This issue does NOT affect the versions of the seamonkey package, as shipped with Red Hat Enterprise Linux 3 and 4. This issue does NOT affect the versions of the firefox package, as shipped with Red Hat Enterprise Linux 4 and 5. This issue does NOT affect the version of the firefox package, as shipped with Fedora release of 10. This issue affects the version of the firefox package, as shipped with Fedora release of 11.
MITRE's CVE entry (CVE-2009-2477): The Just-in-time (JIT) JavaScript compiler in Mozilla Firefox 3.5 allows remote attackers to execute arbitrary code via a crafted document containing P and FONT elements. References: ----------- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2477 http://www.milw0rm.com/exploits/9137 http://isc.sans.org/diary.html?storyid=6796 http://www.h-online.com/security/First-Zero-Day-Exploit-for-Firefox-3-5--/news/113761 http://blog.mozilla.com/security/2009/07/14/critical-javascript-vulnerability-in-firefox-35/ http://secunia.com/advisories/35798 http://www.vupen.com/english/advisories/2009/1868
MITRE's CVE-2009-2478 entry: Mozilla Firefox 3.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via unspecified vectors, related to a "flash bug." References: ---------- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2478 https://bugzilla.mozilla.org/show_bug.cgi?id=502648 https://bugzilla.mozilla.org/show_bug.cgi?id=503286
MITRE's CVE-2009-2479 entry: Stack-based buffer overflow in Mozilla Firefox 3.5 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a long Unicode string argument to the write method. References: ----------- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2479 http://www.milw0rm.com/exploits/9158 http://www.securityfocus.com/bid/35707 http://xforce.iss.net/xforce/xfdb/51729
firefox-3.5.1-1.fc11, xulrunner-1.9.1.1-1.fc11, blam-1.8.5-12.fc11, chmsee-1.0.1-9.fc11, eclipse-3.4.2-13.fc11, epiphany-2.26.3-2.fc11, epiphany-extensions-2.26.1-4.fc11, evolution-rss-0.1.2-11.fc11, galeon-2.0.7-12.fc11, gnome-python2-extras-2.25.3-5.fc11, gnome-web-photo-0.7-4.fc11, google-gadgets-0.11.0-2.fc11, hulahop-0.4.9-6.fc11, java-1.6.0-openjdk-1.6.0.0-25.b16.fc11, kazehakase-0.5.6-11.svn3771_trunk.fc11.3, Miro-2.0.5-2.fc11, mozvoikko-0.9.7-0.5.rc1.fc11, ruby-gnome2-0.19.0-3.fc11.1, perl-Gtk2-MozEmbed-0.08-6.fc11.3, yelp-2.26.0-5.fc11 has been pushed to the Fedora 11 stable repository. If problems still persist, please make note of it in this bug report.