Fedora 7 : Miro-1.2-2.fc7 / chmsee-1.0.0-2.30.fc7 / devhelp-0.13-16.fc7 / epiphany-2.18.3-9.fc7 / etc (2008-3249)

high Nessus Plugin ID 32040

Synopsis

The remote Fedora host is missing one or more security updates.

Description

Mozilla Firefox is an open source Web browser. A flaw was found in the processing of malformed JavaScript content. A web page containing such malicious content could cause Firefox to crash or, potentially, execute arbitrary code as the user running Firefox. (CVE-2008-1380) All Firefox users should upgrade to these updated packages, which contain backported patches that correct these issues.

Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.

Solution

Update the affected packages.

See Also

https://bugzilla.redhat.com/show_bug.cgi?id=440518

http://www.nessus.org/u?d4e82e6b

http://www.nessus.org/u?13585eba

http://www.nessus.org/u?98adf529

http://www.nessus.org/u?52a497d4

http://www.nessus.org/u?e07fc0fd

http://www.nessus.org/u?841485e3

http://www.nessus.org/u?c7a1b61c

http://www.nessus.org/u?1afb8e4b

http://www.nessus.org/u?2fcfb72e

http://www.nessus.org/u?28f7ed17

http://www.nessus.org/u?307acf90

http://www.nessus.org/u?b3859c93

http://www.nessus.org/u?90311d77

http://www.nessus.org/u?106e8c81

Plugin Details

Severity: High

ID: 32040

File Name: fedora_2008-3249.nasl

Version: 1.15

Type: local

Agent: unix

Published: 4/25/2008

Updated: 1/11/2021

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.6

CVSS v2

Risk Factor: High

Base Score: 9.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:fedoraproject:fedora:gtkmozembedmm, p-cpe:/a:fedoraproject:fedora:liferea, cpe:/o:fedoraproject:fedora:7, p-cpe:/a:fedoraproject:fedora:epiphany-extensions, p-cpe:/a:fedoraproject:fedora:kazehakase, p-cpe:/a:fedoraproject:fedora:galeon, p-cpe:/a:fedoraproject:fedora:chmsee, p-cpe:/a:fedoraproject:fedora:yelp, p-cpe:/a:fedoraproject:fedora:devhelp, p-cpe:/a:fedoraproject:fedora:miro, p-cpe:/a:fedoraproject:fedora:openvrml, p-cpe:/a:fedoraproject:fedora:gnome-python2-extras, p-cpe:/a:fedoraproject:fedora:epiphany, p-cpe:/a:fedoraproject:fedora:ruby-gnome2, p-cpe:/a:fedoraproject:fedora:firefox

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Patch Publication Date: 4/22/2008

Reference Information

CVE: CVE-2008-1380

CWE: 399

FEDORA: 2008-3249