Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Patches » RHSA-2014:1635-02

Overview

Id RHSA-2014:1635-02
Name Red Hat 2014:1635-02 RHSA Critical: firefox security update for RHEL 5 x86_64
Vendor Name red_hat
Product None
Content Type Critical - 01 Critical - 01
Language(s)
Operating System(s) Linux 
Released On 15 Oct 2014 12:00:00

RHSA-2014:1635-02

Red Hat 2014:1635-02 RHSA Critical: firefox security update for RHEL 5 x86_64

Vendor Name

red_hat

Product

None

Released On

15 Oct 2014 12:00:00

Url

https://rhn.redhat.com/errata/RHSA-2014-1635.html

Description

LSAC(v2)
Mozilla Firefox is an open source web browser. XULRunner provides the XUL Runtime environment for Mozilla Firefox. Several flaws were found in the processing of malformed web content. A web page containing malicious content could cause Firefox to crash or, potentially, execute arbitrary code with the privileges of the user running Firefox. (CVE-2014-1574, CVE-2014-1578, CVE-2014-1581, CVE-2014-1576, CVE-2014-1577) A flaw was found in the Alarm API, which allows applications to schedule actions to be run in the future. A malicious web application could use this flaw to bypass cross-origin restrictions. (CVE-2014-1583) Red Hat would like to thank the Mozilla project for reporting these issues. Upstream acknowledges Bobby Holley, Christian Holler, David Bolter, Byron Campen Jon Coppeard, Atte Kettunen, Holger Fuhrmannek, Abhishek Arya, regenrecht, and Boris Zbarsky as the original reporters of these issues. For technical details regarding these flaws, refer to the Mozilla security advisories for Firefox 31.2.0 ESR. You can find a link to the Mozilla advisories in the References section of this erratum. All Firefox users should upgrade to these updated packages, which contain Firefox version 31.2.0 ESR, which corrects these issues. After installing the update, Firefox must be restarted for the changes to take effect.

Related Resources

Related Vulnerabilities

CVE-2014-1574   CVE-2014-1576   CVE-2014-1577   CVE-2014-1578   CVE-2014-1581   CVE-2014-1583  

Related Patches

Superseded Patches


Last Updated: 27 May 2016 11:20:46