LWN.net Logo

mozilla: code execution

Package(s):mozilla-thunderbird, firefox CVE #(s):CVE-2012-0452
Created:February 13, 2012 Updated:February 16, 2012
Description: From the Mandriva advisory:

Use-after-free vulnerability in Mozilla Firefox 10.x before 10.0.1, Thunderbird 10.x before 10.0.1, and SeaMonkey 2.7 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger failure of an nsXBLDocumentInfo::ReadPrototypeBindings function call, related to the cycle collector's access to a hash table containing a stale XBL binding

Alerts:
Mandriva MDVSA-2012:018 2012-02-13
Mandriva MDVSA-2012:017 2012-02-12
Ubuntu USN-1360-1 2012-02-13
openSUSE openSUSE-SU-2012:0258-1 2012-02-14
SUSE SUSE-SU-2012:0261-1 2012-02-16
Ubuntu USN-1369-1 2012-02-17
openSUSE openSUSE-SU-2012:0567-1 2012-04-27
Gentoo 201301-01 2013-01-07

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds