int(953)

Boletines de Vulnerabilidades


Desbordamiento de entero en el constructor del objeto SOAPParemeter en Netscape/Mozilla

Clasificación de la vulnerabilidad

Propiedad Valor
Nivel de Confianza Oficial
Impacto Obtener acceso
Dificultad Avanzado
Requerimientos del atacante Acceso remoto sin cuenta a un servicio exotico

Información sobre el sistema

Propiedad Valor
Fabricant afectat GNU/Linux
Software afectado Netscape 7.0, 7.1
Mozilla 1.6
Firefox <1.0.5

Descripción

Se ha descubierto una vulnerabilidad de desbordamiento de entero en el constructor del objeto SOAPParemeter de Netscape y Mozilla.

La explotación de esta vulnerabilidad puede permitir la ejecución remota de código arbitrario en el entorno de seguridad del usuario que se vea afectado.

Dicha explotación está sujeta a la navegación, por parte del usuario, por páginas especialmente diseñadas para aprovechar el fallo aquí descrito.

Solución

Como solución preventiva, se aconseja deshabilitar Javascript en el navegador.
Si lo desea, aplique los mecanismos de actualización propios de su distribución, o bien descargue el software e instálelo usted mismo.


Actualización de software

Mozilla 1.7.1
Descargue una versión actualizada del software
http://www.mozilla.org/products/mozilla1.x/

Red Hat Linux

Red Hat Desktop (v. 3) - AMD64
mozilla-1.4.3-3.0.2.x86_64.rpm
mozilla-chat-1.4.3-3.0.2.x86_64.rpm
mozilla-devel-1.4.3-3.0.2.x86_64.rpm
mozilla-dom-inspector-1.4.3-3.0.2.x86_64.rpm
mozilla-js-debugger-1.4.3-3.0.2.x86_64.rpm
mozilla-mail-1.4.3-3.0.2.x86_64.rpm
mozilla-nspr-1.4.3-3.0.2.x86_64.rpm
mozilla-nspr-devel-1.4.3-3.0.2.x86_64.rpm
mozilla-nss-1.4.3-3.0.2.x86_64.rpm
mozilla-nss-devel-1.4.3-3.0.2.x86_64.rpm

Red Hat Desktop (v. 3) - SRPMS
mozilla-1.4.3-3.0.2.src.rpm

Red Hat Desktop (v. 3) - i386
mozilla-1.4.3-3.0.2.i386.rpm
mozilla-chat-1.4.3-3.0.2.i386.rpm
mozilla-devel-1.4.3-3.0.2.i386.rpm
mozilla-dom-inspector-1.4.3-3.0.2.i386.rpm
mozilla-js-debugger-1.4.3-3.0.2.i386.rpm
mozilla-mail-1.4.3-3.0.2.i386.rpm
mozilla-nspr-1.4.3-3.0.2.i386.rpm
mozilla-nspr-devel-1.4.3-3.0.2.i386.rpm
mozilla-nss-1.4.3-3.0.2.i386.rpm
mozilla-nss-devel-1.4.3-3.0.2.i386.rpm

Red Hat Enterprise Linux AS (v. 2.1) - SRPMS
galeon-1.2.13-3.2.1.src.rpm
mozilla-1.4.3-2.1.2.src.rpm

Red Hat Enterprise Linux AS (v. 2.1) - i386
galeon-1.2.13-3.2.1.i386.rpm
mozilla-1.4.3-2.1.2.i386.rpm
mozilla-chat-1.4.3-2.1.2.i386.rpm
mozilla-devel-1.4.3-2.1.2.i386.rpm
mozilla-dom-inspector-1.4.3-2.1.2.i386.rpm
mozilla-js-debugger-1.4.3-2.1.2.i386.rpm
mozilla-mail-1.4.3-2.1.2.i386.rpm
mozilla-nspr-1.4.3-2.1.2.i386.rpm
mozilla-nspr-devel-1.4.3-2.1.2.i386.rpm
mozilla-nss-1.4.3-2.1.2.i386.rpm
mozilla-nss-devel-1.4.3-2.1.2.i386.rpm

