Patches & Updates
Deploy and monitor updates to all of your systems through Sun from anywhere you have an Internet connection.
Start today with Knowledge-based software update services for Solaris and Linux.
Please review changes to Patch Access.
Patches:
Download Patch (7149845 bytes): HTTP 
Download Signed Patch (7153977 bytes): HTTP 
Signed Patch Documentation  Patch Finder

Obsoleted by: 120671-05 Mozilla 1.7 for Solaris 8 and 9


Disclaimer: 

Please note: Although OBSOLETED patches are available on SunSolve, Sun recommends using the most recent patches and the most recent revision of those patches. OBSOLETED patches do not include the latest bug fixes and/or product enhancements, and may require the installation of additional patches as a corrective measure.

Status: OBSOLETE
Patch Id: 120671-04
***********************************************************************
READ THE TERMS OF THE AGREEMENT ("AGREEMENT") IN THE LEGAL_LICENSE.TXT
FILE CAREFULLY BEFORE USING THIS SOFTWARE. BY USING THE SOFTWARE, YOU
AGREE TO THE TERMS OF THIS AGREEMENT. IF YOU DO NOT AGREE TO ALL OF THE
TERMS, PROMPTLY DESTROY THE UNUSED SOFTWARE.
***********************************************************************
Summary: Obsoleted by: 120671-05 Mozilla 1.7 for Solaris 8 and 9
Date:  Apr/06/2007
Installation Requirements:
NA
Solaris Release: 8 9
Sun OS Release: 5.8 5.9
Unbundled Product: Mozilla
Unbundled Release: 1.7
Xref: This patch available for x86 as 120672
Topic: 
Relevant Architecture: sparc
BugId's fixed with this patch:

6352958 6412730 6415123 6415128 6415131 6415133 6415135 6415138 6415142 6415143 6424493 6424545 6424548 6424551 6424560 6424563 6424567 6424568 6424573 6424574 6424577 6424579 6447020 6447021 6447022 6458750 6458753 6458754 6461074 6488248 6499438

Changes incorporated in this version:

6488248 6499438 6447022

Patches accumulated and obsoleted by this patch:

Patches which conflict with this patch: 

Required Patches:

Obsoleted by:
 
Files Included in this Patch: 
<install_dir>/sfw/lib/mozilla/chrome/comm.jar
<install_dir>/sfw/lib/mozilla/components/libaddrbook.so
<install_dir>/sfw/lib/mozilla/components/libappcomps.so
<install_dir>/sfw/lib/mozilla/components/libcaps.so
<install_dir>/sfw/lib/mozilla/components/libcomposer.so
<install_dir>/sfw/lib/mozilla/components/libgklayout.so
<install_dir>/sfw/lib/mozilla/components/libhtmlpars.so
<install_dir>/sfw/lib/mozilla/components/libpipboot.so
<install_dir>/sfw/lib/mozilla/components/libpipnss.so
<install_dir>/sfw/lib/mozilla/components/libxpconnect.so
<install_dir>/sfw/lib/mozilla/greprefs/all.js
<install_dir>/sfw/lib/mozilla/libmozjs.so
<install_dir>/sfw/lib/mozilla/libnss3.so
<install_dir>/sfw/lib/mozilla/libsmime3.so
<install_dir>/sfw/lib/mozilla/libsoftokn3.so
Problem Description: 
6488248 [MFSA 2006-60] Mozilla(NSS) RSA signature forgery issue
6499438 [MFSA#2006-66] RSA Signature Forgery (variant)
6447022 [MSFA 2006-37] Mozilla may process content-defined setters on object prototypes with elevated priv
 
(from 120671-03)
 
6415123 [MFSA 2006-24] Mozilla crypto.generateCRMFRequest() vulnerability
6447020 [MFSA 2006-43] Mozilla privilege escalation using addSelectionListener
6447021 [MFSA 2006-38] Mozilla contains a buffer overflow vulnerability in crypto.signText()
6458750 [MFSA 2006-49] Mozilla products VCard attachment buffer overflow
6458753 [MFSA 2006-50] Mozilla JavaScript engine contains multiple integer overflows
6458754 [MFSA 2006-51] Mozilla products fail to properly validate JavaScript constructors
 
(from 120671-02)
 
6461074 [s10u3] mozilla cores on browsing to http://www.yahoo.com
6412730 Mozilla: Localstore.rdf XML injection through XULDocument.persist()
6415128 [MFSA 2006-22] Mozilla CSS Letter-Spacing vulnerability
6415131 [MFSA 2006-16] Mozilla XBL binding vulnerability
6415133 [MFSA 2006-15] Mozilla JavaScript cloned parent vulnerability
6415135 [MFSA 2006-14] Mozilla privilege escalation vulnerability via XBL.method.eval
6415138 [MFSA 2006-18] Mozilla tag order memory corruption vulnerability
6415142 [MFSA 2006-11] Mozilla CSS, regex,... memory corruption vulnerabilities
6415143 [MFSA 2006-20] Mozilla DHTML memory corruption vulnerabilities
6424493 [MFSA 2006-27] Table rebuilding code execution vulnerability
6424545 [MFSA 2006-25] Privilege escalation through Print Preview
6424548 [MFSA 2006-23] File stealing by changing input type
6424551 [MFSA 2006-21] JavaScript execution in mail when forwarding in-line
6424560 [MFSA 2006-19] Cross-site scripting using .valueOf.call()
6424563 [MFSA 2006-17] cross-site scripting through window.controllers
6424567 [MFSA 2006-13] Downloading executables with "Save Image As..."
6424568 [MFSA 2006-12] Secure-site spoof (requires security warning dialog)
6424573 [MFSA 2006-10] JavaScript garbage-collection hazard audit
6424574 [MFSA 2006-09] Cross-site JavaScript injection using event handlers
6424577 [MFSA 2006-03] Long document title causes startup denial of service
6424579 [MFSA 2006-01] JavaScript garbage-collection hazards
 
(from 120671-01)
 
6352958 Mozilla 1.7 patch 119115-13 breaks "Automatic proxy configuration file"
Revision History: 

120671-01 120671-03 120671-02

Patch Installation Instructions: 
-------------------------------- 
For Solaris 7-10 releases, refer to the man pages for instructions on
using 'patchadd' and 'patchrm' scripts provided with Solaris.
Any other special or non-generic installation instructions should be
described below as special instructions.  The following example
installs a patch to a standalone machine:
 
	example# patchadd /var/spool/patch/104945-02
 
The following example removes a patch from a standalone system:
 
	example# patchrm 104945-02
 
For additional examples please see the appropriate man pages.
Special Install Instructions: 
----------------------------- 
Logout and login back to JDS after applying the patch.

README -- Last modified date:  Tuesday, April 10, 2007

 
 
Login Required

You must login and have a valid contract to access Sun's Premium content which includes:

  • Sun Alerts
  • Bugs
  • Patches
  • Solutions
  • White Papers
  • Documentation
  • Support Knowledge

Login Required

You must login and have a valid contract to access Sun's contracted features

Access Legend:

(Login to access)   Sun Contracted Content
(Login to access)   Sun Contracted Feature

Please make use of SunSolve Feedback application by selecting the floating [+] to provide feedback about this specific document.

Search

Article Details
Article ID : 120671-04
Article Type : Patch Descriptions
Last reviewed : 2007-04-06
Audience : PUBLIC
Keywords : security mozilla web download automatic proxy
Provide feedback  (help)
Page Tools
»  Print This Page
»  Email This Article
»  Bookmark This Article