--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2008-8399
2008-09-27 03:03:19
--------------------------------------------------------------------------------
Name : Miro
Product : Fedora 8
Version : 1.2.3
Release : 4.fc8
URL : http://www.getmiro.com/
Summary : Miro - Internet TV Player
Description :
Miro is a free application that turns your computer into an
internet TV video player. This release is still a beta version, which means
that there are some bugs, but we're moving quickly to fix them and will be
releasing bug fixes on a regular basis.
--------------------------------------------------------------------------------
Update Information:
Mozilla Firefox is an open source Web browser. Several flaws were found in
the processing of malformed web content. A web page containing malicious content
could cause Firefox to crash or, potentially, execute arbitrary code as the user
running Firefox. (CVE-2008-4058, CVE-2008-4060, CVE-2008-4061, CVE-2008-4062,
CVE-2008-4063, CVE-2008-4064) Several flaws were found in the way malformed
web content was displayed. A web page containing specially crafted content could
potentially trick a Firefox user into surrendering sensitive information.
(CVE-2008-4067, CVE-2008-4068) A flaw was found in the way Firefox handles
mouse click events. A web page containing specially crafted JavaScript code
could move the content window while a mouse-button was pressed, causing any item
under the pointer to be dragged. This could, potentially, cause the user to
perform an unsafe drag-and-drop action. (CVE-2008-3837) A flaw was found in
Firefox that caused certain characters to be stripped from JavaScript code. This
flaw could allow malicious JavaScript to bypass or evade script filters.
(CVE-2008-4065) For technical details regarding these flaws, please see the
Mozilla security advisories for Firefox 3.0.2.[1] All Firefox users should
upgrade to these updated packages, which contain patches that correct these
issues. [1] http://www.mozilla.org/security/known-
vulnerabilities/firefox30.html#firefox3.0.2
--------------------------------------------------------------------------------
ChangeLog:
* Tue Sep 23 2008 Christopher Aillon <caillon(a)redhat.com> - 1.2.3-4
- Rebuild against newer gecko
* Tue Jul 15 2008 Christopher Aillon <caillon(a)redhat.com> - 1.2.3-3
- Rebuild against newer gecko
* Wed Jul 2 2008 Christopher Aillon <caillon(a)redhat.com> - 1.2.3-2
- Rebuild against newer gecko
* Tue Apr 29 2008 Alex Lancaster <alexlan[AT]fedoraproject org> - 1.2.3-1
- Update to new upstream release (1.2.3)
* Wed Apr 16 2008 Christopher Aillon <caillon(a)redhat.com> - 1.2-2
- Rebuild against newer gecko
* Sat Mar 29 2008 Alex Lancaster <alexlan[AT]fedoraproject org> - 1.2-1
- Update to latest upstream (1.2)
* Tue Mar 25 2008 Christopher Aillon <caillon(a)redhat.com> 1.1.2-2
- Rebuild against newer gecko
* Tue Mar 11 2008 Alex Lancaster <alexlan[AT]fedoraproject org> - 1.1.2-1
- Update to upstream 1.1.2 release
* Fri Feb 8 2008 Christopher Aillon <caillon(a)redhat.com> 1.1-3
- Rebuild against newer gecko
* Fri Jan 25 2008 Michel Salim <michel.sylvan(a)gmail.com> - 1.1-2
- Fix charset mismatch in download window
- Remove shebangs from scripts
- Sanitize end-of-line markers
* Thu Jan 17 2008 Alex Lancaster <alexlan[AT]fedoraproject org> - 1.1-1
- Update to upstream 1.1 release
- Add BuildRequires: openssl-devel
* Mon Nov 26 2007 Alex Lancaster <alexlan[AT]fedoraproject org> 1.0-2
- Build against gecko-libs 1.8.1.10 (firefox 2.0.0.10)
* Fri Nov 16 2007 Alex Lancaster <alexlan[AT]fedoraproject org> 1.0-1
- Update to latest upstream (1.0).
* Fri Nov 9 2007 Alex Lancaster <alexlan[AT]fedoraproject org> 0.9.9.9-1
- Update to latest upstream (0.9.9.9)
- Build against gecko-libs 1.8.1.9 (firefox 2.0.0.9)
- Include xine_extractor in package (thanks to Jason Farrell)
- Drop Miro-setup.py.patch
* Thu Nov 1 2007 Alex Lancaster <alexlan[AT]fedoraproject org> 0.9.9.1-6
- Update patch with workaround suggested on:
http://bugzilla.pculture.org/show_bug.cgi?id=8579
* Wed Oct 31 2007 Alex Lancaster <alexlan[AT]fedoraproject org> 0.9.9.1-5
- Add setup.py patch to ignore call to svn.
* Tue Oct 30 2007 Alex Lancaster <alexlan[AT]fedoraproject org> 0.9.9.1-3
- Add BuildRequires: libXv-devel
- Drop dbus patch
* Sun Oct 28 2007 Alex Lancaster <alexlan[AT]fedoraproject org> 0.9.9.1-1
- Update to latest upstream (0.9.9.1)
* Fri Oct 26 2007 Alex Lancaster <alexlan[AT]fedoraproject org> 0.9.8.1-8
- Replace Requires and BuildRequires for firefox with gecko to
smooth eventual xulrunner transition
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update Miro' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
http://fedoraproject.org/keys
--------------------------------------------------------------------------------
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2008-8399
2008-09-27 03:03:19
--------------------------------------------------------------------------------
Name : openvrml
Product : Fedora 8
Version : 0.17.8
Release : 2.0.fc8
URL : http://openvrml.org
Summary : VRML/X3D runtime library
Description :
OpenVRML is a VRML/X3D support library, including a runtime and facilities
for reading and displaying VRML and X3D models.
--------------------------------------------------------------------------------
Update Information:
Mozilla Firefox is an open source Web browser. Several flaws were found in
the processing of malformed web content. A web page containing malicious content
could cause Firefox to crash or, potentially, execute arbitrary code as the user
running Firefox. (CVE-2008-4058, CVE-2008-4060, CVE-2008-4061, CVE-2008-4062,
CVE-2008-4063, CVE-2008-4064) Several flaws were found in the way malformed
web content was displayed. A web page containing specially crafted content could
potentially trick a Firefox user into surrendering sensitive information.
(CVE-2008-4067, CVE-2008-4068) A flaw was found in the way Firefox handles
mouse click events. A web page containing specially crafted JavaScript code
could move the content window while a mouse-button was pressed, causing any item
under the pointer to be dragged. This could, potentially, cause the user to
perform an unsafe drag-and-drop action. (CVE-2008-3837) A flaw was found in
Firefox that caused certain characters to be stripped from JavaScript code. This
flaw could allow malicious JavaScript to bypass or evade script filters.
(CVE-2008-4065) For technical details regarding these flaws, please see the
Mozilla security advisories for Firefox 3.0.2.[1] All Firefox users should
upgrade to these updated packages, which contain patches that correct these
issues. [1] http://www.mozilla.org/security/known-
vulnerabilities/firefox30.html#firefox3.0.2
--------------------------------------------------------------------------------
ChangeLog:
* Tue Sep 23 2008 Christopher Aillon <caillon(a)redhat.com> - 0.17.8-2.0
- Rebuild against newer gecko
* Wed Aug 13 2008 Braden McDaniel <braden(a)endoframe.com>
- Build with -Wno-missing-braces.
* Wed Aug 13 2008 Braden McDaniel <braden(a)endoframe.com> - 0.17.8-1.0
- Updated to 0.17.8.
* Tue Aug 12 2008 Braden McDaniel <braden(a)endoframe.com> - 0.17.7-1.0
- Updated to 0.17.7.
* Tue Aug 12 2008 Braden McDaniel <braden(a)endoframe.com> - 0.17.6-7.0
- Change to x.y convention for the Release number to satisfy Fedora
packaging scripts.
* Tue Jul 15 2008 Christopher Aillon <caillon(a)redhat.com> - 0.17.6-6
- Rebuild against newer gecko
* Mon Jul 7 2008 Braden McDaniel <braden(a)endoframe.com> - 0.17.6-5
- gcc visibility flags are still a problem for firefox headers on F8.
* Sun Jul 6 2008 Braden McDaniel <braden(a)endoframe.com> - 0.17.6-4
- Rebuild after updating gecko-libs requirement.
* Wed Jul 2 2008 Christopher Aillon <caillon(a)redhat.com> - 0.17.6-3
- Rebuild against newer gecko
* Sun Jun 22 2008 Braden McDaniel <braden(a)endoframe.com> - 0.17.6-2
- Make symbols for libglade callbacks in openvrml-player visible.
* Fri Jun 20 2008 Braden McDaniel <braden(a)endoframe.com> - 0.17.6-1
- Updated to 0.17.6.
- Build with -fvisibility=hidden -fvisibility-inlines-hidden
* Wed Apr 16 2008 Christopher Aillon <caillon(a)redhat.com> - 0.17.5-5
- Rebuild against newer gecko
* Tue Mar 25 2008 Christopher Aillon <caillon(a)redhat.com> - 0.17.5-4
- Rebuild against newer gecko
* Mon Mar 17 2008 Braden McDaniel <braden(a)endoframe.com> - 0.17.5-3
- Patch for crash in openvrml-xembed (bug 437611).
* Fri Feb 8 2008 Christopher Aillon <caillon(a)redhat.com> - 0.17.5-2
- Rebuild against newer gecko
* Tue Feb 5 2008 Braden McDaniel <braden(a)endoframe.com> - 0.17.5-1
- Updated to 0.17.5.
- Added --enable-gecko-rpath.