Red Hat Enterprise Linux AS (v. 2.1) - ia64
galeon-1.2.13-3.2.1.ia64.rpm
mozilla-1.4.3-2.1.2.ia64.rpm
mozilla-chat-1.4.3-2.1.2.ia64.rpm
mozilla-devel-1.4.3-2.1.2.ia64.rpm
mozilla-dom-inspector-1.4.3-2.1.2.ia64.rpm
mozilla-js-debugger-1.4.3-2.1.2.ia64.rpm
mozilla-mail-1.4.3-2.1.2.ia64.rpm
mozilla-nspr-1.4.3-2.1.2.ia64.rpm
mozilla-nspr-devel-1.4.3-2.1.2.ia64.rpm
mozilla-nss-1.4.3-2.1.2.ia64.rpm
mozilla-nss-devel-1.4.3-2.1.2.ia64.rpm

Red Hat Enterprise Linux AS (v. 3) - AMD64
mozilla-1.4.3-3.0.2.x86_64.rpm
mozilla-chat-1.4.3-3.0.2.x86_64.rpm
mozilla-devel-1.4.3-3.0.2.x86_64.rpm
mozilla-dom-inspector-1.4.3-3.0.2.x86_64.rpm
mozilla-js-debugger-1.4.3-3.0.2.x86_64.rpm
mozilla-mail-1.4.3-3.0.2.x86_64.rpm
mozilla-nspr-1.4.3-3.0.2.x86_64.rpm
mozilla-nspr-devel-1.4.3-3.0.2.x86_64.rpm
mozilla-nss-1.4.3-3.0.2.x86_64.rpm
mozilla-nss-devel-1.4.3-3.0.2.x86_64.rpm

Red Hat Enterprise Linux AS (v. 3) - SRPMS
mozilla-1.4.3-3.0.2.src.rpm

Red Hat Enterprise Linux AS (v. 3) - i386
mozilla-1.4.3-3.0.2.i386.rpm
mozilla-chat-1.4.3-3.0.2.i386.rpm
mozilla-devel-1.4.3-3.0.2.i386.rpm
mozilla-dom-inspector-1.4.3-3.0.2.i386.rpm
mozilla-js-debugger-1.4.3-3.0.2.i386.rpm
mozilla-mail-1.4.3-3.0.2.i386.rpm
mozilla-nspr-1.4.3-3.0.2.i386.rpm
mozilla-nspr-devel-1.4.3-3.0.2.i386.rpm
mozilla-nss-1.4.3-3.0.2.i386.rpm
mozilla-nss-devel-1.4.3-3.0.2.i386.rpm

Red Hat Enterprise Linux AS (v. 3) - ia64
mozilla-1.4.3-3.0.2.ia64.rpm
mozilla-chat-1.4.3-3.0.2.ia64.rpm
mozilla-devel-1.4.3-3.0.2.ia64.rpm
mozilla-dom-inspector-1.4.3-3.0.2.ia64.rpm
mozilla-js-debugger-1.4.3-3.0.2.ia64.rpm
mozilla-mail-1.4.3-3.0.2.ia64.rpm
mozilla-nspr-1.4.3-3.0.2.ia64.rpm
mozilla-nspr-devel-1.4.3-3.0.2.ia64.rpm
mozilla-nss-1.4.3-3.0.2.ia64.rpm
mozilla-nss-devel-1.4.3-3.0.2.ia64.rpm

Red Hat Enterprise Linux AS (v. 3) - ppc
mozilla-1.4.3-3.0.2.ppc.rpm
mozilla-chat-1.4.3-3.0.2.ppc.rpm
mozilla-devel-1.4.3-3.0.2.ppc.rpm
mozilla-dom-inspector-1.4.3-3.0.2.ppc.rpm
mozilla-js-debugger-1.4.3-3.0.2.ppc.rpm
mozilla-mail-1.4.3-3.0.2.ppc.rpm
mozilla-nspr-1.4.3-3.0.2.ppc.rpm
mozilla-nspr-devel-1.4.3-3.0.2.ppc.rpm
mozilla-nss-1.4.3-3.0.2.ppc.rpm
mozilla-nss-devel-1.4.3-3.0.2.ppc.rpm

Red Hat Enterprise Linux AS (v. 3) - s390
mozilla-1.4.3-3.0.2.s390.rpm
mozilla-chat-1.4.3-3.0.2.s390.rpm
mozilla-devel-1.4.3-3.0.2.s390.rpm
mozilla-dom-inspector-1.4.3-3.0.2.s390.rpm
mozilla-js-debugger-1.4.3-3.0.2.s390.rpm
mozilla-mail-1.4.3-3.0.2.s390.rpm
mozilla-nspr-1.4.3-3.0.2.s390.rpm
mozilla-nspr-devel-1.4.3-3.0.2.s390.rpm
mozilla-nss-1.4.3-3.0.2.s390.rpm
mozilla-nss-devel-1.4.3-3.0.2.s390.rpm

