October 28, 2009, 7:34 pm
Resolved Bugs
530567 – CVE-2009-3380 Firefox crashes with evidence of memory corruption
530168 – CVE-2009-3376 Firefox download filename spoofing with RTL override
530167 – CVE-2009-3375 Firefox cross-origin data theft through document.getSelection()
530162 – CVE-2009-1563 Firefox heap buffer overflow in string to number conversion
530157 – CVE-2009-3374 Firefox chrome privilege escalation in XPCVariant::VariantDataToJS()
530156 – CVE-2009-3373 Firefox heap buffer overflow in GIF color map parser
530155 – CVE-2009-3372 Firefox crash in proxy auto-configuration regexp parsing
524815 – CVE-2009-3274 Firefox: Predictable /tmp pathname use
530151 – CVE-2009-3370 Firefox form history vulnerable to stealing
Update to new upstream Firefox version 3.5.4, fixing multiple security issues detailed in the upstream advisories: http://www.mozilla.org/security/known-vulnerabilities/firefox35.html#firefox3.5.4 Update also includes all packages depending on gecko-libs rebuilt against new version of Firefox / XULRunner…