* Sat Jan 26 2008 Braden McDaniel <braden(a)endoframe.com> - 0.17.4-1
- Updated to 0.17.4.
* Thu Jan 17 2008 Braden McDaniel <braden(a)endoframe.com> - 0.17.3-1
- Updated to 0.17.3.
* Wed Jan 9 2008 Braden McDaniel <braden(a)endoframe.com> - 0.17.2-1
- Updated to 0.17.2.
* Sun Jan 6 2008 Braden McDaniel <braden(a)endoframe.com> - 0.17.1-1
- Updated to 0.17.1.
* Wed Dec 19 2007 Braden McDaniel <braden(a)endoframe.com> - 0.17.0-2
- Removed %check. The "browser" test fails on ppc due to what looks
like a probable compiler bug.
* Wed Dec 19 2007 Braden McDaniel <braden(a)endoframe.com> - 0.17.0-1
- Updated to 0.17.0
- Changed license to LGPLv3+/GPLv3+ per OpenVRML 0.17.0 change.
* Tue Nov 27 2007 Braden McDaniel <braden(a)endoframe.com> - 0.16.7-2
- Updated gecko-libs dependency to 1.8.1.10.
* Thu Nov 15 2007 Braden McDaniel <braden(a)endoframe.com> - 0.16.7-1
- Updated to 0.16.7.
- Changed build prerequisite from firefox-devel to gecko-devel.
- Changed openvrml-xembed to require gecko-libs instead of firefox.
* Fri Nov 9 2007 Braden McDaniel <braden(a)endoframe.com> - 0.16.6-8
- Backed out inadvertent change.
* Fri Nov 9 2007 Braden McDaniel <braden(a)endoframe.com> - 0.16.6-7
- Updated firefox dependency to 2.0.0.9.
* Fri Oct 26 2007 Braden McDaniel <braden(a)endoframe.com>
- Updated license tags to LGPLv2+, GPLv2+.
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update openvrml' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
http://fedoraproject.org/keys
--------------------------------------------------------------------------------
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2008-8399
2008-09-27 03:03:19
--------------------------------------------------------------------------------
Name : ruby-gnome2
Product : Fedora 8
Version : 0.17.0
Release : 2.fc8
URL : http://ruby-gnome2.sourceforge.jp/
Summary : Ruby binding of libgnome/libgnomeui-2.x
Description :
This is a set of bindings for the GNOME-2.x libraries for use from Ruby.
--------------------------------------------------------------------------------
Update Information:
Mozilla Firefox is an open source Web browser. Several flaws were found in
the processing of malformed web content. A web page containing malicious content
could cause Firefox to crash or, potentially, execute arbitrary code as the user
running Firefox. (CVE-2008-4058, CVE-2008-4060, CVE-2008-4061, CVE-2008-4062,
CVE-2008-4063, CVE-2008-4064) Several flaws were found in the way malformed
web content was displayed. A web page containing specially crafted content could
potentially trick a Firefox user into surrendering sensitive information.
(CVE-2008-4067, CVE-2008-4068) A flaw was found in the way Firefox handles
mouse click events. A web page containing specially crafted JavaScript code
could move the content window while a mouse-button was pressed, causing any item
under the pointer to be dragged. This could, potentially, cause the user to
perform an unsafe drag-and-drop action. (CVE-2008-3837) A flaw was found in
Firefox that caused certain characters to be stripped from JavaScript code. This
flaw could allow malicious JavaScript to bypass or evade script filters.
(CVE-2008-4065) For technical details regarding these flaws, please see the
Mozilla security advisories for Firefox 3.0.2.[1] All Firefox users should
upgrade to these updated packages, which contain patches that correct these
issues. [1] http://www.mozilla.org/security/known-
vulnerabilities/firefox30.html#firefox3.0.2
--------------------------------------------------------------------------------
ChangeLog:
* Tue Sep 23 2008 Christopher Aillon <caillon(a)redhat.com> - 0.17.0-2
- Rebuild against newer gecko
* Thu Sep 18 2008 Mamoru Tasaka <mtasaka(a)ioa.s.u-tokyo.ac.jp> 0.17.0-1
- Update to 0.17.0
- Patch from svn to fix Ruby/GLib bug (bug 456816)
* Tue Jul 15 2008 Christopher Aillon <caillon(a)redhat.com> - 0.17.0-0.3.rc1
- Rebuild against newer gecko
* Wed Jul 2 2008 Christopher Aillon <caillon(a)redhat.com> - 0.17.0-0.2.rc1
- Rebuild against newer gecko
* Sun Jun 8 2008 Mamoru Tasaka <mtasaka(a)ioa.s.u-tokyo.ac.jp> - 0.17.0-0.1.rc1
- 0.17.0 rc1
- Remove upstreamed patches - 2 patches remain
- ruby-gnome2-0.17.0-rc1-script.patch
- ruby-gnome2-all-0.16.0-xulrunner.patch
- Restrict ruby abi dependency to exact 1.8 version
- Fix the license (to strict LGPLv2)
* Wed Apr 16 2008 Christopher Aillon <caillon(a)redhat.com> - 0.16.0-22
- Rebuild against newer gecko
* Tue Mar 25 2008 Christopher Aillon <caillon(a)redhat.com> 0.16.0-21
- Rebuild against newer gecko
* Fri Feb 8 2008 Christopher Aillon <caillon(a)redhat.com> 0.16.0-20
- Rebuild against newer gecko
* Sat Jan 26 2008 Allisson Azevedo <allisson(a)gmail.com> 0.16.0-19
- Fix libglade2 Undefined method error (bugzilla #428781)
* Tue Dec 4 2007 Allisson Azevedo <allisson(a)gmail.com> 0.16.0-18
- Fix CVE-2007-6183, format string vulnerability (bugzilla #402871)
* Tue Nov 27 2007 Christopher Aillon <caillon(a)redhat.com> 0.16.0-17
- Rebuild against newer gecko
* Tue Nov 13 2007 Alex Lancaster <alexl(a)users.sourceforge.net> 0.16.0-16
- Fix my typo in BuildRequires
* Tue Nov 13 2007 Alex Lancaster <alexl(a)users.sourceforge.net> 0.16.0-15
- Rebuild against gecko-libs and gecko-devel (firefox 2.0.0.9).
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update ruby-gnome2' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
http://fedoraproject.org/keys
--------------------------------------------------------------------------------
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2008-8399
2008-09-27 03:03:19
--------------------------------------------------------------------------------
Name : yelp
Product : Fedora 8
Version : 2.20.0
Release : 13.fc8
URL : http://live.gnome.org/Yelp
Summary : A system documentation reader from the Gnome project
Description :
Yelp is the Gnome 2 help/documentation browser. It is designed
to help you browse all the documentation on your system in
one central tool.
--------------------------------------------------------------------------------
Update Information:
Mozilla Firefox is an open source Web browser. Several flaws were found in
the processing of malformed web content. A web page containing malicious content
could cause Firefox to crash or, potentially, execute arbitrary code as the user
running Firefox. (CVE-2008-4058, CVE-2008-4060, CVE-2008-4061, CVE-2008-4062,
CVE-2008-4063, CVE-2008-4064) Several flaws were found in the way malformed
web content was displayed. A web page containing specially crafted content could
potentially trick a Firefox user into surrendering sensitive information.
(CVE-2008-4067, CVE-2008-4068) A flaw was found in the way Firefox handles
mouse click events. A web page containing specially crafted JavaScript code
could move the content window while a mouse-button was pressed, causing any item
under the pointer to be dragged. This could, potentially, cause the user to
perform an unsafe drag-and-drop action. (CVE-2008-3837) A flaw was found in
Firefox that caused certain characters to be stripped from JavaScript code. This
flaw could allow malicious JavaScript to bypass or evade script filters.
(CVE-2008-4065) For technical details regarding these flaws, please see the
Mozilla security advisories for Firefox 3.0.2.[1] All Firefox users should
upgrade to these updated packages, which contain patches that correct these
issues. [1] http://www.mozilla.org/security/known-
vulnerabilities/firefox30.html#firefox3.0.2
--------------------------------------------------------------------------------
ChangeLog:
* Tue Sep 23 2008 Christopher Aillon <caillon(a)redhat.com> - 2.20.0-13
- Rebuild against newer gecko
* Mon Aug 25 2008 Matthew Barnes <mbarnes(a)redhat.com> - 2.20.0-12
- Add patch for RH bug #459487 (format string vulnerability).
* Tue Jul 15 2008 Christopher Aillon <caillon(a)redhat.com> - 2.20.0-11
- Rebuild against newer gecko
* Wed Jul 2 2008 Christopher Aillon <caillon(a)redhat.com> - 2.20.0-10
- Rebuild against newer gecko
* Wed Apr 16 2008 Christopher Aillon <caillon(a)redhat.com> - 2.20.0-9
- Rebuild against newer gecko
* Tue Mar 25 2008 Christopher Aillon <caillon(a)redhat.com> - 2.20.0-8
- Rebuild against newer gecko
* Fri Feb 8 2008 Christopher Aillon <caillon(a)redhat.com> - 2.20.0-7
- Rebuild against newer gecko
* Tue Nov 27 2007 Christopher Aillon <caillon(a)redhat.com> - 2.20.0-6
- Rebuild against newer gecko
* Mon Nov 5 2007 Matthias Clasen <mclasen(a)redhat.com> - 2.20.0-5
- Fix a crash in search (#361041)
* Mon Nov 5 2007 Martin Stransky <stransky(a)redhat.com> - 2.20.0-4
- Rebuild against new firefox
* Sun Nov 4 2007 Matthias Clasen <mclasen(a)redhat.com> - 2.20.0-3
- Fix a crash when loading the rarian docs
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update yelp' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
http://fedoraproject.org/keys
--------------------------------------------------------------------------------
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2008-8399
2008-09-27 03:03:19
--------------------------------------------------------------------------------
Name : blam
Product : Fedora 8
Version : 1.8.3
Release : 18.fc8
URL : http://www.cmartin.tk/blam.html
Summary : An RSS/RDF feed reader
Description :
Blam is a tool that helps you keep track of the growing
number of news feeds distributed as RSS. Blam lets you
subscribe to any number of feeds and provides an easy to
use and clean interface to stay up to date
--------------------------------------------------------------------------------
Update Information:
Mozilla Firefox is an open source Web browser. Several flaws were found in
the processing of malformed web content. A web page containing malicious content
could cause Firefox to crash or, potentially, execute arbitrary code as the user
running Firefox. (CVE-2008-4058, CVE-2008-4060, CVE-2008-4061, CVE-2008-4062,
CVE-2008-4063, CVE-2008-4064) Several flaws were found in the way malformed
web content was displayed. A web page containing specially crafted content could
potentially trick a Firefox user into surrendering sensitive information.
(CVE-2008-4067, CVE-2008-4068) A flaw was found in the way Firefox handles
mouse click events. A web page containing specially crafted JavaScript code
could move the content window while a mouse-button was pressed, causing any item
under the pointer to be dragged. This could, potentially, cause the user to
perform an unsafe drag-and-drop action. (CVE-2008-3837) A flaw was found in
Firefox that caused certain characters to be stripped from JavaScript code. This
flaw could allow malicious JavaScript to bypass or evade script filters.
(CVE-2008-4065) For technical details regarding these flaws, please see the
Mozilla security advisories for Firefox 3.0.2.[1] All Firefox users should
upgrade to these updated packages, which contain patches that correct these
issues. [1] http://www.mozilla.org/security/known-
vulnerabilities/firefox30.html#firefox3.0.2
--------------------------------------------------------------------------------
ChangeLog:
* Tue Sep 23 2008 Christopher Aillon <caillon(a)redhat.com> - 1.8.3-18
- Rebuild against newer gecko
* Tue Jul 15 2008 Christopher Aillon <caillon(a)redhat.com> - 1.8.3-17
- Rebuild against newer gecko
* Wed Jul 2 2008 Christopher Aillon <caillon(a)redhat.com> - 1.8.3-16
- Rebuild against newer gecko
* Wed Apr 16 2008 Christopher Aillon <caillon(a)redhat.com> - 1.8.3-15
- Rebuild against newer gecko
* Tue Mar 25 2008 Christopher Aillon <caillon(a)redhat.com> - 1.8.3-14
- Rebuild against newer gecko
* Fri Feb 8 2008 Christopher Aillon <caillon(a)redhat.com> - 1.8.3-13
- Rebuild against newer gecko
* Tue Nov 27 2007 Christopher Aillon <caillon(a)redhat.com> - 1.8.3-12
- Rebuild against newer gecko
* Thu Nov 22 2007 Peter Gordon <peter(a)thecodergeek.com> - 1.8.3-11
- Fix CVE-2005-4790 (bug 252294).
* Tue Nov 13 2007 Peter Gordon <peter(a)thecodergeek.com> - 1.8.3-10
- Rebuild for new Gecko (Firefox 2.0.0.9).
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update blam' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
http://fedoraproject.org/keys
--------------------------------------------------------------------------------
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2008-8399
2008-09-27 03:03:19
--------------------------------------------------------------------------------
Name : firefox
Product : Fedora 8
Version : 2.0.0.17
Release : 1.fc8
URL : http://www.mozilla.org/projects/firefox/
Summary : Mozilla Firefox Web browser.
Description :
Mozilla Firefox is an open-source web browser, designed for standards
compliance, performance and portability.
--------------------------------------------------------------------------------
Update Information:
Mozilla Firefox is an open source Web browser. Several flaws were found in
the processing of malformed web content. A web page containing malicious content
could cause Firefox to crash or, potentially, execute arbitrary code as the user
running Firefox. (CVE-2008-4058, CVE-2008-4060, CVE-2008-4061, CVE-2008-4062,
CVE-2008-4063, CVE-2008-4064) Several flaws were found in the way malformed
web content was displayed. A web page containing specially crafted content could
potentially trick a Firefox user into surrendering sensitive information.
(CVE-2008-4067, CVE-2008-4068) A flaw was found in the way Firefox handles
mouse click events. A web page containing specially crafted JavaScript code
could move the content window while a mouse-button was pressed, causing any item
under the pointer to be dragged. This could, potentially, cause the user to
perform an unsafe drag-and-drop action. (CVE-2008-3837) A flaw was found in
Firefox that caused certain characters to be stripped from JavaScript code. This
flaw could allow malicious JavaScript to bypass or evade script filters.