Red Hat Enterprise Linux AS (v. 3) - s390x
mozilla-1.4.3-3.0.2.s390x.rpm
mozilla-chat-1.4.3-3.0.2.s390x.rpm
mozilla-devel-1.4.3-3.0.2.s390x.rpm
mozilla-dom-inspector-1.4.3-3.0.2.s390x.rpm
mozilla-js-debugger-1.4.3-3.0.2.s390x.rpm
mozilla-mail-1.4.3-3.0.2.s390x.rpm
mozilla-nspr-1.4.3-3.0.2.s390x.rpm
mozilla-nspr-devel-1.4.3-3.0.2.s390x.rpm
mozilla-nss-1.4.3-3.0.2.s390x.rpm
mozilla-nss-devel-1.4.3-3.0.2.s390x.rpm

Red Hat Enterprise Linux ES (v. 2.1) - SRPMS
galeon-1.2.13-3.2.1.src.rpm
mozilla-1.4.3-2.1.2.src.rpm

Red Hat Enterprise Linux ES (v. 2.1) - i386
galeon-1.2.13-3.2.1.i386.rpm
mozilla-1.4.3-2.1.2.i386.rpm
mozilla-chat-1.4.3-2.1.2.i386.rpm
mozilla-devel-1.4.3-2.1.2.i386.rpm
mozilla-dom-inspector-1.4.3-2.1.2.i386.rpm
mozilla-js-debugger-1.4.3-2.1.2.i386.rpm
mozilla-mail-1.4.3-2.1.2.i386.rpm
mozilla-nspr-1.4.3-2.1.2.i386.rpm
mozilla-nspr-devel-1.4.3-2.1.2.i386.rpm
mozilla-nss-1.4.3-2.1.2.i386.rpm
mozilla-nss-devel-1.4.3-2.1.2.i386.rpm

Red Hat Enterprise Linux ES (v. 3) - AMD64
mozilla-1.4.3-3.0.2.x86_64.rpm
mozilla-chat-1.4.3-3.0.2.x86_64.rpm
mozilla-devel-1.4.3-3.0.2.x86_64.rpm
mozilla-dom-inspector-1.4.3-3.0.2.x86_64.rpm
mozilla-js-debugger-1.4.3-3.0.2.x86_64.rpm
mozilla-mail-1.4.3-3.0.2.x86_64.rpm
mozilla-nspr-1.4.3-3.0.2.x86_64.rpm
mozilla-nspr-devel-1.4.3-3.0.2.x86_64.rpm
mozilla-nss-1.4.3-3.0.2.x86_64.rpm
mozilla-nss-devel-1.4.3-3.0.2.x86_64.rpm

Red Hat Enterprise Linux ES (v. 3) - SRPMS
mozilla-1.4.3-3.0.2.src.rpm

Red Hat Enterprise Linux ES (v. 3) - i386
mozilla-1.4.3-3.0.2.i386.rpm
mozilla-chat-1.4.3-3.0.2.i386.rpm
mozilla-devel-1.4.3-3.0.2.i386.rpm
mozilla-dom-inspector-1.4.3-3.0.2.i386.rpm
mozilla-js-debugger-1.4.3-3.0.2.i386.rpm
mozilla-mail-1.4.3-3.0.2.i386.rpm
mozilla-nspr-1.4.3-3.0.2.i386.rpm
mozilla-nspr-devel-1.4.3-3.0.2.i386.rpm
mozilla-nss-1.4.3-3.0.2.i386.rpm
mozilla-nss-devel-1.4.3-3.0.2.i386.rpm

Red Hat Enterprise Linux ES (v. 3) - ia64
mozilla-1.4.3-3.0.2.ia64.rpm
mozilla-chat-1.4.3-3.0.2.ia64.rpm
mozilla-devel-1.4.3-3.0.2.ia64.rpm
mozilla-dom-inspector-1.4.3-3.0.2.ia64.rpm
mozilla-js-debugger-1.4.3-3.0.2.ia64.rpm
mozilla-mail-1.4.3-3.0.2.ia64.rpm
mozilla-nspr-1.4.3-3.0.2.ia64.rpm
mozilla-nspr-devel-1.4.3-3.0.2.ia64.rpm
mozilla-nss-1.4.3-3.0.2.ia64.rpm
mozilla-nss-devel-1.4.3-3.0.2.ia64.rpm

