Package: firefox
Version: 1.5.dfsg-4
Severity: grave
Tags: security
Justification: user security hole


Please, package the new firefox's version, it fix these vulnerabilities
besides some other improvements:

MFSA 2006-08  "AnyName" entrainment and access control hazard
MFSA 2006-07 Read beyond buffer while parsing XML
MFSA 2006-06 Integer overflows in E4X, SVG and Canvas
MFSA 2006-05 Localstore.rdf XML injection through XULDocument.persist()
MFSA 2006-04 Memory corruption via QueryInterface on Location, Navigator objects
MFSA 2006-03 Long document title causes startup denial of Service
MFSA 2006-02 Changing postion:relative to static corrupts memory
MFSA 2006-01 JavaScript garbage-collection hazards

One of them is "critical".

Thanks for your work,

-- System Information:
Debian Release: 3.1
  APT prefers unstable
  APT policy: (990, 'unstable'), (1, 'experimental')
Architecture: i386 (i686)
Shell:  /bin/sh linked to /bin/bash
Kernel: Linux 2.6.13
Locale: LANG=es_CO, LC_CTYPE=es_CO (charmap=ISO-8859-1)

Versions of packages firefox depends on:
ii  debianutils            2.8.4             Miscellaneous utilities specific t
ii  fontconfig             2.3.1-2           generic font configuration library
ii  libatk1.0-0            1.10.3-1          The ATK accessibility toolkit
ii  libc6                  2.3.5-7           GNU C Library: Shared libraries an
ii  libcairo2              1.0.2-3           The Cairo 2D vector graphics libra
ii  libfontconfig1         2.3.1-2           generic font configuration library
ii  libfreetype6           2.1.7-2.4         FreeType 2 font engine, shared lib
ii  libgcc1                1:4.0.2-2         GCC support library
ii  libglib2.0-0           2.8.6-1           The GLib library of C routines
ii  libgtk2.0-0            2.8.10-1          The GTK+ graphical user interface 
ii  libidl0                0.8.5-1           library for parsing CORBA IDL file
ii  libjpeg62              6b-10             The Independent JPEG Group's JPEG 
ii  libpango1.0-0          1.10.2-1          Layout and rendering of internatio
ii  libpng12-0             1.2.8rel-5        PNG library - runtime
ii  libstdc++6             4.0.2-5           The GNU Standard C++ Library v3
ii  libx11-6               4.3.0.dfsg.1-14   X Window System protocol client li
ii  libxcursor1            1.1.3-1           X cursor management library
ii  libxext6               4.3.0.dfsg.1-14   X Window System miscellaneous exte
ii  libxft2                2.1.7-1           FreeType-based font drawing librar
ii  libxi6                 4.3.0.dfsg.1-14   X Window System Input extension li
ii  libxinerama1           6.9.0.dfsg.1-4    X Window System multi-head display
ii  libxp6                 4.3.0.dfsg.1-14   X Window System printing extension
ii  libxrandr2             6.9.0.dfsg.1-4    X Window System Resize, Rotate and
ii  libxrender1            1:0.9.0.2-1       X Rendering Extension client libra
ii  libxt6                 4.3.0.dfsg.1-14   X Toolkit Intrinsics
ii  psmisc                 21.5-1            Utilities that use the proc filesy
ii  zlib1g                 1:1.2.2-4.sarge.2 compression library - runtime

firefox recommends no packages.

-- no debconf information


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to