LWN.net Logo

mozilla: multiple vulnerabilities

Package(s):mozilla, firefox, thunderbird, seamonkey CVE #(s):CVE-2011-3658 CVE-2011-3660 CVE-2011-3661 CVE-2011-3663 CVE-2011-3665
Created:December 26, 2011 Updated:March 23, 2012
Description: From the Mandriva advisory:

The SVG implementation in Mozilla Firefox 8.0, Thunderbird 8.0, and SeaMonkey 2.5 does not properly interact with DOMAttrModified event handlers, which allows remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact via vectors involving removal of SVG elements (CVE-2011-3658).

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors that trigger a compartment mismatch associated with the nsDOMMessageEvent::GetData function, and unknown other vectors (CVE-2011-3660).

YARR, as used in Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted JavaScript (CVE-2011-3661).

Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6 allow remote attackers to capture keystrokes entered on a web page by using SVG animation accessKey events within that web page (CVE-2011-3663).

Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via an Ogg VIDEO element that is not properly handled after scaling (CVE-2011-3665).

Alerts:
Mandriva MDVSA-2011:192 2011-12-23
openSUSE openSUSE-SU-2012:0007-1 2012-01-05
Ubuntu USN-1306-1 2012-01-06
Ubuntu USN-1306-2 2012-01-06
Ubuntu USN-1343-1 2012-01-24
openSUSE openSUSE-SU-2012:0039-2 2012-02-09
Mandriva MDVSA-2012:031 2012-03-17
Ubuntu USN-1401-1 2012-03-19
Ubuntu USN-1401-2 2012-03-23
openSUSE openSUSE-SU-2012:0417-1 2012-03-27
openSUSE openSUSE-SU-2012:0567-1 2012-04-27
Gentoo 201301-01 2013-01-07

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds