Bug 88509 - (CVE-2005-2270) VUL-0: CVE-2005-2270: upcoming security release of mozilla 1.7.9 and Firefox 1.0.5
(CVE-2005-2270)
VUL-0: CVE-2005-2270: upcoming security release of mozilla 1.7.9 and Firefox ...
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other SUSE Other
: P5 - None : Major
: ---
Assigned To: Wolfgang Rosenauer
Security Team bot
CVE-2005-2270: CVSS v2 Base Score: 7....
:
Depends on: 100207
Blocks:
  Show dependency treegraph
 
Reported: 2005-06-09 13:12 UTC by Wolfgang Rosenauer
Modified: 2021-11-10 14:47 UTC (History)
2 users (show)

See Also:
Found By: Other
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments
mfsa2005-45 (1.35 KB, text/html)
2005-07-12 10:32 UTC, Wolfgang Rosenauer
Details
mfsa2005-46 (1.52 KB, text/html)
2005-07-12 10:33 UTC, Wolfgang Rosenauer
Details
mfsa2005-47 (1.46 KB, text/html)
2005-07-12 10:33 UTC, Wolfgang Rosenauer
Details
mfsa2005-48 (2.63 KB, text/html)
2005-07-12 10:33 UTC, Wolfgang Rosenauer
Details
mfsa2005-49 (1.04 KB, text/html)
2005-07-12 10:33 UTC, Wolfgang Rosenauer
Details
mfsa2005-50 (1.36 KB, text/html)
2005-07-12 10:34 UTC, Wolfgang Rosenauer
Details
mfsa2005-51 (1.13 KB, text/html)
2005-07-12 10:34 UTC, Wolfgang Rosenauer
Details
mfsa2005-52 (1.48 KB, text/html)
2005-07-12 10:34 UTC, Wolfgang Rosenauer
Details
mfsa2005-53 (2.07 KB, text/html)
2005-07-12 10:34 UTC, Wolfgang Rosenauer
Details
mfsa2005-54 (1.54 KB, text/html)
2005-07-12 10:34 UTC, Wolfgang Rosenauer
Details
mfsa2005-55 (1.42 KB, text/html)
2005-07-12 10:35 UTC, Wolfgang Rosenauer
Details
mfsa2005-56 (1.41 KB, text/html)
2005-07-12 10:35 UTC, Wolfgang Rosenauer
Details

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Wolfgang Rosenauer 2005-06-23 05:33:13 UTC
mozilla 1.7.9 and firefox 1.0.5 is near.
(as well as Thunderbird 1.0.5 it seems)

Is it OK to do the same procedure as every month? :-(
Means: 
- patch mozilla
- version upgrade for Firefox
  (all changes between 1.0.4 and 1.0.5 are security ones)
Comment 2 Andreas Jaeger 2005-06-23 06:47:22 UTC
Please stay with the previous version.
Comment 3 Wolfgang Rosenauer 2005-07-12 04:25:57 UTC
mozilla.org will ship new versions today (planned)

Mozilla 1.7.9
Firefox 1.0.5
Thunderbird 1.0.5

At the moment I have no information which security information will be provided.
I will prepare update packages ASAP.
Comment 4 Wolfgang Rosenauer 2005-07-12 10:32:49 UTC
Created attachment 41640 [details]
mfsa2005-45
Comment 5 Wolfgang Rosenauer 2005-07-12 10:33:09 UTC
Created attachment 41641 [details]
mfsa2005-46
Comment 6 Wolfgang Rosenauer 2005-07-12 10:33:22 UTC
Created attachment 41642 [details]
mfsa2005-47
Comment 7 Wolfgang Rosenauer 2005-07-12 10:33:36 UTC
Created attachment 41643 [details]
mfsa2005-48
Comment 8 Wolfgang Rosenauer 2005-07-12 10:33:51 UTC
Created attachment 41644 [details]
mfsa2005-49
Comment 9 Wolfgang Rosenauer 2005-07-12 10:34:03 UTC
Created attachment 41645 [details]
mfsa2005-50
Comment 10 Wolfgang Rosenauer 2005-07-12 10:34:15 UTC
Created attachment 41646 [details]
mfsa2005-51
Comment 11 Wolfgang Rosenauer 2005-07-12 10:34:30 UTC
Created attachment 41647 [details]
mfsa2005-52
Comment 12 Wolfgang Rosenauer 2005-07-12 10:34:44 UTC
Created attachment 41648 [details]
mfsa2005-53
Comment 13 Wolfgang Rosenauer 2005-07-12 10:34:59 UTC
Created attachment 41649 [details]
mfsa2005-54
Comment 14 Wolfgang Rosenauer 2005-07-12 10:35:12 UTC
Created attachment 41650 [details]
mfsa2005-55
Comment 15 Wolfgang Rosenauer 2005-07-12 10:35:25 UTC
Created attachment 41651 [details]
mfsa2005-56
Comment 16 Wolfgang Rosenauer 2005-07-12 10:37:39 UTC
Those announcements are not published yet and therefore the naming could be
changed again. I will tell you as soon as it is final.