Red Hat Enterprise Linux WS (v. 2.1) - SRPMS
galeon-1.2.13-3.2.1.src.rpm
mozilla-1.4.3-2.1.2.src.rpm

Red Hat Enterprise Linux WS (v. 2.1) - i386
galeon-1.2.13-3.2.1.i386.rpm
mozilla-1.4.3-2.1.2.i386.rpm
mozilla-chat-1.4.3-2.1.2.i386.rpm
mozilla-devel-1.4.3-2.1.2.i386.rpm
mozilla-dom-inspector-1.4.3-2.1.2.i386.rpm
mozilla-js-debugger-1.4.3-2.1.2.i386.rpm
mozilla-mail-1.4.3-2.1.2.i386.rpm
mozilla-nspr-1.4.3-2.1.2.i386.rpm
mozilla-nspr-devel-1.4.3-2.1.2.i386.rpm
mozilla-nss-1.4.3-2.1.2.i386.rpm
mozilla-nss-devel-1.4.3-2.1.2.i386.rpm

Red Hat Enterprise Linux WS (v. 3) - AMD64
mozilla-1.4.3-3.0.2.x86_64.rpm
mozilla-chat-1.4.3-3.0.2.x86_64.rpm
mozilla-devel-1.4.3-3.0.2.x86_64.rpm
mozilla-dom-inspector-1.4.3-3.0.2.x86_64.rpm
mozilla-js-debugger-1.4.3-3.0.2.x86_64.rpm
mozilla-mail-1.4.3-3.0.2.x86_64.rpm
mozilla-nspr-1.4.3-3.0.2.x86_64.rpm
mozilla-nspr-devel-1.4.3-3.0.2.x86_64.rpm
mozilla-nss-1.4.3-3.0.2.x86_64.rpm
mozilla-nss-devel-1.4.3-3.0.2.x86_64.rpm

Red Hat Enterprise Linux WS (v. 3) - SRPMS
mozilla-1.4.3-3.0.2.src.rpm

Red Hat Enterprise Linux WS (v. 3) - i386
mozilla-1.4.3-3.0.2.i386.rpm
mozilla-chat-1.4.3-3.0.2.i386.rpm
mozilla-devel-1.4.3-3.0.2.i386.rpm
mozilla-dom-inspector-1.4.3-3.0.2.i386.rpm
mozilla-js-debugger-1.4.3-3.0.2.i386.rpm
mozilla-mail-1.4.3-3.0.2.i386.rpm
mozilla-nspr-1.4.3-3.0.2.i386.rpm
mozilla-nspr-devel-1.4.3-3.0.2.i386.rpm
mozilla-nss-1.4.3-3.0.2.i386.rpm
mozilla-nss-devel-1.4.3-3.0.2.i386.rpm

Red Hat Enterprise Linux WS (v. 3) - ia64
mozilla-1.4.3-3.0.2.ia64.rpm
mozilla-chat-1.4.3-3.0.2.ia64.rpm
mozilla-devel-1.4.3-3.0.2.ia64.rpm
mozilla-dom-inspector-1.4.3-3.0.2.ia64.rpm
mozilla-js-debugger-1.4.3-3.0.2.ia64.rpm
mozilla-mail-1.4.3-3.0.2.ia64.rpm
mozilla-nspr-1.4.3-3.0.2.ia64.rpm
mozilla-nspr-devel-1.4.3-3.0.2.ia64.rpm
mozilla-nss-1.4.3-3.0.2.ia64.rpm
mozilla-nss-devel-1.4.3-3.0.2.ia64.rpm

Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor - SRPMS
galeon-1.2.13-3.2.1.src.rpm
mozilla-1.4.3-2.1.2.src.rpm

Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor - ia64
galeon-1.2.13-3.2.1.ia64.rpm
mozilla-1.4.3-2.1.2.ia64.rpm
mozilla-chat-1.4.3-2.1.2.ia64.rpm
mozilla-devel-1.4.3-2.1.2.ia64.rpm
mozilla-dom-inspector-1.4.3-2.1.2.ia64.rpm
mozilla-js-debugger-1.4.3-2.1.2.ia64.rpm
mozilla-mail-1.4.3-2.1.2.ia64.rpm
mozilla-nspr-1.4.3-2.1.2.ia64.rpm
mozilla-nspr-devel-1.4.3-2.1.2.ia64.rpm
mozilla-nss-1.4.3-2.1.2.ia64.rpm
mozilla-nss-devel-1.4.3-2.1.2.ia64.rpm

SUSE Linux

SUSE 8.1
Actualización disponible mediante Yast Online Update

SUSE 8.2
Actualización disponible mediante Yast Online Update

SUSE 9.0
Actualización disponible mediante Yast Online Update

SUSE 9.1
Actualización disponible mediante Yast Online Update

SUSE Linux Enterprise Server 8
Actualización disponible mediante Yast Online Update

SUSE Linux Enterprise Server 9
Actualización disponible mediante Yast Online Update

SUSE Linux Desktop 1.0
Actualización disponible mediante Yast Online Update

Sun

Solaris 8
SPARC
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21-117765-02-1
x86
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21-117766-02-1

Solaris 9
SPARC
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21-117767-02-1
x86
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21-117768-02-1

Sun Java Desktop System
Sun Java Desktop System 2003
Sun Java Desktop System Release 2
http://wwws.sun.com/software/javadesktopsystem/faq.html#5q5
http://wwws.sun.com/software/javadesktopsystem/faq.html#5q7

Debian Linux
Debian Linux 3.1
Source
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge1.dsc
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge1.diff.gz
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4.orig.tar.gz
Alpha
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge1_alpha.deb
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-dom-inspector_1.0.4-2sarge1_alpha.deb
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-gnome-support_1.0.4-2sarge1_alpha.deb
AMD64
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge1_amd64.deb
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-dom-inspector_1.0.4-2sarge1_amd64.deb
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-gnome-support_1.0.4-2sarge1_amd64.deb
ARM
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge1_arm.deb
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-dom-inspector_1.0.4-2sarge1_arm.deb
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-gnome-support_1.0.4-2sarge1_arm.deb
Intel IA-32
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge1_i386.deb
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-dom-inspector_1.0.4-2sarge1_i386.deb
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-gnome-support_1.0.4-2sarge1_i386.deb
Intel IA-64
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge1_ia64.deb
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-dom-inspector_1.0.4-2sarge1_ia64.deb
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-gnome-support_1.0.4-2sarge1_ia64.deb
HP Precision
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge1_hppa.deb
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-dom-inspector_1.0.4-2sarge1_hppa.deb
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-gnome-support_1.0.4-2sarge1_hppa.deb
Motorola 680x0
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge1_m68k.deb
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-dom-inspector_1.0.4-2sarge1_m68k.deb
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-gnome-support_1.0.4-2sarge1_m68k.deb
Big endian MIPS
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge1_mips.deb
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-dom-inspector_1.0.4-2sarge1_mips.deb
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-gnome-support_1.0.4-2sarge1_mips.deb
Little endian MIPS
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge1_mipsel.deb
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-dom-inspector_1.0.4-2sarge1_mipsel.deb
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-gnome-support_1.0.4-2sarge1_mipsel.deb
PowerPC
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge1_powerpc.deb
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-dom-inspector_1.0.4-2sarge1_powerpc.deb
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-gnome-support_1.0.4-2sarge1_powerpc.deb
IBM S/390
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge1_s390.deb
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-dom-inspector_1.0.4-2sarge1_s390.deb
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-gnome-support_1.0.4-2sarge1_s390.deb
Sun Sparc
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge1_sparc.deb
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-dom-inspector_1.0.4-2sarge1_sparc.deb
http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-gnome-support_1.0.4-2sarge1_sparc.deb

Debian Linux

Debian Linux 3.1
Source
http://security.debian.org/pool/updates/main/m/mozilla/mozilla_1.7.8-1sarge1.dsc
http://security.debian.org/pool/updates/main/m/mozilla/mozilla_1.7.8-1sarge1.diff.gz
http://security.debian.org/pool/updates/main/m/mozilla/mozilla_1.7.8.orig.tar.gz
Alpha
http://security.debian.org/pool/updates/main/m/mozilla/libnspr-dev_1.7.8-1sarge1_alpha.deb
http://security.debian.org/pool/updates/main/m/mozilla/libnspr4_1.7.8-1sarge1_alpha.deb
http://security.debian.org/pool/updates/main/m/mozilla/libnss-dev_1.7.8-1sarge1_alpha.deb
http://security.debian.org/pool/updates/main/m/mozilla/libnss3_1.7.8-1sarge1_alpha.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla_1.7.8-1sarge1_alpha.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-browser_1.7.8-1sarge1_alpha.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-calendar_1.7.8-1sarge1_alpha.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-chatzilla_1.7.8-1sarge1_alpha.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-dev_1.7.8-1sarge1_alpha.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-dom-inspector_1.7.8-1sarge1_alpha.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-js-debugger_1.7.8-1sarge1_alpha.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-mailnews_1.7.8-1sarge1_alpha.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-psm_1.7.8-1sarge1_alpha.deb
AMD64
http://security.debian.org/pool/updates/main/m/mozilla/libnspr-dev_1.7.8-1sarge1_amd64.deb
http://security.debian.org/pool/updates/main/m/mozilla/libnspr4_1.7.8-1sarge1_amd64.deb
http://security.debian.org/pool/updates/main/m/mozilla/libnss-dev_1.7.8-1sarge1_amd64.deb
http://security.debian.org/pool/updates/main/m/mozilla/libnss3_1.7.8-1sarge1_amd64.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla_1.7.8-1sarge1_amd64.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-browser_1.7.8-1sarge1_amd64.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-calendar_1.7.8-1sarge1_amd64.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-chatzilla_1.7.8-1sarge1_amd64.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-dev_1.7.8-1sarge1_amd64.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-dom-inspector_1.7.8-1sarge1_amd64.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-js-debugger_1.7.8-1sarge1_amd64.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-mailnews_1.7.8-1sarge1_amd64.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-psm_1.7.8-1sarge1_amd64.deb
ARM
http://security.debian.org/pool/updates/main/m/mozilla/libnspr-dev_1.7.8-1sarge1_arm.deb
http://security.debian.org/pool/updates/main/m/mozilla/libnspr4_1.7.8-1sarge1_arm.deb
http://security.debian.org/pool/updates/main/m/mozilla/libnss-dev_1.7.8-1sarge1_arm.deb
http://security.debian.org/pool/updates/main/m/mozilla/libnss3_1.7.8-1sarge1_arm.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla_1.7.8-1sarge1_arm.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-browser_1.7.8-1sarge1_arm.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-calendar_1.7.8-1sarge1_arm.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-chatzilla_1.7.8-1sarge1_arm.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-dev_1.7.8-1sarge1_arm.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-dom-inspector_1.7.8-1sarge1_arm.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-js-debugger_1.7.8-1sarge1_arm.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-mailnews_1.7.8-1sarge1_arm.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-psm_1.7.8-1sarge1_arm.deb
Intel IA-32
http://security.debian.org/pool/updates/main/m/mozilla/libnspr-dev_1.7.8-1sarge1_i386.deb
http://security.debian.org/pool/updates/main/m/mozilla/libnspr4_1.7.8-1sarge1_i386.deb
http://security.debian.org/pool/updates/main/m/mozilla/libnss-dev_1.7.8-1sarge1_i386.deb
http://security.debian.org/pool/updates/main/m/mozilla/libnss3_1.7.8-1sarge1_i386.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla_1.7.8-1sarge1_i386.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-browser_1.7.8-1sarge1_i386.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-calendar_1.7.8-1sarge1_i386.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-chatzilla_1.7.8-1sarge1_i386.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-dev_1.7.8-1sarge1_i386.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-dom-inspector_1.7.8-1sarge1_i386.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-js-debugger_1.7.8-1sarge1_i386.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-mailnews_1.7.8-1sarge1_i386.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-psm_1.7.8-1sarge1_i386.deb
Intel IA-64
http://security.debian.org/pool/updates/main/m/mozilla/libnspr-dev_1.7.8-1sarge1_ia64.deb
http://security.debian.org/pool/updates/main/m/mozilla/libnspr4_1.7.8-1sarge1_ia64.deb
http://security.debian.org/pool/updates/main/m/mozilla/libnss-dev_1.7.8-1sarge1_ia64.deb
http://security.debian.org/pool/updates/main/m/mozilla/libnss3_1.7.8-1sarge1_ia64.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla_1.7.8-1sarge1_ia64.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-browser_1.7.8-1sarge1_ia64.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-calendar_1.7.8-1sarge1_ia64.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-chatzilla_1.7.8-1sarge1_ia64.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-dev_1.7.8-1sarge1_ia64.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-dom-inspector_1.7.8-1sarge1_ia64.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-js-debugger_1.7.8-1sarge1_ia64.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-mailnews_1.7.8-1sarge1_ia64.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-psm_1.7.8-1sarge1_ia64.deb
HP Precision
http://security.debian.org/pool/updates/main/m/mozilla/libnspr-dev_1.7.8-1sarge1_hppa.deb
http://security.debian.org/pool/updates/main/m/mozilla/libnspr4_1.7.8-1sarge1_hppa.deb
http://security.debian.org/pool/updates/main/m/mozilla/libnss-dev_1.7.8-1sarge1_hppa.deb
http://security.debian.org/pool/updates/main/m/mozilla/libnss3_1.7.8-1sarge1_hppa.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla_1.7.8-1sarge1_hppa.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-browser_1.7.8-1sarge1_hppa.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-calendar_1.7.8-1sarge1_hppa.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-chatzilla_1.7.8-1sarge1_hppa.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-dev_1.7.8-1sarge1_hppa.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-dom-inspector_1.7.8-1sarge1_hppa.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-js-debugger_1.7.8-1sarge1_hppa.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-mailnews_1.7.8-1sarge1_hppa.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-psm_1.7.8-1sarge1_hppa.deb
