PGP SIGNED MESSAGE
Hash: SHA1
Mandriva Linux Security Advisory MDKSA-2006:145
Package : mozilla-firefox
Date : August 21, 2006
Affected: Corporate 3.0
Problem Description:
A number of security vulnerabilities have been discovered and corrected
in the latest Mozilla Firefox program.
Corporate 3 had contained the Mozilla suite however, due to the support
cycle for Mozilla, it was felt that upgrading Mozilla to Firefox and
Thunderbird would allow for better future support for Corporate 3
users. To that end, the latest Firefox is being provided for Corporate
3 users which fix all known vulnerabilities up to version 1.5.0.6, as
well as providing new and enhanced features.
As a result of this upgrade migration, galeon and epiphany are no
longer being supported. Upgrading to these packages may require an
explicit install of the mozilla-firefox package, which will then remove
the old mozilla, galeon, and epiphany browsers.
Those users using Mozilla for mail should install the mozilla-
thunderbird package as well.
The following CVE names have been corrected with this update:
CVE-2006-2613, CVE-2006-2894, CVE-2006-2775, CVE-2006-2776,
CVE-2006-2777, CVE-2006-2778, CVE-2006-2779, CVE-2006-2780,
CVE-2006-2782, CVE-2006-2783, CVE-2006-2784, CVE-2006-2785,
CVE-2006-2786, CVE-2006-2787, CVE-2006-2788, CVE-2006-3677,
CVE-2006-3803, CVE-2006-3804, CVE-2006-3806, CVE-2006-3807,
CVE-2006-3113, CVE-2006-3801, CVE-2006-3802, CVE-2006-3805,
CVE-2006-3808, CVE-2006-3809, CVE-2006-3810, CVE-2006-3811,
CVE-2006-3812.
References:
Updated Packages:
Corporate 3.0:
Corporate 3.0/X86_64:
To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.
All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:
gpg pgp.mit.edu 0x22458A98
You can view other update advisories for Mandriva Linux at:
If you want to report vulnerabilities, please contact
security_(at)_mandriva.com
Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team
<security*mandriva.com>
PGP SIGNATURE
Version: GnuPG v1.4.2.2 (GNU/Linux)
Zfr/QW44GlydU0dn1Hn2pBY=
=5uHm
PGP SIGNATURE