安全研究

安全漏洞
Mozilla Firefox 2.0.0.18和3.0.4版本修复多个安全漏洞

发布日期:2008-11-13
更新日期:2008-11-14

受影响系统:
Mozilla Firefox < 3.0.4
Mozilla Firefox < 2.0.0.18
Mozilla Thunderbird < 3.0.4
Mozilla Thunderbird < 2.0.0.18
Mozilla SeaMonkey < 1.1.13
不受影响系统:
Mozilla Firefox 3.0.4
Mozilla Firefox 2.0.0.18
Mozilla Thunderbird 3.0.4
Mozilla Thunderbird 2.0.0.18
Mozilla SeaMonkey 1.1.13
描述:
BUGTRAQ  ID: 32281,32351
CVE(CAN) ID: CVE-2008-5012,CVE-2008-5013,CVE-2008-5014,CVE-2008-5016,CVE-2008-5017,CVE-2008-5018,CVE-2008-5019,CVE-2008-5021,CVE-2008-5022,CVE-2008-5023,CVE-2008-5024,CVE-2008-5015,CVE-2008-0017

Firefox是Mozilla所发布的开源WEB浏览器。

Firefox中的多个安全漏洞允许恶意用户泄露敏感信息、绕过安全限制、执行欺骗攻击或入侵用户系统。由于代码共享,Thunderbird和SeaMonkey也受这些漏洞的影响。

1) 攻击者可能结合HTTP重新定向利用画布单元绕过同源限制访问其他域中任意图形的内容。如果受害用户登录的站点在图形中存储了数据的话,攻击者就可以窃取敏感信息。

2) 由于没有充分地检查是否正确地动态上传了Flash模块,从外部JavaScript函数动态上传其自身的SWF文件可能导致浏览器访问已不再映射到Flash模块的内存地址,造成拒绝服务。

3) 通过篡改window.__proto__.__proto__对象,攻击者就可以导致浏览器锁定非原始对象,造成崩溃。

4) 在与chrome页面或特权的about:页面相同标签页中打开file: URI时,就会给予其chrome权限,这允许攻击者以chrome权限执行任意JavaScript。

5) Firefox和其他Mozilla产品的浏览器引擎中存在多个BUG,其中的一些BUG在某些情况下可能导致内存破坏。

6) 浏览器重置功能可能导致破坏同源策略,以其他站点的环境执行JavaScript。

7) Mozilla解析http-index-format MIME类型的方式存在漏洞,远程攻击者可以在HTTP索引响应中发送特制的200头导致浏览器崩溃或在用户机器上执行任意代码。

8) Mozilla的DOM创建代码中存在漏洞,通过在完成初始化之前修改文件输入单元的某些属性,就可以利用这个漏洞。在调用修改后输入单元的blur方式的时候,浏览器就会访问未初始化的内存,导致崩溃。

9) 攻击者可以绕过nsXMLHttpRequest::NotifyEventListeners()中的同源检查,导致以其他站点的环境执行JavaScript。

10) -moz-binding CSS属性中的漏洞可能允许绕过安全检查,攻击者可以通过使用相对路径的签名JAR替换样式表,然后使用-moz-binding属性向JAR中注入恶意脚本,注入的脚本会以签名JAR的权限执行。

11) 由于没有正确地转义名称空间中的引号字符,用于解析E4X文档中默认名称空间的方式存在错误。

<*来源:Chris Evans (chris@ferret.lmh.ox.ac.uk
        moz_bug_r_a4 (moz_bug_r_a4@yahoo.com
        Georgi Guninski (guninski@guninski.com
        Collin Jackson (collinj@cs.stanford.edu
  