Motorola 680x0
http://security.debian.org/pool/updates/main/m/mozilla/libnspr-dev_1.7.8-1sarge1_m68k.deb
http://security.debian.org/pool/updates/main/m/mozilla/libnspr4_1.7.8-1sarge1_m68k.deb
http://security.debian.org/pool/updates/main/m/mozilla/libnss-dev_1.7.8-1sarge1_m68k.deb
http://security.debian.org/pool/updates/main/m/mozilla/libnss3_1.7.8-1sarge1_m68k.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla_1.7.8-1sarge1_m68k.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-browser_1.7.8-1sarge1_m68k.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-calendar_1.7.8-1sarge1_m68k.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-chatzilla_1.7.8-1sarge1_m68k.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-dev_1.7.8-1sarge1_m68k.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-dom-inspector_1.7.8-1sarge1_m68k.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-js-debugger_1.7.8-1sarge1_m68k.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-mailnews_1.7.8-1sarge1_m68k.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-psm_1.7.8-1sarge1_m68k.deb
Big endian MIPS
http://security.debian.org/pool/updates/main/m/mozilla/libnspr-dev_1.7.8-1sarge1_mips.deb
http://security.debian.org/pool/updates/main/m/mozilla/libnspr4_1.7.8-1sarge1_mips.deb
http://security.debian.org/pool/updates/main/m/mozilla/libnss-dev_1.7.8-1sarge1_mips.deb
http://security.debian.org/pool/updates/main/m/mozilla/libnss3_1.7.8-1sarge1_mips.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla_1.7.8-1sarge1_mips.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-browser_1.7.8-1sarge1_mips.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-calendar_1.7.8-1sarge1_mips.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-chatzilla_1.7.8-1sarge1_mips.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-dev_1.7.8-1sarge1_mips.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-dom-inspector_1.7.8-1sarge1_mips.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-js-debugger_1.7.8-1sarge1_mips.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-mailnews_1.7.8-1sarge1_mips.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-psm_1.7.8-1sarge1_mips.deb
Little endian MIPS
http://security.debian.org/pool/updates/main/m/mozilla/libnspr-dev_1.7.8-1sarge1_mipsel.deb
http://security.debian.org/pool/updates/main/m/mozilla/libnspr4_1.7.8-1sarge1_mipsel.deb
http://security.debian.org/pool/updates/main/m/mozilla/libnss-dev_1.7.8-1sarge1_mipsel.deb
http://security.debian.org/pool/updates/main/m/mozilla/libnss3_1.7.8-1sarge1_mipsel.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla_1.7.8-1sarge1_mipsel.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-browser_1.7.8-1sarge1_mipsel.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-calendar_1.7.8-1sarge1_mipsel.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-chatzilla_1.7.8-1sarge1_mipsel.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-dev_1.7.8-1sarge1_mipsel.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-dom-inspector_1.7.8-1sarge1_mipsel.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-js-debugger_1.7.8-1sarge1_mipsel.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-mailnews_1.7.8-1sarge1_mipsel.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-psm_1.7.8-1sarge1_mipsel.deb
PowerPC
http://security.debian.org/pool/updates/main/m/mozilla/libnspr-dev_1.7.8-1sarge1_powerpc.deb
http://security.debian.org/pool/updates/main/m/mozilla/libnspr4_1.7.8-1sarge1_powerpc.deb
http://security.debian.org/pool/updates/main/m/mozilla/libnss-dev_1.7.8-1sarge1_powerpc.deb
http://security.debian.org/pool/updates/main/m/mozilla/libnss3_1.7.8-1sarge1_powerpc.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla_1.7.8-1sarge1_powerpc.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-browser_1.7.8-1sarge1_powerpc.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-calendar_1.7.8-1sarge1_powerpc.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-chatzilla_1.7.8-1sarge1_powerpc.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-dev_1.7.8-1sarge1_powerpc.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-dom-inspector_1.7.8-1sarge1_powerpc.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-js-debugger_1.7.8-1sarge1_powerpc.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-mailnews_1.7.8-1sarge1_powerpc.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-psm_1.7.8-1sarge1_powerpc.deb
IBM S/390
http://security.debian.org/pool/updates/main/m/mozilla/libnspr-dev_1.7.8-1sarge1_s390.deb
http://security.debian.org/pool/updates/main/m/mozilla/libnspr4_1.7.8-1sarge1_s390.deb
http://security.debian.org/pool/updates/main/m/mozilla/libnss-dev_1.7.8-1sarge1_s390.deb
http://security.debian.org/pool/updates/main/m/mozilla/libnss3_1.7.8-1sarge1_s390.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla_1.7.8-1sarge1_s390.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-browser_1.7.8-1sarge1_s390.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-calendar_1.7.8-1sarge1_s390.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-chatzilla_1.7.8-1sarge1_s390.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-dev_1.7.8-1sarge1_s390.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-dom-inspector_1.7.8-1sarge1_s390.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-js-debugger_1.7.8-1sarge1_s390.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-mailnews_1.7.8-1sarge1_s390.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-psm_1.7.8-1sarge1_s390.deb
Sun Sparc
http://security.debian.org/pool/updates/main/m/mozilla/libnspr-dev_1.7.8-1sarge1_sparc.deb
http://security.debian.org/pool/updates/main/m/mozilla/libnspr4_1.7.8-1sarge1_sparc.deb
http://security.debian.org/pool/updates/main/m/mozilla/libnss-dev_1.7.8-1sarge1_sparc.deb
http://security.debian.org/pool/updates/main/m/mozilla/libnss3_1.7.8-1sarge1_sparc.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla_1.7.8-1sarge1_sparc.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-browser_1.7.8-1sarge1_sparc.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-calendar_1.7.8-1sarge1_sparc.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-chatzilla_1.7.8-1sarge1_sparc.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-dev_1.7.8-1sarge1_sparc.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-dom-inspector_1.7.8-1sarge1_sparc.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-js-debugger_1.7.8-1sarge1_sparc.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-mailnews_1.7.8-1sarge1_sparc.deb
http://security.debian.org/pool/updates/main/m/mozilla/mozilla-psm_1.7.8-1sarge1_sparc.deb