Firefox packages are submitted for 9.0, 9.1, 9.2 and 9.3.
Comment 17 Marcus Meissner 2005-07-12 14:56:55 UTC
swampid: 1773 
Comment 18 Marcus Meissner 2005-07-12 15:17:43 UTC
actually swampid: 1783 
 
Comment 19 Wolfgang Rosenauer 2005-07-13 05:10:42 UTC
Firefox 1.0.5 is released by mozilla.org now.
Security announcements are public here:
http://www.mozilla.org/projects/security/known-vulnerabilities.html#Firefox

Mozilla and Thunderbird are not released yet but will follow soon.
Comment 20 Wolfgang Rosenauer 2005-07-20 07:13:23 UTC
Firefox updates based on 1.0.6 are now submitted to /work/src/done.
mozilla is waiting for upstream approval for another day.
Comment 21 Ludwig Nussel 2005-07-27 07:51:05 UTC
firefox released 
Comment 22 Ludwig Nussel 2005-07-28 15:38:49 UTC
I have some questions 
 
Will the following packages magically work with the new mozilla? 
  - galeon 
  - epiphany 
  - mozilla-cs,mozilla-deat,mozilla-hu,mozilla-ja,mozilla-ko 
 
Did the list of subpackages change in any release? sles9 for example doesn't 
include the spellchecker. 
Comment 23 Wolfgang Rosenauer 2005-07-28 18:48:00 UTC
(In reply to comment #22)

> Will the following packages magically work with the new mozilla? 
>   - galeon 
>   - epiphany 
>   - mozilla-cs,mozilla-deat,mozilla-hu,mozilla-ja,mozilla-ko 

I guess you speak about SLES8, 8.2, 9.0 which will go from 1.6 to 1.7.8(11)?
No, not all of those will work with new mozilla.
We made an evaluation for SLES8:

# whatdependson -D sles8-slec-i386 mozilla              Status
- evolution (gnome-maintainers@suse.de)                 rebuild works
- galeon (gnome-maintainers@suse.de)                    1.2.13 incompatible
- gnome-pilot (gnome-maintainers@suse.de)               don't see how it depends
on mozilla
                                                        (but it builds anyway
against 1.7.8)
- kdebindings3 (kde-maintainers@suse.de)                rebuild works
- mozilla-deat (stark@suse.de)                          must be updated to SLES9
version

# whatdependson -D sles8-i386 mozilla
- POS_Image (jhargadon@novell.com)                      just included in the image
- POS_Image-Desktop (jhargadon@novell.com)              "
- POS_Image-Desktop2                                    "
- POS_Image2 (jhargadon@novell.com)                     "
- saint (mjancar@suse.cz)                               only need a web browser
(no build deps)

This was discussed on prjmgr and the only problem is galeon on SLEC. If we can't
get it to work easily it will be obsoleted.
I've discussed with Marcus to get mozilla checked in and check the missing
details before the update is published IIRC. mozilla-deat is already there for
checkin to SLEC.

For SLES9 we have no problem. We've made already sure that all packages work
with mozilla 1.7.8 as SP2 arrived.
I'm not sure if we care much about 8.2 and 9.0. We haven't much choice here.
  
> Did the list of subpackages change in any release? sles9 for example doesn't 
> include the spellchecker. 

The package already included it IMHO. It's just not in the packagelist of the
distribution and it needn't to be now. It's completely optional. We don't have
to add any package anywhere.
Comment 24 Ludwig Nussel 2005-07-29 06:41:39 UTC
According to check_patchinfo we need to update the following packages on 9.1  
as they depend on mozilla 1.6:  
mozilla-cs,mozilla-deat,mozilla-hu,mozilla-ja,mozilla-ko,epiphany,epiphany-plugins,galeon  
  
On 9.0 the following packages depend on 1.4:  
mozilla-cs,mozilla-deat,mozilla-hu,epiphany,epiphany-plugins,galeon  
  
On 8.2 it's:  
mozilla-cs,mozilla-deat,mozilla-hu,galeon  
If any of those breaks we don't need to care I guess as 8.2 is end of life  
anyways.  
  
On NLD the following packages depend on 1.6:  
mozilla-cs,mozilla-deat,mozilla-hu,mozilla-ja,mozilla-ko,epiphany 
and on SLES9: 
mozilla-cs,mozilla-deat,mozilla-hu,mozilla-ja,mozilla-ko 
That's odd as there is a mozilla 1.7.8 release already, maybe it's not merged 
back or something. 
  
On SLEC the following packages depend on 1.4:  
galeon,mozilla-deat  
Comment 25 Marcus Meissner 2005-08-11 14:08:24 UTC
released. 
Comment 26 Marcus Meissner 2007-05-12 16:24:59 UTC
CVE-2005-2270
CVE-2005-2269
CVE-2005-2268
CVE-2005-2267
CVE-2005-2266
CVE-2005-1937
CVE-2005-2265
CVE-2005-2264
CVE-2005-2263
CVE-2005-2262
CVE-2005-2261
CVE-2005-2260
Comment 27 Thomas Biege 2009-10-13 21:27:03 UTC
CVE-2005-2270: CVSS v2 Base Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)