  链接:http://secunia.com/advisories/32713/
        http://secunia.com/advisories/32693/
        http://www.mozilla.org/security/announce/2008/mfsa2008-48.html
        http://www.mozilla.org/security/announce/2008/mfsa2008-49.html
        http://www.mozilla.org/security/announce/2008/mfsa2008-50.html
        http://www.mozilla.org/security/announce/2008/mfsa2008-51.html
        http://www.mozilla.org/security/announce/2008/mfsa2008-52.html
        http://www.mozilla.org/security/announce/2008/mfsa2008-53.html
        http://www.mozilla.org/security/announce/2008/mfsa2008-54.html
        http://www.mozilla.org/security/announce/2008/mfsa2008-55.html
        http://www.mozilla.org/security/announce/2008/mfsa2008-56.html
        http://www.mozilla.org/security/announce/2008/mfsa2008-57.html
        http://www.mozilla.org/security/announce/2008/mfsa2008-58.html
        https://www.redhat.com/support/errata/RHSA-2008-0978.html
        https://www.redhat.com/support/errata/RHSA-2008-0977.html
        http://www.debian.org/security/2008/dsa-1669
        https://www.redhat.com/support/errata/RHSA-2008-0976.html
*>

测试方法:

警 告

以下程序(方法)可能带有攻击性,仅供安全研究与教学之用。使用者风险自负!

<html>
<head>
<script type="text/javascript">

window.__proto__.__proto__ = [{}];
for (var j in window);

</script>
</head>
<body>
</body>
</html>


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
    <head>
        <meta http-equiv="Content-Type" content="text/html;
charset=utf-8">
        <title>wushi0016</title>
        <script type='text/javascript'>
            function goodbye() {
                nodeList = document.getElementsByTagName("input");
                testNode = nodeList.item(0);
                testNode.type = "yabba-dabba-do";
                return testNode.blur();
            }
        </script>
    </head>
    <body onload="goodbye()">
        <input type="file" />
    </body>
</html>

https://bugzilla.mozilla.org/attachment.cgi?id=333792

建议:
临时解决方法:

* 禁用JavaScript。

厂商补丁:

Debian
------
Debian已经为此发布了一个安全公告(DSA-1669-1)以及相应补丁:
DSA-1669-1:New xulrunner packages fix several vulnerabilities
链接:http://www.debian.org/security/2008/dsa-1669

补丁下载:
Source archives:

http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.15~pre080614h.orig.tar.gz
Size/MD5 checksum: 43763318 269ce29df92d5053f6d0fc659717c18b
http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.15~pre080614h-0etch1.diff.gz
Size/MD5 checksum:   144529 7f517d4bd904df70b6ead61c85e5eb71
http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.15~pre080614h-0etch1.dsc
Size/MD5 checksum:     1984 2f56bfad80749a3af01a185cfc3a19e5

Architecture independent packages:

http://security.debian.org/pool/updates/main/x/xulrunner/libsmjs-dev_1.8.0.15~pre080614h-0etch1_all.deb
Size/MD5 checksum:    37108 ac110712c554bc90e6156ddf375c20e6
http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-dev_1.8.0.15~pre080614h-0etch1_all.deb
Size/MD5 checksum:   231230 75b9b3c909279253b358fe73c87ae920
http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs-dev_1.8.0.15~pre080614h-0etch1_all.deb
Size/MD5 checksum:   176254 6bffe2de1c86a23ea69141da310df072
http://security.debian.org/pool/updates/main/x/xulrunner/libsmjs1_1.8.0.15~pre080614h-0etch1_all.deb
Size/MD5 checksum:    37070 a83bac43079f44db9c6a8ba23638481a
http://security.debian.org/pool/updates/main/x/xulrunner/libxul-dev_1.8.0.15~pre080614h-0etch1_all.deb
Size/MD5 checksum:  2637220 39ab7259a30e82173bd736ff4d26b366
http://security.debian.org/pool/updates/main/x/xulrunner/libxul-common_1.8.0.15~pre080614h-0etch1_all.deb
Size/MD5 checksum:  1051896 e9a4021391f5153eaca415b5f6e93fe6
http://security.debian.org/pool/updates/main/x/xulrunner/libmozillainterfaces-java_1.8.0.15~pre080614h-0etch1_all.deb
Size/MD5 checksum:  1032080 388688d0bfcb0a5c4abde96f9fb24c98
http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-dev_1.8.0.15~pre080614h-0etch1_all.deb
Size/MD5 checksum:   207752 516386bf8588e6210ac121d38cc67308

alpha architecture (DEC Alpha)

http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.15~pre080614h-0etch1_alpha.deb
Size/MD5 checksum:   292440 187aad52fc63d5fdca6521359b6a360a
http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d_1.8.0.15~pre080614h-0etch1_alpha.deb
Size/MD5 checksum:   386628 536f366c637868a9f27746f776d37a31
http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d_1.8.0.15~pre080614h-0etch1_alpha.deb
Size/MD5 checksum:  7346254 4b946a8f3cde017ff0580a9a97687e7e
http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d-dbg_1.8.0.15~pre080614h-0etch1_alpha.deb
Size/MD5 checksum:   765180 673c7bd51731495926293ff92301b327
http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-tools_1.8.0.15~pre080614h-0etch1_alpha.deb
Size/MD5 checksum:   739026 d96d09c1ecbf280a77ee5f4fe4a7d1a3
http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d-dbg_1.8.0.15~pre080614h-0etch1_alpha.deb
Size/MD5 checksum:  3188906 5cfc3218c50b909a4e64e06d09774224
http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.8.0.15~pre080614h-0etch1_alpha.deb
Size/MD5 checksum:    53106 20768cf8e831ad71f45cccb657eb3448
http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-gnome-support_1.8.0.15~pre080614h-0etch1_alpha.deb
Size/MD5 checksum:    71212 0f8fe3e84b4faf38d25347f3dfdc463d
http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d-dbg_1.8.0.15~pre080614h-0etch1_alpha.deb
Size/MD5 checksum:   302616 01109cc8d78492dbbbcbad4756255e8b
http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d_1.8.0.15~pre080614h-0etch1_alpha.deb
Size/MD5 checksum:   162612 9af11053277aa8398ed4852890076b41
http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.8.0.15~pre080614h-0etch1_alpha.deb
Size/MD5 checksum:   129930 7b03aa5bcfb76b15d860621806ffbccb
http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d_1.8.0.15~pre080614h-0etch1_alpha.deb
Size/MD5 checksum:   905638 3a558f50e394d109e4d306559b48283a
http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d-dbg_1.8.0.15~pre080614h-0etch1_alpha.deb
Size/MD5 checksum: 46017420 d5f238086f7f77270d31a3d34c4b9a35

amd64 architecture (AMD x86_64 (AMD64))

http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d-dbg_1.8.0.15~pre080614h-0etch1_amd64.deb
Size/MD5 checksum:  3177838 69775ab87c4c2677faf2fbe8ed1c4617
http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d_1.8.0.15~pre080614h-0etch1_amd64.deb
Size/MD5 checksum:   148946 d179d55f788e6fbaf2259446d79c342c
http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d_1.8.0.15~pre080614h-0etch1_amd64.deb
Size/MD5 checksum:   356028 7e6147ae3531fb175cdf637a25f4dc33
http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.8.0.15~pre080614h-0etch1_amd64.deb
Size/MD5 checksum:   126632 7795ccbd3edeb72623450ec3b0c407f9
http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d_1.8.0.15~pre080614h-0etch1_amd64.deb
Size/MD5 checksum:   810296 09a7217cbe1b1180c71ae7b16a306747
http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-gnome-support_1.8.0.15~pre080614h-0etch1_amd64.deb
Size/MD5 checksum:    69360 2e6a6559a22ce55f2b6b9331b0bfbd68
http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d-dbg_1.8.0.15~pre080614h-0etch1_amd64.deb
Size/MD5 checksum:   755560 ade61fc66030701ba9d62086288403bf
http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.15~pre080614h-0etch1_amd64.deb
Size/MD5 checksum:   278728 9124a96cd6b202d076a35829b542f6f6
http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d_1.8.0.15~pre080614h-0etch1_amd64.deb
Size/MD5 checksum:  6343406 7683694615827e8674c59034978b86b1
http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-tools_1.8.0.15~pre080614h-0etch1_amd64.deb
Size/MD5 checksum:   671010 7984141447417ad48f657e5752a197c5
http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d-dbg_1.8.0.15~pre080614h-0etch1_amd64.deb
Size/MD5 checksum: 45217322 e18a8c41099328f6979c27614a81b83c
http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.8.0.15~pre080614h-0etch1_amd64.deb
Size/MD5 checksum:    53340 803733e356f2f74037a6f3a7d9a4a91f
http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d-dbg_1.8.0.15~pre080614h-0etch1_amd64.deb
Size/MD5 checksum:   304624 36ced9e2336ccaa648a15c76707f8645

arm architecture (ARM)

http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.8.0.15~pre080614h-0etch1_arm.deb
Size/MD5 checksum:    50992 e655c2956e96e317f0a32c4122b34d3b
http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d_1.8.0.15~pre080614h-0etch1_arm.deb
Size/MD5 checksum:   732278 0f2bce0bc1d0b13b36c5b45465516b04
http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d-dbg_1.8.0.15~pre080614h-0etch1_arm.deb
Size/MD5 checksum: 44746676 980a58b4e66d48cb8e913a3846081001
http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d_1.8.0.15~pre080614h-0etch1_arm.deb
Size/MD5 checksum:  5368942 8a6560e2302db9686218205d5c347e16
http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d-dbg_1.8.0.15~pre080614h-0etch1_arm.deb
Size/MD5 checksum:   290778 305d1c3d9f893d75d6b92e7b02819bdb
http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-gnome-support_1.8.0.15~pre080614h-0etch1_arm.deb
Size/MD5 checksum:    63054 72ef44af146319f439a44197b7d4743a
http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-tools_1.8.0.15~pre080614h-0etch1_arm.deb
Size/MD5 checksum:   594214 7c6d64740f289185389b15b790d645ad
http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d-dbg_1.8.0.15~pre080614h-0etch1_arm.deb
Size/MD5 checksum:  2969882 9acb7cc81292692bedc12f523fb25f19
http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.8.0.15~pre080614h-0etch1_arm.deb
Size/MD5 checksum:   119110 249f11b4d5c08aa5d1bd4d74221e0c38
http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d_1.8.0.15~pre080614h-0etch1_arm.deb
Size/MD5 checksum:   136886 ce4ac4ba2050790518c8528c2a415f02
http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d_1.8.0.15~pre080614h-0etch1_arm.deb
Size/MD5 checksum:   326184 5c4f59cedea7db6e7dd5d9a9522c24c7
http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.15~pre080614h-0etch1_arm.deb
Size/MD5 checksum:   260186 a9ac930957d7416cc7a160b6044f96b3
http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d-dbg_1.8.0.15~pre080614h-0etch1_arm.deb
Size/MD5 checksum:   705170 fbdb65410c70fa8805ce72c0c97c179b

hppa architecture (HP PA RISC)

http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d-dbg_1.8.0.15~pre080614h-0etch1_hppa.deb
Size/MD5 checksum:   302322 61f8282f8cd276c69d24fa6824761a4e
http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-tools_1.8.0.15~pre080614h-0etch1_hppa.deb
Size/MD5 checksum:   703692 06452f715efa7e66c5d22e3866db2c0e
http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d-dbg_1.8.0.15~pre080614h-0etch1_hppa.deb
Size/MD5 checksum: 46134820 cd29259ebf9caf9dca35560e806f984b
http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.8.0.15~pre080614h-0etch1_hppa.deb
Size/MD5 checksum:    53462 27cc05a50b56afbe49b5fa3b30672e58
http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d_1.8.0.15~pre080614h-0etch1_hppa.deb
Size/MD5 checksum:   390962 9fed7a335de83d6333b1c2e5c9bedfea
http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d_1.8.0.15~pre080614h-0etch1_hppa.deb
Size/MD5 checksum:   161670 b9c1c8bfdf1db386d301dbb03d5c403c
http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d_1.8.0.15~pre080614h-0etch1_hppa.deb
Size/MD5 checksum:  7552110 91b773e5373158755289930d39ff7470
http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.8.0.15~pre080614h-0etch1_hppa.deb
Size/MD5 checksum:   132130 8a5c0d6d99049ab1a499c584a602d7dc
http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d-dbg_1.8.0.15~pre080614h-0etch1_hppa.deb
Size/MD5 checksum:   753050 bc5f4f2723836580fbfbaed5a71272b1
http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.15~pre080614h-0etch1_hppa.deb
Size/MD5 checksum:   287828 b0a84eacece17a811defbb7b30c757f7
http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d-dbg_1.8.0.15~pre080614h-0etch1_hppa.deb
Size/MD5 checksum:  3104660 47ab34d7126c8f64cbaa269f7a2afdd4
http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-gnome-support_1.8.0.15~pre080614h-0etch1_hppa.deb
Size/MD5 checksum:    70902 67634b0f71a03fd87476396172ccffe7
http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d_1.8.0.15~pre080614h-0etch1_hppa.deb
Size/MD5 checksum:   874810 ae271a1ca58484ddf43ba14d66387a06

i386 architecture (Intel ia32)

http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d_1.8.0.15~pre080614h-0etch1_i386.deb
Size/MD5 checksum:  5383100 25dfd28aef781b5ca352f0232aa211e9
http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-gnome-support_1.8.0.15~pre080614h-0etch1_i386.deb
Size/MD5 checksum:    63834 2691c48af147f802e684e030d3e04701
http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d-dbg_1.8.0.15~pre080614h-0etch1_i386.deb
Size/MD5 checksum: 44696504 d3f45db182ee59de39c86b5ea12ad01a
http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d-dbg_1.8.0.15~pre080614h-0etch1_i386.deb
Size/MD5 checksum:   714892 13951abf0a2c9030ed8ff163f6259351
http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d-dbg_1.8.0.15~pre080614h-0etch1_i386.deb
Size/MD5 checksum:   296446 b8a9da32c6184afac2f6649ce8ad5847
http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d_1.8.0.15~pre080614h-0etch1_i386.deb
Size/MD5 checksum:   139824 13cb243ffadc155900abb00835a6507b
http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d-dbg_1.8.0.15~pre080614h-0etch1_i386.deb
Size/MD5 checksum:  3033280 705838b8f872cd335ce180cbad03cdb1
http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d_1.8.0.15~pre080614h-0etch1_i386.deb
Size/MD5 checksum:   337086 87db12ec21885f3833560b334e1af3e4
http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.8.0.15~pre080614h-0etch1_i386.deb
Size/MD5 checksum:    50868 707ae35a901c3e9ae1ec40c3c00f7921
http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d_1.8.0.15~pre080614h-0etch1_i386.deb
Size/MD5 checksum:   742916 bd2ff5be8f3a94deaf104bafe477a9d3
http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.8.0.15~pre080614h-0etch1_i386.deb
Size/MD5 checksum:   118548 8ce74f7ef876172271c72c3c411cbd33
http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.15~pre080614h-0etch1_i386.deb
Size/MD5 checksum:   267924 7d8bcf96f9244594b9a937b6224fa097
http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-tools_1.8.0.15~pre080614h-0etch1_i386.deb
Size/MD5 checksum:   628432 e109e6b6aa054ced99a8844df67ced17

ia64 architecture (Intel ia64)

