Juan Pablo Lopez Yacubian discovered that incorrect handling of invalid URLs could be used for spoofing the location bar and the SSL certificate status of a web page.
Xulrunner is no longer supported for the old stable distribution (etch).
For the stable distribution (lenny), this problem has been fixed in version 1.9.0.13-0lenny1.
For the unstable distribution (sid), this problem has been fixed in version 1.9.0.13-1.
We recommend that you upgrade your xulrunner packages.
MD5 checksums of the listed files are available in the original advisory.