<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="3dddf5e823b876ce1c3b5bd9784f0837"!-->
<update status="stable" from="maint-coord@suse.de" type="security" version="745">
  <id>dbg111-MozillaFirefox</id>
  <title>MozillaFirefox: Security update to version 3.0.8</title>
  <release>openSUSE 11.1</release>
  <issued date="1239095645"/>
  <references>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=488955" id="488955" title="bug number 488955" type="bugzilla"/>
  </references>
  <description>The Mozilla Firefox Browser was updated to the 3.0.8
release. It fixes several security issues:

MFSA 2009-13 / CVE-2009-1044: Security researcher Nils
reported via TippingPoint's Zero Day Initiative that the
XUL tree method _moveToEdgeShift was in some cases
triggering garbage collection routines on objects which
were still in use. In such cases, the browser would crash
when attempting to access a previously destroyed object and
this crash could be used by an attacker to run arbitrary
code on a victim's computer. This vulnerability was used by
the reporter to win the 2009 CanSecWest Pwn2Own contest.
This vulnerability does not affect Firefox 2, Thunderbird
2, or released versions of SeaMonkey.

MFSA 2009-12 / CVE-2009-1169:Security researcher Guido
Landi discovered that a XSL stylesheet could be used to
crash the browser during a XSL transformation. An attacker
could potentially use this crash to run arbitrary code on a
victim's computer. This vulnerability was also previously
reported as a stability problem by Ubuntu community member,
Andre. Ubuntu community member Michael Rooney reported
Andre's findings to Mozilla, and Mozilla community member
Martin helped reduce Andre's original testcase and
contributed a patch to fix the vulnerability.
</description>
  <pkglist>
    <collection>
        <package name="MozillaFirefox-debuginfo" arch="i586" version="3.0.8" release="1.1.1">
          <filename>MozillaFirefox-debuginfo-3.0.8-1.1.1.i586.rpm</filename>
        </package>
        <package name="MozillaFirefox-debuginfo" arch="ppc" version="3.0.8" release="1.1.1">
          <filename>MozillaFirefox-debuginfo-3.0.8-1.1.1.ppc.rpm</filename>
        </package>
        <package name="MozillaFirefox-debuginfo" arch="x86_64" version="3.0.8" release="1.1.1">
          <filename>MozillaFirefox-debuginfo-3.0.8-1.1.1.x86_64.rpm</filename>
        </package>
        <package name="MozillaFirefox-debugsource" arch="i586" version="3.0.8" release="1.1.1">
          <filename>MozillaFirefox-debugsource-3.0.8-1.1.1.i586.rpm</filename>
        </package>
        <package name="MozillaFirefox-debugsource" arch="ppc" version="3.0.8" release="1.1.1">
          <filename>MozillaFirefox-debugsource-3.0.8-1.1.1.ppc.rpm</filename>
        </package>
        <package name="MozillaFirefox-debugsource" arch="x86_64" version="3.0.8" release="1.1.1">
          <filename>MozillaFirefox-debugsource-3.0.8-1.1.1.x86_64.rpm</filename>
        </package>
        <package name="mozilla-xulrunner190-debuginfo" arch="i586" version="1.9.0.8" release="1.1.1">
          <filename>mozilla-xulrunner190-debuginfo-1.9.0.8-1.1.1.i586.rpm</filename>
        </package>
        <package name="mozilla-xulrunner190-debuginfo" arch="ppc" version="1.9.0.8" release="1.1.1">
          <filename>mozilla-xulrunner190-debuginfo-1.9.0.8-1.1.1.ppc.rpm</filename>
        </package>
        <package name="mozilla-xulrunner190-debuginfo" arch="x86_64" version="1.9.0.8" release="1.1.1">
          <filename>mozilla-xulrunner190-debuginfo-1.9.0.8-1.1.1.x86_64.rpm</filename>
        </package>
        <package name="mozilla-xulrunner190-debuginfo-32bit" arch="x86_64" version="1.9.0.8" release="1.1.1">
          <filename>mozilla-xulrunner190-debuginfo-32bit-1.9.0.8-1.1.1.x86_64.rpm</filename>
        </package>
        <package name="mozilla-xulrunner190-debugsource" arch="i586" version="1.9.0.8" release="1.1.1">
          <filename>mozilla-xulrunner190-debugsource-1.9.0.8-1.1.1.i586.rpm</filename>
        </package>
        <package name="mozilla-xulrunner190-debugsource" arch="ppc" version="1.9.0.8" release="1.1.1">
          <filename>mozilla-xulrunner190-debugsource-1.9.0.8-1.1.1.ppc.rpm</filename>
        </package>
        <package name="mozilla-xulrunner190-debugsource" arch="x86_64" version="1.9.0.8" release="1.1.1">
          <filename>mozilla-xulrunner190-debugsource-1.9.0.8-1.1.1.x86_64.rpm</filename>
        </package>
    </collection>
  </pkglist>
</update>