(CVE-2008-4065) For technical details regarding these flaws, please see the
Mozilla security advisories for Firefox 3.0.2.[1] All Firefox users should
upgrade to these updated packages, which contain patches that correct these
issues. [1] http://www.mozilla.org/security/known-
vulnerabilities/firefox30.html#firefox3.0.2
--------------------------------------------------------------------------------
ChangeLog:
* Tue Sep 23 2008 Christopher Aillon <caillon(a)redhat.com> 2.0.0.17-1
- Update to 2.0.0.17
* Tue Jul 15 2008 Christopher Aillon <caillon(a)redhat.com> 2.0.0.16-1
- Update to 2.0.0.16
* Wed Jul 2 2008 Christopher Aillon <caillon(a)redhat.com> 2.0.0.15-1
- Update to 2.0.0.15
* Wed Apr 16 2008 Christopher Aillon <caillon(a)redhat.com> 2.0.0.14-1
- Update to 2.0.0.14
* Tue Mar 25 2008 Christopher Aillon <caillon(a)redhat.com> 2.0.0.13-1
- Update to 2.0.0.13
* Fri Feb 8 2008 Christopher Aillon <caillon(a)redhat.com> 2.0.0.12-1
- Update to 2.0.0.12
* Thu Dec 13 2007 Christopher Aillon <caillon(a)redhat.com> 2.0.0.10-3
- Fix the getStartPage method to not return blank.
Patch by pspencer(a)fields.utoronto.ca
* Wed Nov 28 2007 Christopher Aillon <caillon(a)redhat.com> 2.0.0.10-2
- Make Canvas.drawImage work again
* Mon Nov 26 2007 Christopher Aillon <caillon(a)redhat.com> 2.0.0.10-1
- Update to 2.0.0.10
* Mon Nov 5 2007 Martin Stransky <stransky(a)redhat.com> 2.0.0.9-1
- updated to the latest upstream
* Wed Oct 31 2007 Martin Stransky <stransky(a)redhat.com> 2.0.0.8-3
- added mozilla-plugin-config to startup script
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update firefox' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
http://fedoraproject.org/keys
--------------------------------------------------------------------------------
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2008-8399
2008-09-27 03:03:19
--------------------------------------------------------------------------------
Name : chmsee
Product : Fedora 8
Version : 1.0.0
Release : 4.31.fc8
URL : http://chmsee.gro.clinux.org/
Summary : A Gtk+2 CHM document viewer
Description :
A gtk2 chm document viewer.
It uses chmlib to extract files. It uses gecko to display pages. It supports
displaying multilingual pages due to gecko. It features bookmarks and tabs.
The tabs could be used to jump inside the chm file conveniently. Its UI is
clean and handy, also is well localized. It is actively developed and
maintained. The author of chmsee is Jungle Ji and several other great people.
Hint
* Unlike other chm viewers, chmsee extracts files from chm file, and then read
and display them. The extracted files could be found in $HOME/.chmsee/bookshelf
directory. You can clean those files at any time and there is a special config
option for that.
* The bookmark is related to each file so not all bookmarks will be loaded,
only current file's.
* Try to remove $HOME/.chmsee if you encounter any problem after an upgrade.
--------------------------------------------------------------------------------
Update Information:
Mozilla Firefox is an open source Web browser. Several flaws were found in
the processing of malformed web content. A web page containing malicious content
could cause Firefox to crash or, potentially, execute arbitrary code as the user
running Firefox. (CVE-2008-4058, CVE-2008-4060, CVE-2008-4061, CVE-2008-4062,
CVE-2008-4063, CVE-2008-4064) Several flaws were found in the way malformed
web content was displayed. A web page containing specially crafted content could
potentially trick a Firefox user into surrendering sensitive information.
(CVE-2008-4067, CVE-2008-4068) A flaw was found in the way Firefox handles
mouse click events. A web page containing specially crafted JavaScript code
could move the content window while a mouse-button was pressed, causing any item
under the pointer to be dragged. This could, potentially, cause the user to
perform an unsafe drag-and-drop action. (CVE-2008-3837) A flaw was found in
Firefox that caused certain characters to be stripped from JavaScript code. This
flaw could allow malicious JavaScript to bypass or evade script filters.
