Lucene search

K
ubuntucveUbuntu.comUB:CVE-2010-3768
HistoryDec 09, 2010 - 12:00 a.m.

CVE-2010-3768

2010-12-0900:00:00
ubuntu.com
ubuntu.com
29

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.174

Percentile

96.1%

Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird before
3.0.11 and 3.1.x before 3.1.7, and SeaMonkey before 2.0.11 do not properly
validate downloadable fonts before use within an operating system’s font
implementation, which allows remote attackers to execute arbitrary code via
vectors related to @font-face Cascading Style Sheets (CSS) rules.

Notes

Author Note
jdstrand Ubuntu 11.04 (Natty Narwhal) has 4.0b7. Fixes will be in 4.0b8.
OSVersionArchitecturePackageVersionFilename
ubuntu10.04noarchfirefox< 3.6.13+build3+nobinonly-0ubuntu0.10.04.1UNKNOWN
ubuntu10.10noarchfirefox< 3.6.13+build3+nobinonly-0ubuntu0.10.10.1UNKNOWN
ubuntu8.04noarchfirefox-3.0< 3.6.13+build3+nobinonly-0ubuntu0.8.04.1UNKNOWN
ubuntu9.10noarchfirefox-3.5< 3.6.13+build3+nobinonly-0ubuntu0.9.10.1UNKNOWN
ubuntu8.04noarchseamonkey< 2.0.11+build1+nobinonly-0ubuntu0.8.04.1UNKNOWN
ubuntu9.10noarchseamonkey< 2.0.11+build1+nobinonly-0ubuntu0.9.10.1UNKNOWN
ubuntu10.04noarchseamonkey< 2.0.11+build1+nobinonly-0ubuntu0.10.04.1UNKNOWN
ubuntu10.10noarchseamonkey< 2.0.11+build1+nobinonly-0ubuntu0.10.10.1UNKNOWN
ubuntu8.04noarchxulrunner-1.9.2< 1.9.2.13+build3+nobinonly-0ubuntu0.8.04.1UNKNOWN
ubuntu9.10noarchxulrunner-1.9.2< 1.9.2.13+build3+nobinonly-0ubuntu0.9.10.1UNKNOWN
Rows per page:
1-10 of 121

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.174

Percentile

96.1%