SCO
OpenServer 5.0.7
ftp://ftp.sco.com/pub/openserver5/507/mp/osr507mp4/osr507mp4_vol.tar

Identificadores estándar

Propiedad Valor
CVE CAN-2004-0722
CAN-2004-0757
CAN-2004-0759
CAN-2004-0760
CAN-2004-0718
CAN-2004-0761
CAN-2004-0762
CAN-2004-0764
CAN-2004-0765
BID

Recursos adicionales

iDEFENSE Security Advisory 08.02.04
http://www.idefense.com/application/poi/display?id=117&type=vulnerabilities&flashstatus=true

Redhat Security Advisory RHSA-2004:421-17
https://rhn.redhat.com/errata/RHSA-2004-421.html

SUSE Security Announcement SUSE-SA:2004:036
http://www.suse.de/de/security/2004_36_mozilla.html

Sun(sm) Alert Notification (57701)
http://sunsolve.sun.com/search/document.do?assetkey=1-26-57701-1

Debian Security Advisory DSA 775-1
http://lists.debian.org/debian-security-announce/debian-security-announce-2005/msg00162.html

Debian Security Advisory DSA 777-1
http://lists.debian.org/debian-security-announce/debian-security-announce-2005/msg00165.html

SCO Security Advisory (SCOSA-2005.49)
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt

Histórico de versiones

Versión Comentario Data
1.0 Aviso emitido 2004-08-03
1.1 Aviso emitido por Red Hat (2004:421-17) 2004-08-09
1.2 Aviso emitido por SUSE (SUSE-SA:2004:036) 2004-10-07
1.3 Aviso emitido por Sun (57701) 2004-12-16
1.4 Aviso actualizado por Sun (57701) 2005-01-28
1.5 Aviso actualizado por Debian (DSA 775-1) 2005-08-19
1.6 Aviso emitido por Debian (DSA 777-1) 2005-08-23
1.7 Aviso emitido por SCO (SCOSA-2005.49) 2005-11-28
Ministerio de Defensa
CNI
CCN
CCN-CERT