(CVE-2008-4065) For technical details regarding these flaws, please see the
Mozilla security advisories for Firefox 3.0.2.[1] All Firefox users should
upgrade to these updated packages, which contain patches that correct these
issues. [1] http://www.mozilla.org/security/known-
vulnerabilities/firefox30.html#firefox3.0.2
--------------------------------------------------------------------------------
ChangeLog:
* Tue Sep 23 2008 Christopher Aillon <caillon(a)redhat.com> - 1.0.0-4.31
- Rebuild against newer gecko
* Tue Jul 15 2008 Christopher Aillon <caillon(a)redhat.com> - 1.0.0-3.31
- Rebuild against newer gecko
* Wed Jul 2 2008 Christopher Aillon <caillon(a)redhat.com> - 1.0.0-2.31
- Rebuild against newer gecko
* Wed Apr 16 2008 Christopher Aillon <caillon(a)redhat.com> - 1.0.0-2.30
- Rebuild against newer gecko
* Tue Mar 25 2008 Christopher Aillon <caillon(a)redhat.com> - 1.0.0-1.30
- Rebuild against newer gecko
* Tue Mar 4 2008 bbbush <bbbush.yuan(a)gmail.com> - 1.0.0-1.29
- re-add firefox_version
* Fri Feb 8 2008 Christopher Aillon <caillon(a)redhat.com> - 1.0.0-1.28
- Rebuild against newer gecko
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update chmsee' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
http://fedoraproject.org/keys
--------------------------------------------------------------------------------
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2008-8399
2008-09-27 03:03:19
--------------------------------------------------------------------------------
Name : cairo-dock
Product : Fedora 8
Version : 1.6.2.3
Release : 1.fc8.1
URL : http://www.cairo-dock.org/
Summary : Light eye-candy fully themable animated dock
Description :
An light eye-candy fully themable animated dock for any
Linux desktop. It has a family-likeness with OSX dock,
but with more options.
--------------------------------------------------------------------------------
Update Information:
Mozilla Firefox is an open source Web browser. Several flaws were found in
the processing of malformed web content. A web page containing malicious content
could cause Firefox to crash or, potentially, execute arbitrary code as the user
running Firefox. (CVE-2008-4058, CVE-2008-4060, CVE-2008-4061, CVE-2008-4062,
CVE-2008-4063, CVE-2008-4064) Several flaws were found in the way malformed
web content was displayed. A web page containing specially crafted content could
potentially trick a Firefox user into surrendering sensitive information.
(CVE-2008-4067, CVE-2008-4068) A flaw was found in the way Firefox handles
mouse click events. A web page containing specially crafted JavaScript code
could move the content window while a mouse-button was pressed, causing any item
under the pointer to be dragged. This could, potentially, cause the user to
perform an unsafe drag-and-drop action. (CVE-2008-3837) A flaw was found in
Firefox that caused certain characters to be stripped from JavaScript code. This
flaw could allow malicious JavaScript to bypass or evade script filters.
(CVE-2008-4065) For technical details regarding these flaws, please see the
Mozilla security advisories for Firefox 3.0.2.[1] All Firefox users should
upgrade to these updated packages, which contain patches that correct these
issues. [1] http://www.mozilla.org/security/known-
vulnerabilities/firefox30.html#firefox3.0.2
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update cairo-dock' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
http://fedoraproject.org/keys
--------------------------------------------------------------------------------
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2008-8399
2008-09-27 03:03:19
--------------------------------------------------------------------------------
Name : epiphany
Product : Fedora 8
Version : 2.20.3
Release : 7.fc8
URL : http://www.gnome.org/projects/epiphany/
Summary : GNOME web browser based on the Mozilla rendering engine
Description :
epiphany is a simple GNOME web browser based on the Mozilla rendering
engine.
--------------------------------------------------------------------------------
Update Information:
Mozilla Firefox is an open source Web browser. Several flaws were found in
the processing of malformed web content. A web page containing malicious content
could cause Firefox to crash or, potentially, execute arbitrary code as the user
running Firefox. (CVE-2008-4058, CVE-2008-4060, CVE-2008-4061, CVE-2008-4062,
CVE-2008-4063, CVE-2008-4064) Several flaws were found in the way malformed
web content was displayed. A web page containing specially crafted content could
potentially trick a Firefox user into surrendering sensitive information.
(CVE-2008-4067, CVE-2008-4068) A flaw was found in the way Firefox handles
mouse click events. A web page containing specially crafted JavaScript code
could move the content window while a mouse-button was pressed, causing any item
under the pointer to be dragged. This could, potentially, cause the user to
perform an unsafe drag-and-drop action. (CVE-2008-3837) A flaw was found in
Firefox that caused certain characters to be stripped from JavaScript code. This
flaw could allow malicious JavaScript to bypass or evade script filters.
