Lucene search

K
ubuntucveUbuntu.comUB:CVE-2010-1212
HistoryJul 23, 2010 - 12:00 a.m.

CVE-2010-1212

2010-07-2300:00:00
ubuntu.com
ubuntu.com
15

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.039

Percentile

92.0%

js/src/jstracer.cpp in the browser engine in Mozilla Firefox 3.6.x before
3.6.7 and Thunderbird 3.1.x before 3.1.1 allows remote attackers to cause a
denial of service (memory corruption and application crash) or possibly
execute arbitrary code via vectors related to (1) propagation of deep
aborts in the TraceRecorder::record_JSOP_BINDNAME function, (2) depth
handling in the TraceRecorder::record_JSOP_GETELEM function, and (3)
tracing of out-of-range arguments in the TraceRecorder::record_JSOP_ARGSUB
function.

Notes

Author Note
jdstrand CVEs in Firefox are tracked in the xulrunner source packages for builds that use the system xulrunner, and firefox source packages for those that use a static build xulrunner (1.8.0): firefox (1.5) - Ubuntu 6.06 LTS (system xul) xulrunner (1.8.1): firefox (2.0) - Ubuntu 6.10 - 8.04 LTS (system xul) xulrunner-1.9: (ignored) reverse dependencies no longer process web content xulrunner-1.9.1: (ignored) reverese dependencies no longer process web content xulrunner-1.9.2: system xul for reverese dependencies that process web content firefox: Ubuntu 6.06 LTS (static build) firefox: Ubuntu 10.04 LTS and higher (static build of 3.6.x or higher) firefox-3.0: Ubuntu 8.04 LTS, 9.04 (static build of 3.6.x) firefox-3.5: Ubuntu 9.04 (ignored, uses system xul 1.9.1. Use 3.0 instead) firefox-3.5: Ubuntu 9.10 (static build of 3.6.x)
OSVersionArchitecturePackageVersionFilename
ubuntu10.04noarchfirefox< 3.6.7+build2+nobinonly-0ubuntu0.10.04.1UNKNOWN
ubuntu8.04noarchfirefox-3.0< 3.6.7+build2+nobinonly-0ubuntu0.8.04.1UNKNOWN
ubuntu9.04noarchfirefox-3.0< 3.6.7+build2+nobinonly-0ubuntu0.9.04.1UNKNOWN
ubuntu9.10noarchfirefox-3.5< 3.6.7+build2+nobinonly-0ubuntu0.9.10.1UNKNOWN
ubuntu8.04noarchxulrunner-1.9.2< 1.9.2.7+build2+nobinonly-0ubuntu0.8.04.2UNKNOWN
ubuntu9.04noarchxulrunner-1.9.2< 1.9.2.7+build2+nobinonly-0ubuntu0.9.04.2UNKNOWN
ubuntu9.10noarchxulrunner-1.9.2< 1.9.2.7+build2+nobinonly-0ubuntu0.9.10.2UNKNOWN
ubuntu10.04noarchxulrunner-1.9.2< 1.9.2.7+build2+nobinonly-0ubuntu0.10.04.1UNKNOWN

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.039

Percentile

92.0%