Lucene search

K
ubuntuUbuntuUSN-896-1
HistoryFeb 17, 2010 - 12:00 a.m.

Firefox 3.5 and Xulrunner 1.9.1 vulnerabilities

2010-02-1700:00:00
ubuntu.com
49

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

10

Confidence

High

EPSS

0.367

Percentile

97.2%

Releases

  • Ubuntu 9.10

Packages

  • firefox-3.5 -
  • xulrunner-1.9.1 -

Details

Several flaws were discovered in the browser engine of Firefox. If a user
were tricked into viewing a malicious website, a remote attacker could
cause a denial of service or possibly execute arbitrary code with the
privileges of the user invoking the program. (CVE-2010-0159)

Orlando Barrera II discovered a flaw in the Web Workers implementation of
Firefox. If a user were tricked into posting to a malicious website, an
attacker could cause a denial of service or possibly execute arbitrary code
with the privileges of the user invoking the program. (CVE-2010-0160)

Alin Rad Pop discovered that Firefox’s HTML parser would incorrectly free
memory under certain circumstances. If the browser could be made to access
these freed memory objects, an attacker could exploit this to execute
arbitrary code with the privileges of the user invoking the program.
(CVE-2009-1571)

Hidetake Jo discovered that the showModalDialog in Firefox did not always
honor the same-origin policy. An attacker could exploit this to run
untrusted JavaScript from other domains. (CVE-2009-3988)

Georgi Guninski discovered that the same-origin check in Firefox could be
bypassed by utilizing a crafted SVG image. If a user were tricked into
viewing a malicious website, an attacker could exploit this to read data
from other domains. (CVE-2010-0162)

OSVersionArchitecturePackageVersionFilename
Ubuntu9.10noarchxulrunner-1.9.1< 1.9.1.8+build1+nobinonly-0ubuntu0.9.10.1UNKNOWN
Ubuntu9.10noarchxulrunner-1.9.1-dbg< 1.9.1.8+build1+nobinonly-0ubuntu0.9.10.1UNKNOWN
Ubuntu9.10noarchxulrunner-1.9.1-dev< 1.9.1.8+build1+nobinonly-0ubuntu0.9.10.1UNKNOWN
Ubuntu9.10noarchxulrunner-1.9.1-gnome-support< 1.9.1.8+build1+nobinonly-0ubuntu0.9.10.1UNKNOWN
Ubuntu9.10noarchxulrunner-1.9.1-testsuite< 1.9.1.8+build1+nobinonly-0ubuntu0.9.10.1UNKNOWN
Ubuntu9.10noarchxulrunner-1.9.1-testsuite-dev< 1.9.1.8+build1+nobinonly-0ubuntu0.9.10.1UNKNOWN
Ubuntu9.10noarchxulrunner-dev< 1.9.1.8+build1+nobinonly-0ubuntu0.9.10.1UNKNOWN
Ubuntu9.10noarchfirefox-3.5< 3.5.8+build1+nobinonly-0ubuntu0.9.10.1UNKNOWN
Ubuntu9.10noarchabrowser-3.5-branding< 3.5.8+build1+nobinonly-0ubuntu0.9.10.1UNKNOWN
Ubuntu9.10noarchfirefox-3.5-branding< 3.5.8+build1+nobinonly-0ubuntu0.9.10.1UNKNOWN
Rows per page:
1-10 of 131

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

10

Confidence

High

EPSS

0.367

Percentile

97.2%