http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.8.0.15~pre080614h-0etch1_ia64.deb
Size/MD5 checksum:   150698 ab8c0d92e7ac8bb48b604d6ea36197e4
http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d-dbg_1.8.0.15~pre080614h-0etch1_ia64.deb
Size/MD5 checksum:   287530 c9db22cd56cc17dd619cbd95b3b45075
http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d_1.8.0.15~pre080614h-0etch1_ia64.deb
Size/MD5 checksum:   532996 b7c0eadd7ddd85642c761e29cf7cafc3
http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d-dbg_1.8.0.15~pre080614h-0etch1_ia64.deb
Size/MD5 checksum:   755714 eae62df93df4e8bb5f0deda5dd4ec4e9
http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d-dbg_1.8.0.15~pre080614h-0etch1_ia64.deb
Size/MD5 checksum:  3051824 e516b3a4601b8350faeff14a47b298b2
http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.15~pre080614h-0etch1_ia64.deb
Size/MD5 checksum:   334028 3a0cc332ff6b095193b7c70952d13532
http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d-dbg_1.8.0.15~pre080614h-0etch1_ia64.deb
Size/MD5 checksum: 45437166 c3a164f9d48b0c96277be51a441915dd
http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d_1.8.0.15~pre080614h-0etch1_ia64.deb
Size/MD5 checksum:  1121458 5f97e14d0837fc02241fec88c81f706a
http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-gnome-support_1.8.0.15~pre080614h-0etch1_ia64.deb
Size/MD5 checksum:    80872 a36655812bc3600a00ada31f7b5af8d7
http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d_1.8.0.15~pre080614h-0etch1_ia64.deb
Size/MD5 checksum:  9685646 1ec5fef153646e888c1e28c306e0edae
http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.8.0.15~pre080614h-0etch1_ia64.deb
Size/MD5 checksum:    57870 97e42348ab45451378fd360df57ee996
http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d_1.8.0.15~pre080614h-0etch1_ia64.deb
Size/MD5 checksum:   198742 bbba497dfc3b9e556082c6357e3dfde5
http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-tools_1.8.0.15~pre080614h-0etch1_ia64.deb
Size/MD5 checksum:   937264 e538ce36bc43ed941394d13ee0d52a53

mipsel architecture (MIPS (Little Endian))

http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.15~pre080614h-0etch1_mipsel.deb
Size/MD5 checksum:   274964 8cc829f5a01dabeb02357a57f26de510
http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-gnome-support_1.8.0.15~pre080614h-0etch1_mipsel.deb
Size/MD5 checksum:    65170 7ca8f4598376b9e35cf62096cd0663aa
http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d_1.8.0.15~pre080614h-0etch1_mipsel.deb
Size/MD5 checksum:   785530 464969451374f49191184fdd78363633
http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d_1.8.0.15~pre080614h-0etch1_mipsel.deb
Size/MD5 checksum:   351424 21b9b17a786ee9e8a28bff8e2cb7b067
http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d-dbg_1.8.0.15~pre080614h-0etch1_mipsel.deb
Size/MD5 checksum:  3187334 da69f74749bc9d111d4a1e4597b7a075
http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.8.0.15~pre080614h-0etch1_mipsel.deb
Size/MD5 checksum:    52554 fd3706c6cfccb0442e3b092e184adfbb
http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.8.0.15~pre080614h-0etch1_mipsel.deb
Size/MD5 checksum:   118606 3f78ef107edbf118d6da0a504b1a6c90
http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d_1.8.0.15~pre080614h-0etch1_mipsel.deb
Size/MD5 checksum:  5756448 5d27b51600c5aecf30d82872ea5ef976
http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-tools_1.8.0.15~pre080614h-0etch1_mipsel.deb
Size/MD5 checksum:   670678 861a749803d3906cd21d77e8f45ecae6
http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d-dbg_1.8.0.15~pre080614h-0etch1_mipsel.deb
Size/MD5 checksum:   305782 739ba0f2bcb1c8204734225044648734
http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d-dbg_1.8.0.15~pre080614h-0etch1_mipsel.deb
Size/MD5 checksum: 45367986 ff5cbe1732d1dae74bb822119d86a925
http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d-dbg_1.8.0.15~pre080614h-0etch1_mipsel.deb
Size/MD5 checksum:   766946 438965e5962147e88570d0f0502b43fd
http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d_1.8.0.15~pre080614h-0etch1_mipsel.deb
Size/MD5 checksum:   146350 3cdb4a00d928cd6d222841d961edcaf8

