LWN.net Logo

firefox: multiple vulnerabilities

Package(s):firefox CVE #(s):CVE-2011-0065 CVE-2011-0066 CVE-2011-0067 CVE-2011-0069 CVE-2011-1202
Created:April 29, 2011 Updated:October 4, 2012
Description: From the Red Hat advisory:

Two use-after-free flaws were found in the Firefox mObserverList and mChannel objects. Malicious content could use these flaws to execute arbitrary code with the privileges of the user running Firefox. (CVE-2011-0066, CVE-2011-0065)

A flaw was found in the way Firefox displayed the autocomplete pop-up. Malicious content could use this flaw to steal form history information. (CVE-2011-0067)

A flaw was found in the way Firefox handled certain JavaScript cross-domain requests. If malicious content generated a large number of cross-domain JavaScript requests, it could cause Firefox to execute arbitrary code with the privileges of the user running Firefox. (CVE-2011-0069)

A flaw was found in the Firefox XSLT generate-id() function. This function returned the memory address of an object in memory, which could possibly be used by attackers to bypass address randomization protections. (CVE-2011-1202)

Alerts:
Ubuntu USN-1122-3 2011-06-06
Fedora FEDORA-2011-6205 2011-04-29
Fedora FEDORA-2011-6215 2011-04-29
Fedora FEDORA-2011-6215 2011-04-29
Fedora FEDORA-2011-6215 2011-04-29
Ubuntu USN-1123-1 2011-04-30
Red Hat RHSA-2011:0471-01 2011-04-28
Fedora FEDORA-2011-6205 2011-04-29
openSUSE openSUSE-SU-2011:0437-1 2011-05-06
Slackware SSA:2011-122-02 2011-05-03
Fedora FEDORA-2011-6215 2011-04-29
Fedora FEDORA-2011-6215 2011-04-29
Fedora FEDORA-2011-6215 2011-04-29
Fedora FEDORA-2011-6215 2011-04-29
Debian DSA-2227-1 2011-04-30
Fedora FEDORA-2011-6205 2011-04-29
Fedora FEDORA-2011-6205 2011-04-29
Fedora FEDORA-2011-6205 2011-04-29
Fedora FEDORA-2011-6205 2011-04-29
Fedora FEDORA-2011-6215 2011-04-29
Debian DSA-2228-1 2011-05-01
Ubuntu USN-1121-1 2011-04-30
CentOS CESA-2011:0471 2011-04-29
Fedora FEDORA-2011-6245 2011-04-29
Fedora FEDORA-2011-6258 2011-04-29
Fedora FEDORA-2011-6205 2011-04-29
Fedora FEDORA-2011-6205 2011-04-29
Ubuntu USN-1122-2 2011-05-05
Ubuntu USN-1122-1 2011-05-05
SUSE SUSE-SA:2011:022 2011-05-05
Slackware SSA:2011-122-01 2011-05-03
Ubuntu USN-1112-1 2011-04-29
CentOS CESA-2011:0471 2011-04-29
Debian DSA-2235-1 2011-05-10
Slackware SSA:2011-122-03 2011-05-03
Mandriva MDVSA-2011:080 2011-05-01
Mandriva MDVSA-2011:079 2011-04-30
Red Hat RHSA-2012:1265-01 2012-09-13
CentOS CESA-2012:1265 2012-09-13
CentOS CESA-2012:1265 2012-09-13
Oracle ELSA-2012-1265 2012-09-14
Oracle ELSA-2012-1265 2012-09-14
Scientific Linux SL-libx-20120914 2012-09-14
Mageia MGASA-2012-0271 2012-09-15
Fedora FEDORA-2012-14083 2012-09-26
Fedora FEDORA-2012-14048 2012-09-27
Ubuntu USN-1595-1 2012-10-04
Mandriva MDVSA-2012:164 2012-10-11
Gentoo 201301-01 2013-01-07

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds