LWN.net Logo

Mozilla products: multiple vulnerabilities

Package(s):firefox, thunderbird, seamonkey CVE #(s):CVE-2011-0084 CVE-2011-2378 CVE-2011-2981 CVE-2011-2982 CVE-2011-2983 CVE-2011-2984
Created:August 17, 2011 Updated:September 23, 2011
Description: From the Red Hat advisory:

Several flaws were found in the processing of malformed web content. A web page containing malicious content could cause Firefox to crash or, potentially, execute arbitrary code with the privileges of the user running Firefox. (CVE-2011-2982)

A dangling pointer flaw was found in the Firefox Scalable Vector Graphics (SVG) text manipulation routine. A web page containing a malicious SVG image could cause Firefox to crash or, potentially, execute arbitrary code with the privileges of the user running Firefox. (CVE-2011-0084)

A dangling pointer flaw was found in the way Firefox handled a certain Document Object Model (DOM) element. A web page containing malicious content could cause Firefox to crash or, potentially, execute arbitrary code with the privileges of the user running Firefox. (CVE-2011-2378)

A flaw was found in the event management code in Firefox. A website containing malicious JavaScript could cause Firefox to execute that JavaScript with the privileges of the user running Firefox. (CVE-2011-2981)

A flaw was found in the way Firefox handled malformed JavaScript. A web page containing malicious JavaScript could cause Firefox to access already freed memory, causing Firefox to crash or, potentially, execute arbitrary code with the privileges of the user running Firefox. (CVE-2011-2983)

It was found that a malicious web page could execute arbitrary code with the privileges of the user running Firefox if the user dropped a tab onto the malicious web page. (CVE-2011-2984)

Alerts:
CentOS CESA-2011:1164 2011-09-22
CentOS CESA-2011:1164 2011-09-22
CentOS CESA-2011:1165 2011-09-22
openSUSE openSUSE-SU-2011:0957-2 2011-08-30
openSUSE openSUSE-SU-2011:0935-2 2011-08-30
SUSE SUSE-SU-2011:0967-1 2011-08-30
SUSE SUSE-SA:2011:037 2011-08-29
openSUSE openSUSE-SU-2011:0958-1 2011-08-29
openSUSE openSUSE-SU-2011:0957-1 2011-08-29
Ubuntu USN-1185-1 2011-08-26
openSUSE openSUSE-SU-2011:0935-1 2011-08-23
Fedora FEDORA-2011-11084 2011-08-18
Fedora FEDORA-2011-11084 2011-08-18
Fedora FEDORA-2011-11084 2011-08-18
Fedora FEDORA-2011-11084 2011-08-18
Fedora FEDORA-2011-11084 2011-08-18
Fedora FEDORA-2011-11084 2011-08-18
Fedora FEDORA-2011-11084 2011-08-18
Fedora FEDORA-2011-11084 2011-08-18
Fedora FEDORA-2011-11087 2011-08-18
Fedora FEDORA-2011-11084 2011-08-18
Fedora FEDORA-2011-11087 2011-08-18
Debian DSA-2297-1 2011-08-21
Ubuntu USN-1184-1 2011-08-19
Ubuntu USN-1192-2 2011-08-17
Debian DSA-2296-1 2011-08-17
Ubuntu USN-1192-1 2011-08-17
Debian DSA-2295-1 2011-08-17
Mandriva MDVSA-2011:127 2011-08-17
Scientific Linux SL-fire-20110816 2011-08-16
Scientific Linux SL-thun-20110816 2011-08-16
Scientific Linux SL-thun-20110816 2011-08-16
Scientific Linux SL-seam-20110816 2011-08-16
CentOS CESA-2011:1164 2011-08-17
CentOS CESA-2011:1165 2011-08-17
CentOS CESA-2011:1167 2011-08-17
Red Hat RHSA-2011:1166-01 2011-08-16
Red Hat RHSA-2011:1165-01 2011-08-16
Red Hat RHSA-2011:1167-01 2011-08-16
Red Hat RHSA-2011:1164-01 2011-08-16
Mageia MGASA-2012-0176 2012-07-21
Gentoo 201301-01 2013-01-07

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds