-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2009.1222
            New xulrunner packages fix spoofing vulnerabilities
                              27 August 2009

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           xulrunner
Publisher:         Debian
Operating System:  Debian GNU/Linux 5
                   UNIX variants (UNIX, Linux, OSX)
                   Windows
Impact/Access:     Provide Misleading Information -- Remote/Unauthenticated
Resolution:        Patch/Upgrade
CVE Names:         CVE-2009-2654  

Reference:         ASB-2009.1040

Original Bulletin: 
   http://www.debian.org/security/2009/dsa-1873

Comment: This advisory references vulnerabilities in products which run on 
         platforms other than Debian. It is recommended that administrators 
         running xulrunner check for an updated version of the software for 
         their operating system.

- --------------------------BEGIN INCLUDED TEXT--------------------

- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- - ------------------------------------------------------------------------
Debian Security Advisory DSA-1873-1                  security@debian.org
http://www.debian.org/security/                       Moritz Muehlenhoff
August 26, 2009                       http://www.debian.org/security/faq
- - ------------------------------------------------------------------------

Package        : xulrunner
Vulnerability  : programming error
Problem type   : remote
Debian-specific: no
CVE Id(s)      : CVE-2009-2654

Juan Pablo Lopez Yacubian discovered that incorrect handling of invalid
URLs could be used for spoofing the location bar and the SSL certificate
status of a web page.

Xulrunner is no longer supported for the old stable distribution (etch).

For the stable distribution (lenny), this problem has been fixed in
version 1.9.0.13-0lenny1.

For the unstable distribution (sid), this problem has been fixed in
version 1.9.0.13-1.

We recommend that you upgrade your xulrunner packages.

Upgrade instructions
- - --------------------

wget url
        will fetch the file for you
dpkg -i file.deb
        will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
        will update the internal database
apt-get upgrade
        will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.


Debian GNU/Linux 5.0 alias lenny
- - --------------------------------

Stable updates are available for alpha, amd64, arm, armel, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc.

Source archives:

  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.9.0.13-0lenny1.dsc
    Size/MD5 checksum:     1784 3cb69f62da64dd1811ba2390cda7ad70
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.9.0.13.orig.tar.gz
    Size/MD5 checksum: 44087336 54f6301790198d83d9781a8d107d903f
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.9.0.13-0lenny1.diff.gz
    Size/MD5 checksum:   116763 193df5562df81a7d2cc54624fd2a0f51

Architecture independent packages:

  http://security.debian.org/pool/updates/main/x/xulrunner/libmozillainterfaces-java_1.9.0.13-0lenny1_all.deb
    Size/MD5 checksum:  1463692 3b7d737dad1999992c031048c503b67f

alpha architecture (DEC Alpha)

  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-dev_1.9.0.13-0lenny1_alpha.deb
    Size/MD5 checksum:  3650174 f2d621d2e631411a1893b76416f35698
  http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.9.0.13-0lenny1_alpha.deb
    Size/MD5 checksum:   163726 4cb583d327edcd3edc684fa0426caab1
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9-dbg_1.9.0.13-0lenny1_alpha.deb
    Size/MD5 checksum: 51076842 1350fb7090a2690e36b8709f653b561b
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9-gnome-support_1.9.0.13-0lenny1_alpha.deb
    Size/MD5 checksum:   111814 4bb1d9a1370d0622e866ff6210f18066
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9_1.9.0.13-0lenny1_alpha.deb
    Size/MD5 checksum:  9490426 215edc3094a23db0c6adabd50884a3a0
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs1d-dbg_1.9.0.13-0lenny1_alpha.deb
    Size/MD5 checksum:   936830 ff33f0f1af57ae59db2aaa6598985adf
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs-dev_1.9.0.13-0lenny1_alpha.deb
    Size/MD5 checksum:   221362 1d2d8cbb54b693fde85dd515b55d9922
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs1d_1.9.0.13-0lenny1_alpha.deb
    Size/MD5 checksum:   431216 d2ddb135a2c4a8cc03c1be10f6ca82f8
  http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.9.0.13-0lenny1_alpha.deb
    Size/MD5 checksum:    71488 368acbceaa33290726ee9f91b1f389f8

amd64 architecture (AMD x86_64 (AMD64))

  http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.9.0.13-0lenny1_amd64.deb
    Size/MD5 checksum:   151740 9106bb0c5d9e8625604f613f5194ae1a
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs1d_1.9.0.13-0lenny1_amd64.deb
    Size/MD5 checksum:   373904 0bc676e23d286be9271b3fd364a9c836
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9-gnome-support_1.9.0.13-0lenny1_amd64.deb
    Size/MD5 checksum:   101310 221078690fc300a9fcf87a26bd4800bb
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-dev_1.9.0.13-0lenny1_amd64.deb
    Size/MD5 checksum:  3286694 f72eb5cd02d92766474a20579aa74a8b
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9_1.9.0.13-0lenny1_amd64.deb
    Size/MD5 checksum:  7717078 a49f4154a3e5e4a6522ca7ea58d0cf79
  http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.9.0.13-0lenny1_amd64.deb
    Size/MD5 checksum:    69392 3730969373079331b269890cb104629e
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs-dev_1.9.0.13-0lenny1_amd64.deb
    Size/MD5 checksum:   222702 c98d1bbf8f80c512a7eea7f94eaf8952
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs1d-dbg_1.9.0.13-0lenny1_amd64.deb
    Size/MD5 checksum:   889904 a7c23d16ff8d30bc16767f6af21c23e3
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9-dbg_1.9.0.13-0lenny1_amd64.deb
    Size/MD5 checksum: 50310800 c8555989c076088e089e838de0c358f0

arm architecture (ARM)

  http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.9.0.13-0lenny1_arm.deb
    Size/MD5 checksum:    67760 647d54e6c11674dac17de983be62ba50
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs-dev_1.9.0.13-0lenny1_arm.deb
    Size/MD5 checksum:   221772 ab8d0eea1b0bf9b6c200803b4192f629
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9-gnome-support_1.9.0.13-0lenny1_arm.deb
    Size/MD5 checksum:    83654 fc7e855940039a4fff5eb80c625beebe
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs1d_1.9.0.13-0lenny1_arm.deb
    Size/MD5 checksum:   350400 534ba7ef0348ff992af810ffeb1f76d8
  http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.9.0.13-0lenny1_arm.deb
    Size/MD5 checksum:   140512 690f123b67cbe0e7e274d747797e352e
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9_1.9.0.13-0lenny1_arm.deb
    Size/MD5 checksum:  6787090 aba34ff0035b27bb484ff0836704fc7f
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs1d-dbg_1.9.0.13-0lenny1_arm.deb
    Size/MD5 checksum:   815226 1a9276433c4f7e874361fbe5da86f729
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9-dbg_1.9.0.13-0lenny1_arm.deb
    Size/MD5 checksum: 49271924 62555f78d84da2a81b92464eab212c84
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-dev_1.9.0.13-0lenny1_arm.deb
    Size/MD5 checksum:  3579964 0de1b683c71a22bed53ac594622c0468

armel architecture (ARM EABI)

  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs-dev_1.9.0.13-0lenny1_armel.deb
    Size/MD5 checksum:   223226 ae31e5e725a09f487b0476485fb705f9
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs1d-dbg_1.9.0.13-0lenny1_armel.deb
    Size/MD5 checksum:   823178 93fa22f50efadbca49e10a4486f7a6c9
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-dev_1.9.0.13-0lenny1_armel.deb
    Size/MD5 checksum:  3569696 47bfedd77b1ccbece88d409689446e18
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9-gnome-support_1.9.0.13-0lenny1_armel.deb
    Size/MD5 checksum:    84234 cffb345d34eb558d3f5f146271f9b6ce
  http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.9.0.13-0lenny1_armel.deb
    Size/MD5 checksum:    69972 3ab93baf817484f69bab714f051aaa99
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs1d_1.9.0.13-0lenny1_armel.deb
    Size/MD5 checksum:   352934 14daf47f48e323cec7e1a808ec0a8f28
  http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.9.0.13-0lenny1_armel.deb
    Size/MD5 checksum:   142542 b3d32666b9f5b5380e70bf10103645a0
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9-dbg_1.9.0.13-0lenny1_armel.deb
    Size/MD5 checksum: 50103556 f3931dc067555d273bb2f7af74c97b6b
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9_1.9.0.13-0lenny1_armel.deb
    Size/MD5 checksum:  6948592 46428e5f62b429da082113b8da76564e

hppa architecture (HP PA RISC)

  http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.9.0.13-0lenny1_hppa.deb
    Size/MD5 checksum:   158262 bf0a5603b559f81e51b3e8fe835d5eff
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9-dbg_1.9.0.13-0lenny1_hppa.deb
    Size/MD5 checksum: 51211330 caec065a57aa72660a0a73c237e652f3
  http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.9.0.13-0lenny1_hppa.deb
    Size/MD5 checksum:    71492 da5e96bc768535373f3df6797b79e888
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs1d_1.9.0.13-0lenny1_hppa.deb
    Size/MD5 checksum:   412516 3cba0886d4220c295ff51d6fce4a874f
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs-dev_1.9.0.13-0lenny1_hppa.deb
    Size/MD5 checksum:   223092 4872c51582be0e1972239ec1ef56d7ad
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-dev_1.9.0.13-0lenny1_hppa.deb
    Size/MD5 checksum:  3629140 aac13891915a46ed202713dcaa1ffdd2
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs1d-dbg_1.9.0.13-0lenny1_hppa.deb
    Size/MD5 checksum:   899436 1f8368b4f8d577904f586f84c3f5250a
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9_1.9.0.13-0lenny1_hppa.deb
    Size/MD5 checksum:  9503478 e1e18573037291f60981240e81a5a80e
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9-gnome-support_1.9.0.13-0lenny1_hppa.deb
    Size/MD5 checksum:   106514 eb881ae75b3fe865b5e8f78db5141565

i386 architecture (Intel ia32)

  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9-gnome-support_1.9.0.13-0lenny1_i386.deb
    Size/MD5 checksum:    78942 d69b8b65d1c250d24d21e7961242ce4d
  http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.9.0.13-0lenny1_i386.deb
    Size/MD5 checksum:    67614 3ef0065dbf512988f310b379ecbb0c7b
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs-dev_1.9.0.13-0lenny1_i386.deb
    Size/MD5 checksum:   222934 5671e70f2de1832fd1b2f96decdb2de7
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs1d_1.9.0.13-0lenny1_i386.deb
    Size/MD5 checksum:   350452 fcfb729d77cdfcaa34d1dbce66c2b90c
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs1d-dbg_1.9.0.13-0lenny1_i386.deb
    Size/MD5 checksum:   851486 7cbad5a2fb4453b08fb8a4a4543f238b
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-dev_1.9.0.13-0lenny1_i386.deb
    Size/MD5 checksum:  3564388 bc2223a0931115a4d3ecc6bb0062ed03
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9-dbg_1.9.0.13-0lenny1_i386.deb
    Size/MD5 checksum: 49481952 b12493504db71e8379ea0eac86d9869b
  http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.9.0.13-0lenny1_i386.deb
    Size/MD5 checksum:   141078 fd880d99a562d8e07b83dd885f8c4a56
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9_1.9.0.13-0lenny1_i386.deb
    Size/MD5 checksum:  6594618 e8043afeed3bcd924d6fab356965b69c

ia64 architecture (Intel ia64)

  http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.9.0.13-0lenny1_ia64.deb
    Size/MD5 checksum:   179980 719fac1e4f7c966ae583fb0dc370f14f
  http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.9.0.13-0lenny1_ia64.deb
    Size/MD5 checksum:    75864 0f1777d61ada527ef5b8116b2b3097d1
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs1d-dbg_1.9.0.13-0lenny1_ia64.deb
    Size/MD5 checksum:   811252 bf630847aff060fcd1a9867139c33dd9
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9-gnome-support_1.9.0.13-0lenny1_ia64.deb
    Size/MD5 checksum:   121340 a22aa06f1fad6e084b896e8bf3ef69c8
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-dev_1.9.0.13-0lenny1_ia64.deb
    Size/MD5 checksum:  3396354 d694cff83fe82d7125af3bca844e2434
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9_1.9.0.13-0lenny1_ia64.deb
    Size/MD5 checksum: 11292004 8874413465733b654819940cebc9ce0a
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9-dbg_1.9.0.13-0lenny1_ia64.deb
    Size/MD5 checksum: 49653978 993621bd3d1b2cdc05663f8941ae90b8
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs-dev_1.9.0.13-0lenny1_ia64.deb
    Size/MD5 checksum:   222916 aeeb890a09b31ed3c9d4b56db64a9b80
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs1d_1.9.0.13-0lenny1_ia64.deb
    Size/MD5 checksum:   542196 7dcca5c07da0ee93bf746b49d58c703c

mips architecture (MIPS (Big Endian))

  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9-gnome-support_1.9.0.13-0lenny1_mips.deb
    Size/MD5 checksum:    96912 8aeb2510afea5d1f92ff7810cf4ae8f1
  http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.9.0.13-0lenny1_mips.deb
    Size/MD5 checksum:   144496 3fe45b281a226a094732bb2bae46fd3c
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs1d_1.9.0.13-0lenny1_mips.deb
    Size/MD5 checksum:   379912 e1d1da46d473c72f1a462aecbeba45a5
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9-dbg_1.9.0.13-0lenny1_mips.deb
    Size/MD5 checksum: 51839016 804b5b45b4899b1f96fb02ff558b1017
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs1d-dbg_1.9.0.13-0lenny1_mips.deb
    Size/MD5 checksum:   918304 1c49ffadf9f71ad385932389ef10624f
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9_1.9.0.13-0lenny1_mips.deb
    Size/MD5 checksum:  7661930 dde7ba616bfeef980f71f0a07c158026
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs-dev_1.9.0.13-0lenny1_mips.deb
    Size/MD5 checksum:   222762 181364c559aaf7a91899d16dabe4fcb3
  http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.9.0.13-0lenny1_mips.deb
    Size/MD5 checksum:    69692 0f5c37b1b56abbf4583fa347afb3f5cc
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-dev_1.9.0.13-0lenny1_mips.deb
    Size/MD5 checksum:  3612680 13b571b9dc508ff6f49471e180ccbf8f

mipsel architecture (MIPS (Little Endian))

  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs1d_1.9.0.13-0lenny1_mipsel.deb
    Size/MD5 checksum:   378170 4f6003e95c9a9326c3d331a83fbc0c07
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9-dbg_1.9.0.13-0lenny1_mipsel.deb
    Size/MD5 checksum: 49952368 ea9e3bb040ec093988b53745a55dd170
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9-gnome-support_1.9.0.13-0lenny1_mipsel.deb
    Size/MD5 checksum:    96570 cbcaf650c878d4e1e5759614e65e4372
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9_1.9.0.13-0lenny1_mipsel.deb
    Size/MD5 checksum:  7371816 4e0cd58aec00a343d0964254b4d4be6d
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs-dev_1.9.0.13-0lenny1_mipsel.deb
    Size/MD5 checksum:   222906 6c08a02a49459bfb64876f40fe910d5b
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-dev_1.9.0.13-0lenny1_mipsel.deb
    Size/MD5 checksum:  3307316 2982b19df977a71f65f5aa180294bc3c
  http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.9.0.13-0lenny1_mipsel.deb
    Size/MD5 checksum:    69374 654f66b755959297882b8719e673cb36
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs1d-dbg_1.9.0.13-0lenny1_mipsel.deb
    Size/MD5 checksum:   900092 438dc2616c421125d23af5ff72794226
  http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.9.0.13-0lenny1_mipsel.deb
    Size/MD5 checksum:   144774 0ba7ddcd1cadb1ec34e2295cf3222cd1

powerpc architecture (PowerPC)

  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9-gnome-support_1.9.0.13-0lenny1_powerpc.deb
    Size/MD5 checksum:    94598 0555d823fb826f33f955e2bc155f39af
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs-dev_1.9.0.13-0lenny1_powerpc.deb
    Size/MD5 checksum:   222912 5c58ab00c1c27713fe3ae42142647a85
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs1d-dbg_1.9.0.13-0lenny1_powerpc.deb
    Size/MD5 checksum:   888022 194f79d5ce4448c04908cbaa103b0483
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9_1.9.0.13-0lenny1_powerpc.deb
    Size/MD5 checksum:  7270354 8a754bf9937966182d61179c73200e07
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs1d_1.9.0.13-0lenny1_powerpc.deb
    Size/MD5 checksum:   362116 eaaa7e43204f7565d618907240a0a533
  http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.9.0.13-0lenny1_powerpc.deb
    Size/MD5 checksum:   152068 ad2ff0c3674e5d1f321d62b1327c3223
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9-dbg_1.9.0.13-0lenny1_powerpc.deb
    Size/MD5 checksum: 51365442 9d24613bc7c49884c20a07d14f3f07b2
  http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.9.0.13-0lenny1_powerpc.deb
    Size/MD5 checksum:    72542 8c09d7d4ef509da594af64f85ccce9ca
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-dev_1.9.0.13-0lenny1_powerpc.deb
    Size/MD5 checksum:  3282570 7ba98adc2a29b38f779ceb93c4a9f420

s390 architecture (IBM S/390)