powerpc architecture (PowerPC)

http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.8.0.15~pre080614h-0etch1_powerpc.deb
Size/MD5 checksum:   124684 defd7a2555c14d3a0f06c971bea7a451
http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d_1.8.0.15~pre080614h-0etch1_powerpc.deb
Size/MD5 checksum:   810014 20a1a9dbf4a3ad3eb8fd0d35ee64342f
http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d-dbg_1.8.0.15~pre080614h-0etch1_powerpc.deb
Size/MD5 checksum: 46948440 e99e9c17fe4fff09ffa231ab61344926
http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d-dbg_1.8.0.15~pre080614h-0etch1_powerpc.deb
Size/MD5 checksum:  3207304 106c8e04e7e69a403629a08113af60b1
http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.8.0.15~pre080614h-0etch1_powerpc.deb
Size/MD5 checksum:    53822 06e6021788dfa6ed42f73c42dc42d4c6
http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d_1.8.0.15~pre080614h-0etch1_powerpc.deb
Size/MD5 checksum:   148102 9ee04ff3dbad84bebf8536adf942da51
http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.15~pre080614h-0etch1_powerpc.deb
Size/MD5 checksum:   279498 2a91ba4052440b688a084142034094b2
http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d_1.8.0.15~pre080614h-0etch1_powerpc.deb
Size/MD5 checksum:   350088 2cdf2cc81b27d7ecab9c8045f9fa3f4c
http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d-dbg_1.8.0.15~pre080614h-0etch1_powerpc.deb
Size/MD5 checksum:   774852 68f4364621232a4ccaf379739fe90844
http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-tools_1.8.0.15~pre080614h-0etch1_powerpc.deb
Size/MD5 checksum:   640770 caf3b284405fe5c5c630aa3079b03a98
http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-gnome-support_1.8.0.15~pre080614h-0etch1_powerpc.deb
Size/MD5 checksum:    65030 1fb0c63b382b718542a93f6a5044c5dd
http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d_1.8.0.15~pre080614h-0etch1_powerpc.deb
Size/MD5 checksum:  6111652 8084da84956a7dd10fb41a748571d1ce
http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d-dbg_1.8.0.15~pre080614h-0etch1_powerpc.deb
Size/MD5 checksum:   311138 dd2cdb789b213198e2d07793ff6cda7d

s390 architecture (IBM S/390)

http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d_1.8.0.15~pre080614h-0etch1_s390.deb
Size/MD5 checksum:   372540 2a5ba267a8fe0873efd38cd4b7901cc6
http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.15~pre080614h-0etch1_s390.deb
Size/MD5 checksum:   282950 45ee96102546cd3721b3035fa66625d5
http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.8.0.15~pre080614h-0etch1_s390.deb
Size/MD5 checksum:   127476 c84ebe0a16a997feec58a7e4b8cb680e
http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d_1.8.0.15~pre080614h-0etch1_s390.deb
Size/MD5 checksum:  6815988 904ffedb7cf2d3951fa3ba419db97bf8
http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-tools_1.8.0.15~pre080614h-0etch1_s390.deb
Size/MD5 checksum:   688656 68fe7ceca84ad73d3af368cafcc8bb8d
http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d-dbg_1.8.0.15~pre080614h-0etch1_s390.deb
Size/MD5 checksum:  3182688 e31c62d66bbc8c56803ad26bebdd759b
http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.8.0.15~pre080614h-0etch1_s390.deb
Size/MD5 checksum:    54072 143164871ff9749b6b6b4430cb32041b
http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d-dbg_1.8.0.15~pre080614h-0etch1_s390.deb
Size/MD5 checksum:   756986 e369095cb45670013a7842c16e4b705d
http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-gnome-support_1.8.0.15~pre080614h-0etch1_s390.deb
Size/MD5 checksum:    69980 9d100c8a6ce21bf7072068084fb0d686
http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d-dbg_1.8.0.15~pre080614h-0etch1_s390.deb
Size/MD5 checksum:   306772 7d5c5de6d3b220c4ed01f0f41fdee5bc
http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d_1.8.0.15~pre080614h-0etch1_s390.deb
Size/MD5 checksum:   899720 3ac2e0a53da7a24c693705e38222063e
http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d_1.8.0.15~pre080614h-0etch1_s390.deb
Size/MD5 checksum:   160818 24d85411a0b362051bf4a01071b62fba
http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d-dbg_1.8.0.15~pre080614h-0etch1_s390.deb
Size/MD5 checksum: 46082350 b519a68a5f31a04f0f5e236845487bde