(CVE-2008-4065) For technical details regarding these flaws, please see the
Mozilla security advisories for Firefox 3.0.2.[1] All Firefox users should
upgrade to these updated packages, which contain patches that correct these
issues. [1] http://www.mozilla.org/security/known-
vulnerabilities/firefox30.html#firefox3.0.2
--------------------------------------------------------------------------------
ChangeLog:
* Tue Sep 23 2008 Christopher Aillon <caillon(a)redhat.com> - 2.20.3-7
- Rebuild against newer gecko
* Tue Jul 15 2008 Christopher Aillon <caillon(a)redhat.com> - 2.20.3-6
- Rebuild against newer gecko
* Wed Jul 2 2008 Christopher Aillon <caillon(a)redhat.com> - 2.20.3-5
- Rebuild against newer gecko
* Sun Apr 27 2008 Christopher Aillon <caillon(a)redhat.com> - 2.20.3-4
- Stop shipping LowContrastLargePrint icons
* Wed Apr 16 2008 Christopher Aillon <caillon(a)redhat.com> - 2.20.3-3
- Rebuild against newer gecko
* Tue Mar 25 2008 Christopher Aillon <caillon(a)redhat.com> - 2.20.3-2
- Rebuild against newer gecko
* Sat Mar 8 2008 Christopher Aillon <caillon(a)redhat.com> - 2.20.3-1
- Update to 2.20.3
* Sat Mar 8 2008 Christopher Aillon <caillon(a)redhat.com> - 2.20.2-4
- Update the useragent for Fedora
* Fri Feb 8 2008 Christopher Aillon <caillon(a)redhat.com> - 2.20.2-3
- Rebuild against newer gecko
* Thu Nov 29 2007 Martin Stransky <stransky(a)redhat.com> - 2.20.2-2
- Polished wrapper patch
* Tue Nov 27 2007 Matthias Clasen <mclasen(a)redhat.com> - 2.20.2-1
- Update to 2.20.2
* Tue Nov 27 2007 Christopher Aillon <caillon(a)redhat.com> - 2.20.1-6
- Rebuild against newer gecko
* Mon Nov 19 2007 Martin Stransky <stransky(a)redhat.com> - 2.20.1-5
- Updated wrapper patch
* Mon Nov 5 2007 Martin Stransky <stransky(a)redhat.com> - 2.20.1-4
- Rebuild against new firefox
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update epiphany' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
http://fedoraproject.org/keys
--------------------------------------------------------------------------------
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2008-8399
2008-09-27 03:03:19
--------------------------------------------------------------------------------
Name : devhelp
Product : Fedora 8
Version : 0.16.1
Release : 10.fc8
URL : http://developer.imendio.com/projects/devhelp
Summary : API document browser
Description :
An API document browser for GNOME 2.
--------------------------------------------------------------------------------
Update Information:
Mozilla Firefox is an open source Web browser. Several flaws were found in
the processing of malformed web content. A web page containing malicious content
could cause Firefox to crash or, potentially, execute arbitrary code as the user
running Firefox. (CVE-2008-4058, CVE-2008-4060, CVE-2008-4061, CVE-2008-4062,
CVE-2008-4063, CVE-2008-4064) Several flaws were found in the way malformed
web content was displayed. A web page containing specially crafted content could
potentially trick a Firefox user into surrendering sensitive information.
(CVE-2008-4067, CVE-2008-4068) A flaw was found in the way Firefox handles
mouse click events. A web page containing specially crafted JavaScript code
could move the content window while a mouse-button was pressed, causing any item
under the pointer to be dragged. This could, potentially, cause the user to
perform an unsafe drag-and-drop action. (CVE-2008-3837) A flaw was found in
Firefox that caused certain characters to be stripped from JavaScript code. This
flaw could allow malicious JavaScript to bypass or evade script filters.
(CVE-2008-4065) For technical details regarding these flaws, please see the
Mozilla security advisories for Firefox 3.0.2.[1] All Firefox users should
upgrade to these updated packages, which contain patches that correct these
issues. [1] http://www.mozilla.org/security/known-
vulnerabilities/firefox30.html#firefox3.0.2
--------------------------------------------------------------------------------
ChangeLog:
* Tue Sep 23 2008 Christopher Aillon <caillon(a)redhat.com> - 0.16.1-10
- Rebuild against newer gecko
* Tue Jul 15 2008 Christopher Aillon <caillon(a)redhat.com> - 0.16.1-9
- Rebuild against newer gecko
* Wed Jul 2 2008 Christopher Aillon <caillon(a)redhat.com> - 0.16.1-8
- Rebuild against newer gecko
* Wed Apr 16 2008 Christopher Aillon <caillon(a)redhat.com> - 0.16.1-7
- Rebuild against newer gecko
* Tue Mar 25 2008 Christopher Aillon <caillon(a)redhat.com> - 0.16.1-6
- Rebuild against newer gecko
* Fri Feb 8 2008 Christopher Aillon <caillon(a)redhat.com> - 0.16.1-5
- Rebuild against newer gecko
* Tue Nov 27 2007 Christopher Aillon <caillon(a)redhat.com> - 0.16.1-4
- Rebuild against newer gecko
* Mon Nov 5 2007 Martin Stransky <stransky(a)redhat.com> - 0.16.1-3.fc8
- rebuild against new firefox
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update devhelp' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
http://fedoraproject.org/keys
--------------------------------------------------------------------------------