  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9-gnome-support_1.9.0.13-0lenny1_s390.deb
    Size/MD5 checksum:   105364 3f1e74e0623c971c41234822c44808a5
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9-dbg_1.9.0.13-0lenny1_s390.deb
    Size/MD5 checksum: 51156554 62fb601d05680608773383f5755fc271
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9_1.9.0.13-0lenny1_s390.deb
    Size/MD5 checksum:  8381832 24aa30f03b5f8ea822f9679614021d68
  http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.9.0.13-0lenny1_s390.deb
    Size/MD5 checksum:   155884 daa6d5ca41f2a17ea2c62a88491383cf
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs1d-dbg_1.9.0.13-0lenny1_s390.deb
    Size/MD5 checksum:   909310 a382ee499cea150ef460a74baf528764
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-dev_1.9.0.13-0lenny1_s390.deb
    Size/MD5 checksum:  3305188 0828ab7702dc77530a331a45da049d22
  http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.9.0.13-0lenny1_s390.deb
    Size/MD5 checksum:    72364 1d508c1eb2518d24993a011a026c9952
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs1d_1.9.0.13-0lenny1_s390.deb
    Size/MD5 checksum:   406306 b7cee75289784de2c682c4f5abd0b5cb
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs-dev_1.9.0.13-0lenny1_s390.deb
    Size/MD5 checksum:   222908 76f9c545195fb95ad53419b037b35583

sparc architecture (Sun SPARC/UltraSPARC)

  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-dev_1.9.0.13-0lenny1_sparc.deb
    Size/MD5 checksum:  3575950 9760510e902b131e94d6057733c69566
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9-dbg_1.9.0.13-0lenny1_sparc.deb
    Size/MD5 checksum: 49350930 9cc7507d39a67b4fd06267dbf2bd93e3
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs1d_1.9.0.13-0lenny1_sparc.deb
    Size/MD5 checksum:   349936 398ae95c0067f213383696b86b341b36
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs-dev_1.9.0.13-0lenny1_sparc.deb
    Size/MD5 checksum:   222994 f28fbfc9107b7a13e0695a4888fe8f75
  http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.9.0.13-0lenny1_sparc.deb
    Size/MD5 checksum:   143022 945475c4924eef6eee00f8738aaea153
  http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.9.0.13-0lenny1_sparc.deb
    Size/MD5 checksum:    68862 ebe2658e7020e3d866644d1151d4dd07
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9_1.9.0.13-0lenny1_sparc.deb
    Size/MD5 checksum:  7169696 3356fafabab8464291700a09f78c59c1
  http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-1.9-gnome-support_1.9.0.13-0lenny1_sparc.deb
    Size/MD5 checksum:    88016 6d500d79d352c9d9b1e1fb451cba45a3
  http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs1d-dbg_1.9.0.13-0lenny1_sparc.deb
    Size/MD5 checksum:   821482 625b551efab2c8854443878748ce17c0

  These files will probably be moved into the stable distribution on
  its next update.

- - ---------------------------------------------------------------------------------
For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
Mailing list: debian-security-announce@lists.debian.org
Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>
- -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iEYEARECAAYFAkqVg+YACgkQXm3vHE4uylra+gCbBazHHfxnqAeYLdlOS5Y2708z
GvwAoMeQF/X5nHp5alQ5n533IKheiWSj
=0J39
- -----END PGP SIGNATURE-----

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        http://www.auscert.org.au/render.html?cid=1980

If you believe that your computer system has been compromised or attacked in 
any way, we encourage you to let us know by completing the secure National IT 
Incident Reporting Form at:

        http://www.auscert.org.au/render.html?it=3192

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iD8DBQFKldGLNVH5XJJInbgRAqS4AJ9F8lTxwAbK7mzI+mF8iXcxC1ivZgCfdWTl
QQ5vleUDgeLtYc7P8XGD5Qk=
=FPWm
-----END PGP SIGNATURE-----