher Aillon <caillon(a)redhat.com> 0.16.0-21
- Rebuild against newer gecko
* Fri Feb 8 2008 Christopher Aillon <caillon(a)redhat.com> 0.16.0-20
- Rebuild against newer gecko
* Sat Jan 26 2008 Allisson Azevedo <allisson(a)gmail.com> 0.16.0-19
- Fix libglade2 Undefined method error (bugzilla #428781)
* Tue Dec 4 2007 Allisson Azevedo <allisson(a)gmail.com> 0.16.0-18
- Fix CVE-2007-6183, format string vulnerability (bugzilla #402871)
* Tue Nov 27 2007 Christopher Aillon <caillon(a)redhat.com> 0.16.0-17
- Rebuild against newer gecko
* Tue Nov 13 2007 Alex Lancaster <alexl(a)users.sourceforge.net> 0.16.0-16
- Fix my typo in BuildRequires
* Tue Nov 13 2007 Alex Lancaster <alexl(a)users.sourceforge.net> 0.16.0-15
- Rebuild against gecko-libs and gecko-devel (firefox 2.0.0.9).
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #438721 - CVE-2008-1237 javascript crashes
https://bugzilla.redhat.com/show_bug.cgi?id=438721
[ 2 ] Bug #438713 - CVE-2008-1233 Mozilla products XPCNativeWrapper pollution
https://bugzilla.redhat.com/show_bug.cgi?id=438713
[ 3 ] Bug #438717 - CVE-2008-1235 chrome privilege via wrong principal
https://bugzilla.redhat.com/show_bug.cgi?id=438717
[ 4 ] Bug #438715 - CVE-2008-1234 universal XSS using event handlers
https://bugzilla.redhat.com/show_bug.cgi?id=438715
[ 5 ] Bug #438718 - CVE-2008-1236 browser engine crashes
https://bugzilla.redhat.com/show_bug.cgi?id=438718
[ 6 ] Bug #438724 - CVE-2008-1238 Referrer spoofing bug
https://bugzilla.redhat.com/show_bug.cgi?id=438724
[ 7 ] Bug #438730 - CVE-2008-1241 XUL popup spoofing
https://bugzilla.redhat.com/show_bug.cgi?id=438730
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update ruby-gnome2' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
http://fedoraproject.org/keys
--------------------------------------------------------------------------------
16 years, 1 month
Fedora 8 Update: perl-5.8.8-38.fc8
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2008-2580
2008-03-26 16:46:40
--------------------------------------------------------------------------------
Name : perl
Product : Fedora 8
Version : 5.8.8
Release : 38.fc8
URL : http://www.perl.org/
Summary : The Perl programming language
Description :
Perl is a high-level programming language with roots in C, sed, awk
and shell scripting. Perl is good at handling processes and files,
and is especially good at handling text. Perl's hallmarks are
practicality and efficiency. While it is used to do a lot of
different things, Perl's most common applications are system
administration utilities and web programming. A large proportion of
the CGI scripts on the web are written in Perl. You need the perl
package installed on your system so that your system can handle Perl
scripts.
Install this package if you want to program in Perl or enable your
system to handle Perl scripts.
--------------------------------------------------------------------------------
Update Information:
New Test::Simple. Saver way to handle gethostbyname in Socket module. And
updated CGI module, which fixes the broken upload method.
--------------------------------------------------------------------------------
ChangeLog:
* Wed Mar 19 2008 Marcela Maslanova <mmaslano(a)redhat.com> - 4:5.8.8-38
- 434865 upgrade Test::Simple
- turn off test on loading Dummy in More.t, can't find module (path problem?)
- 238581: careless use of gethostbyname() in Socket.xs
* Thu Mar 13 2008 Marcela Maslanova <mmaslano(a)redhat.com> - 4:5.8.8-37
- update CGI, because of broken upload method #431774
* Fri Feb 29 2008 Marcela Maslanova <mmaslano(a)redhat.com> - 4:5.8.8-36
- remove conflicts perl-File-Temp. Use obsoletes.
* Fri Feb 29 2008 Marcela Maslanova <mmaslano(a)redhat.com> - 4:5.8.8-35
- upgrade Scalar::Util - possible fix for many bugs. Packages dependent on
this module could work even with use of CPAN modules.
-
- Fri Feb 22 2008 Stepan Kasal <skasal(a)redhat.com>
- make the obsoletes versioned
- add conflict with any version of perl-File-Temp
- escape the macros in Jan 31 entry
* Mon Feb 18 2008 Bill McGonigle <bill(a)bfccomputing.com> - 4:5.8.8-34
- add perl-File-Temp provides/obsolete
- Resolves: rhbz#433836
* Thu Jan 31 2008 Tom "spot" Callaway <tcallawa(a)redhat.com> - 4:5.8.8-33
- create %{_prefix}/lib/perl5/vendor_perl/%{perl_version}/auto and own it
in base perl (resolves bugzilla 214580)
* Mon Nov 26 2007 Tom "spot" Callaway <tcallawa(a)redhat.com> - 4:5.8.8-32
- break dep loop, fix bugzilla 397881
* Mon Nov 12 2007 Tom "spot" Callaway <tcallawa(a)redhat.com> - 4:5.8.8-31
- fix for CVE-2007-5116
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #434865 - Upgrade Request for Perl Module Test::Simple
https://bugzilla.redhat.com/show_bug.cgi?id=434865
[ 2 ] Bug #238581 - careless use of gethostbyname() in Socket.xs
https://bugzilla.redhat.com/show_bug.cgi?id=238581
[ 3 ] Bug #431774 - CGI.pm Version 3.15 Contains Broken File Upload Method
https://bugzilla.redhat.com/show_bug.cgi?id=431774
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update perl' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
http://fedoraproject.org/keys
--------------------------------------------------------------------------------
16 years, 1 month