sparc architecture (Sun SPARC/UltraSPARC)

http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d_1.8.0.15~pre080614h-0etch1_sparc.deb
Size/MD5 checksum:   719922 5bc9efc37cef094718adb36d5a016179
http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d-dbg_1.8.0.15~pre080614h-0etch1_sparc.deb
Size/MD5 checksum:   676172 b0241dcaf3f7153dc9145a9c5babe787
http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-gnome-support_1.8.0.15~pre080614h-0etch1_sparc.deb
Size/MD5 checksum:    63314 4e65fa183e0e12f543d0eb669c6d670d
http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.8.0.15~pre080614h-0etch1_sparc.deb
Size/MD5 checksum:    51986 303f9de96490f0633aab95306fe30f05
http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-tools_1.8.0.15~pre080614h-0etch1_sparc.deb
Size/MD5 checksum:   586488 6236e767259e06e3d3b4c062ee6362a2
http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d-dbg_1.8.0.15~pre080614h-0etch1_sparc.deb
Size/MD5 checksum: 44786670 07e5e02fced64c2303043cffa255a4ee
http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d_1.8.0.15~pre080614h-0etch1_sparc.deb
Size/MD5 checksum:  5691050 3f4e9e5e4feff6a386094101820c9f11
http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d_1.8.0.15~pre080614h-0etch1_sparc.deb
Size/MD5 checksum:   323786 ec3a7690b2e154e51132d1983a72be3b
http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d-dbg_1.8.0.15~pre080614h-0etch1_sparc.deb
Size/MD5 checksum:  2854664 214407a606e9b94ab300ea306d1c0e18
http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d_1.8.0.15~pre080614h-0etch1_sparc.deb
Size/MD5 checksum:   136908 be6e397388eb412bcbf9ec6a014b00f5
http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.8.0.15~pre080614h-0etch1_sparc.deb
Size/MD5 checksum:   118720 346aa123c24a426716a1576c3c285dc6
http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d-dbg_1.8.0.15~pre080614h-0etch1_sparc.deb
Size/MD5 checksum:   284372 63ba1195ae71a92c6b780004c0c7e2da
http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.15~pre080614h-0etch1_sparc.deb
Size/MD5 checksum:   261348 690d1985e4d4cd1c5b076e76af55ac84

补丁安装方法:

1. 手工安装补丁包:

  首先,使用下面的命令来下载补丁软件:
  # wget url  (url是补丁下载链接地址)

  然后,使用下面的命令来安装补丁:  
  # dpkg -i file.deb (file是相应的补丁名)

2. 使用apt-get自动安装补丁包:

   首先,使用下面的命令更新内部数据库:
   # apt-get update
  
   然后,使用下面的命令安装更新软件包:
   # apt-get upgrade

Mozilla
-------
目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载:

http://www.mozilla.com/en-US/firefox/all.html

RedHat
------
RedHat已经为此发布了一个安全公告(RHSA-2008:0976-01)以及相应补丁:
RHSA-2008:0976-01:Moderate: thunderbird security update
链接:https://www.redhat.com/support/errata/RHSA-2008-0976.html

浏览次数:3835
严重程度:0(网友投票)
本安全漏洞由绿盟科技翻译整理,版权所有,未经许可,不得转载
绿盟科技给您安全的保障