Bug 770676 (CVE-2011-3658, CVE-2011-3660, CVE-2011-3661, CVE-2011-3663, CVE-2011-3664, CVE-2011-3665, CVE-2011-3666) - CVE-2011-3660 Mozilla: Multiple security flaws fixed in v3.6.25 (Mac) and v9
Summary: CVE-2011-3660 Mozilla: Multiple security flaws fixed in v3.6.25 (Mac) and v9
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2011-3658, CVE-2011-3660, CVE-2011-3661, CVE-2011-3663, CVE-2011-3664, CVE-2011-3665, CVE-2011-3666
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
urgent
urgent
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 765820
TreeView+ depends on / blocked
 
Reported: 2011-12-28 09:53 UTC by Huzaifa S. Sidhpurwala
Modified: 2021-02-24 13:33 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2011-12-28 09:57:00 UTC
Embargoed:


Attachments (Terms of Use)

Description Huzaifa S. Sidhpurwala 2011-12-28 09:53:41 UTC
Multiple flaws fixed during Mozilla update of December 20 2011:
===============================================================

* MFSA 2011-59 .jar not treated as executable in Firefox 3.6 on Mac
Affects Mac OS

* MFSA 2011-58 Crash scaling <video> to extreme sizes
Affects Firefox and Thunderbird 8, fixed in Firefox and Thunderbird 9

* MFSA 2011-57 Crash when plugin removes itself on Mac OS X
Affects Firefox and Thunderbird 8, fixed in Firefox and Thunderbird 9 on MAC OS

* MFSA 2011-56 Key detection without JavaScript via SVG animation
Affects Firefox and Thunderbird 8, fixed in Firefox and Thunderbird 9

* MFSA 2011-55 nsSVGValue out-of-bounds access
Affects Firefox and Thunderbird 8, fixed in Firefox and Thunderbird 9

* MFSA 2011-54 Potentially exploitable crash in the YARR regular expression library
Affects Firefox and Thunderbird 8, fixed in Firefox and Thunderbird 9

* MFSA 2011-53 Miscellaneous memory safety hazards (rv:9.0)
Affects Firefox and Thunderbird 8, fixed in Firefox and Thunderbird 9

Comment 1 Huzaifa S. Sidhpurwala 2011-12-28 09:57:00 UTC
Statement:

This issue did not affect the version of firefox and thunderbird packages as shipped with Red Hat Enterprise Linux 4, 5 and 6. This issue did not affect the version of seamonkey package as shipped with Red Hat Enterprise Linux 4.


Note You need to log in before you can comment on or make changes to this bug.