RHSA-2011:0471: Critical: firefox security update
Mozilla Firefox is an open source web browser. XULRunner provides the XULRuntime environment for Mozilla Firefox.Several flaws were found in the processing of malformed web content. A webpage containing malicious content could possibly lead to arbitrary codeexecution with the privileges of the user running Firefox. (CVE-2011-0080,CVE-2011-0081)An arbitrary memory write flaw was found in the way Firefox handledout-of-memory conditions. If all memory was consumed when a user visited amalicious web page, it could possibly lead to arbitrary code executionwith the privileges of the user running Firefox. (CVE-2011-0078)An integer overflow flaw was found in the way Firefox handled the HTMLframeset tag. A web page with a frameset tag containing large values forthe "rows" and "cols" attributes could trigger this flaw, possibly leadingto arbitrary code execution with the privileges of the user runningFirefox. (CVE-2011-0077)A flaw was found in the way Firefox handled the HTML iframe tag. A web pagewith an iframe tag containing a specially-crafted source address couldtrigger this flaw, possibly leading to arbitrary code execution with theprivileges of the user running Firefox. (CVE-2011-0075)A flaw was found in the way Firefox displayed multiple marquee elements. Amalformed HTML document could cause Firefox to execute arbitrary code withthe privileges of the user running Firefox. (CVE-2011-0074)A flaw was found in the way Firefox handled the nsTreeSelection element.Malformed content could cause Firefox to execute arbitrary code with theprivileges of the user running Firefox. (CVE-2011-0073)A use-after-free flaw was found in the way Firefox appended frame andiframe elements to a DOM tree when the NoScript add-on was enabled.Malicious HTML content could cause Firefox to execute arbitrary code withthe privileges of the user running Firefox. (CVE-2011-0072)A directory traversal flaw was found in the Firefox resource:// protocolhandler. Malicious content could cause Firefox to access arbitrary filesaccessible to the user running Firefox. (CVE-2011-0071)A double free flaw was found in the way Firefox handled"application/http-index-format" documents. A malformed HTTP response couldcause Firefox to execute arbitrary code with the privileges of the userrunning Firefox. (CVE-2011-0070)A flaw was found in the way Firefox handled certain JavaScript cross-domainrequests. If malicious content generated a large number of cross-domainJavaScript requests, it could cause Firefox to execute arbitrary code withthe privileges of the user running Firefox. (CVE-2011-0069)A flaw was found in the way Firefox displayed the autocomplete pop-up.Malicious content could use this flaw to steal form history information.(CVE-2011-0067)Two use-after-free flaws were found in the Firefox mObserverList andmChannel objects. Malicious content could use these flaws to executearbitrary code with the privileges of the user running Firefox.(CVE-2011-0066, CVE-2011-0065)A flaw was found in the Firefox XSLT generate-id() function. This functionreturned the memory address of an object in memory, which could possibly beused by attackers to bypass address randomization protections.(CVE-2011-1202)For technical details regarding these flaws, refer to the Mozilla securityadvisories for Firefox 3.6.17. You can find a link to the Mozillaadvisories in the References section of this erratum.All Firefox users should upgrade to these updated packages, which containFirefox version 3.6.17, which corrects these issues. After installing theupdate, Firefox must be restarted for the changes to take effect.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2011:0471?
RHSA-2011:0471 is classified as a moderate severity vulnerability due to potential arbitrary code execution risks.
How do I fix RHSA-2011:0471?
To fix RHSA-2011:0471, update to the fixed versions of the affected packages: firefox-3.6.17-1.el6_0 or xulrunner-1.9.2.17-4.el6_0.
What products are affected by RHSA-2011:0471?
RHSA-2011:0471 affects Mozilla Firefox versions prior to 3.6.17-1.el6_0 and XULRunner versions prior to 1.9.2.17-4.el6_0.
What types of exploits are associated with RHSA-2011:0471?
Exploits associated with RHSA-2011:0471 involve the processing of malformed web content that could lead to arbitrary code execution.
Is there a workaround for RHSA-2011:0471?
There is no known workaround for RHSA-2011:0471; upgrading to the latest patched version of the software is the recommended action.