Lucene search

K
ubuntucveUbuntu.comUB:CVE-2010-3769
HistoryDec 10, 2010 - 12:00 a.m.

CVE-2010-3769

2010-12-1000:00:00
ubuntu.com
ubuntu.com
18

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.2

Percentile

96.4%

The line-breaking implementation in Mozilla Firefox before 3.5.16 and 3.6.x
before 3.6.13, Thunderbird before 3.0.11 and 3.1.x before 3.1.7, and
SeaMonkey before 2.0.11 on Windows does not properly handle long strings,
which allows remote attackers to execute arbitrary code via a crafted
document.write call that triggers a buffer over-read.

Notes

Author Note
jdstrand Ubuntu 11.04 (Natty Narwhal) has 4.0b7. Fixes will be in 4.0b8. thunderbird low (javascript not enabled by default)
OSVersionArchitecturePackageVersionFilename
ubuntu10.04noarchfirefox< 3.6.13+build3+nobinonly-0ubuntu0.10.04.1UNKNOWN
ubuntu10.10noarchfirefox< 3.6.13+build3+nobinonly-0ubuntu0.10.10.1UNKNOWN
ubuntu11.04noarchfirefox< 4.0~b8+nobinonly-0ubuntu3UNKNOWN
ubuntu8.04noarchfirefox-3.0< 3.6.13+build3+nobinonly-0ubuntu0.8.04.1UNKNOWN
ubuntu9.10noarchfirefox-3.5< 3.6.13+build3+nobinonly-0ubuntu0.9.10.1UNKNOWN
ubuntu8.04noarchseamonkey< 2.0.11+build1+nobinonly-0ubuntu0.8.04.1UNKNOWN
ubuntu9.10noarchseamonkey< 2.0.11+build1+nobinonly-0ubuntu0.9.10.1UNKNOWN
ubuntu10.04noarchseamonkey< 2.0.11+build1+nobinonly-0ubuntu0.10.04.1UNKNOWN
ubuntu10.10noarchseamonkey< 2.0.11+build1+nobinonly-0ubuntu0.10.10.1UNKNOWN
ubuntu11.04noarchseamonkey< 2.0.11+build1+nobinonly-0ubuntu1UNKNOWN
Rows per page:
1-10 of 181

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.2

Percentile

96.4%