LWN.net Logo

firefox, xulrunner: multiple vulnerabilities

Package(s):firefox-3.0, firefox-3.5, xulrunner-1.9, xulrunner-1.9.1 CVE #(s):CVE-2009-3371 CVE-2009-3377 CVE-2009-3381 CVE-2009-3383
Created:November 2, 2009 Updated:June 11, 2010
Description:

From the Ubuntu advisory:

Orlando Berrera discovered that Firefox did not properly free memory when using web-workers. If a user were tricked into viewing a malicious website, a remote attacker could cause a denial of service or possibly execute arbitrary code with the privileges of the user invoking the program. This issue only affected Ubuntu 9.10. (CVE-2009-3371)

Several flaws were discovered in third party media libraries. If a user were tricked into opening a crafted media file, a remote attacker could cause a denial of service or possibly execute arbitrary code with the privileges of the user invoking the program. This issue only affected Ubuntu 9.10. (CVE-2009-3377)

Vladimir Vukicevic, Jesse Ruderman, Martijn Wargers, Daniel Banchero, David Keeler, Boris Zbarsky, Thomas Frederiksen, Marcia Knous, Carsten Book, Kevin Brosnan, David Anderson and Jeff Walden discovered various flaws in the browser and JavaScript engines of Firefox. If a user were tricked into viewing a malicious website, a remote attacker could cause a denial of service or possibly execute arbitrary code with the privileges of the user invoking the program. (CVE-2009-3380, CVE-2009-3381, CVE-2009-3382, CVE-2009-3383)

Alerts:
Fedora FEDORA-2010-9774 2010-06-10
Fedora FEDORA-2010-9774 2010-06-10
Fedora FEDORA-2010-9253 2010-05-31
Fedora FEDORA-2010-9774 2010-06-10
Fedora FEDORA-2010-9774 2010-06-10
Fedora FEDORA-2010-9774 2010-06-10
Slackware SSA:2009-306-01 2009-11-03
SuSE SUSE-SA:2009:052 2009-11-04
Ubuntu USN-853-2 2009-11-11
Mandriva MDVSA-2009:294 2009-11-05
Ubuntu USN-853-1 2009-10-31

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds