<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="9ca8a268825abc5af253fffbb2888dd8"!-->
<update status="stable" from="maint-coord@suse.de" type="security" version="1510">
  <id>dbg111-mozilla-nspr</id>
  <title>mozilla-nspr: Security update to 4.8.2</title>
  <release>openSUSE 11.1</release>
  <issued date="1257334379"/>
  <references>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=546371" id="546371" title="bug number 546371" type="bugzilla"/>
  </references>
  <description>This update fixes a bug in the Mozilla NSPR helper
libraries, which could be used by remote attackers to
potentially execute code via javascript vectors.

MFSA 2009-59 / CVE-2009-1563: Security researcher Alin Rad
Pop of Secunia Research reported a heap-based buffer
overflow in Mozilla's string to floating point number
conversion routines. Using this vulnerability an attacker
could craft some malicious JavaScript code containing a
very long string to be converted to a floating point number
which would result in improper memory allocation and the
execution of an arbitrary memory location. This
vulnerability could thus be leveraged by the attacker to
run arbitrary code on a victim's computer.
</description>
  <pkglist>
    <collection>
        <package name="mozilla-nspr-debuginfo" arch="i586" version="4.8.2" release="1.1.1">
          <filename>mozilla-nspr-debuginfo-4.8.2-1.1.1.i586.rpm</filename>
        </package>
        <package name="mozilla-nspr-debuginfo" arch="ppc" version="4.8.2" release="1.1.1">
          <filename>mozilla-nspr-debuginfo-4.8.2-1.1.1.ppc.rpm</filename>
        </package>
        <package name="mozilla-nspr-debuginfo" arch="x86_64" version="4.8.2" release="1.1.1">
          <filename>mozilla-nspr-debuginfo-4.8.2-1.1.1.x86_64.rpm</filename>
        </package>
        <package name="mozilla-nspr-debuginfo-32bit" arch="x86_64" version="4.8.2" release="1.1.1">
          <filename>mozilla-nspr-debuginfo-32bit-4.8.2-1.1.1.x86_64.rpm</filename>
        </package>
        <package name="mozilla-nspr-debuginfo-64bit" arch="ppc" version="4.8.2" release="1.1.1">
          <filename>mozilla-nspr-debuginfo-64bit-4.8.2-1.1.1.ppc.rpm</filename>
        </package>
        <package name="mozilla-nspr-debugsource" arch="i586" version="4.8.2" release="1.1.1">
          <filename>mozilla-nspr-debugsource-4.8.2-1.1.1.i586.rpm</filename>
        </package>
        <package name="mozilla-nspr-debugsource" arch="ppc" version="4.8.2" release="1.1.1">
          <filename>mozilla-nspr-debugsource-4.8.2-1.1.1.ppc.rpm</filename>
        </package>
        <package name="mozilla-nspr-debugsource" arch="x86_64" version="4.8.2" release="1.1.1">
          <filename>mozilla-nspr-debugsource-4.8.2-1.1.1.x86_64.rpm</filename>
        </package>
    </collection>
  </pkglist>
</update>
