USN-381-1: Firefox vulnerabilities
===========================================================
Ubuntu Security Notice USN-381-1 November 16, 2006
firefox vulnerabilities
CVE-2006-5462, CVE-2006-5463, CVE-2006-5464, CVE-2006-5747,
CVE-2006-5748
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 5.10
Ubuntu 6.06 LTS
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 5.10:
firefox 1.5.dfsg+1.5.0.8-0ubuntu0.5.10
firefox-dev 1.5.dfsg+1.5.0.8-0ubuntu0.5.10
Ubuntu 6.06 LTS:
firefox 1.5.dfsg+1.5.0.8-0ubuntu0.6.06
firefox-dev 1.5.dfsg+1.5.0.8-0ubuntu0.6.06
libnspr-dev 1.5.dfsg+1.5.0.8-0ubuntu0.6.06
libnspr4 1.5.dfsg+1.5.0.8-0ubuntu0.6.06
libnss-dev 1.5.dfsg+1.5.0.8-0ubuntu0.6.06
libnss3 1.5.dfsg+1.5.0.8-0ubuntu0.6.06
After a standard system upgrade you need to restart Firefox to
effect the necessary changes.
Details follow:
USN-351-1 fixed a flaw in the verification of PKCS certificate
signatures. Ulrich Kuehn discovered a variant of the original attack
which the original fix did not cover. (CVE-2006-5462)
Various flaws have been reported that allow an attacker to execute
arbitrary code with user privileges by tricking the user into opening
a malicious web page containing JavaScript. (CVE-2006-5463,
CVE-2006-5464, CVE-2006-5747, CVE-2006-5748)



