Oval Definition:oval:org.mitre.oval:def:13323
Revision Date:2014-06-30Version:20
Title:USN-921-1 -- firefox-3.5, xulrunner-1.9.1 vulnerabilities
Description:Martijn Wargers, Josh Soref, Jesse Ruderman, and Ehsan Akhgari discovered flaws in the browser engine of Firefox. If a user were tricked into viewing a malicious website, a remote attacker could cause a denial of service or possibly execute arbitrary code with the privileges of the user invoking the program. It was discovered that Firefox could be made to access previously freed memory. If a user were tricked into viewing a malicious website, a remote attacker could cause a denial of service or possibly execute arbitrary code with the privileges of the user invoking the program. Paul Stone discovered that Firefox could be made to change a mouse click into a drag and drop event. If the user could be tricked into performing this action twice on a crafted website, an attacker could execute arbitrary JavaScript with chrome privileges. It was discovered that the XMLHttpRequestSpy module as used by the Firebug add-on could be used to escalate privileges within the browser. If the user had the Firebug add-on installed and were tricked into viewing a malicious website, an attacker could potentially run arbitrary JavaScript. Henry Sudhof discovered that an image tag could be used as a redirect to a mailto: URL to launch an external mail handler. Wladimir Palant discovered that Firefox did not always perform security checks on XML content. An attacker could exploit this to bypass security policies to load certain resources
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2010-0173
CVE-2010-0174
CVE-2010-0175
CVE-2010-0176
CVE-2010-0177
CVE-2010-0178
CVE-2010-0179
CVE-2010-0181
CVE-2010-0182
USN-921-1
USN-921-1
Platform(s):Ubuntu 9.10
Product(s):firefox-3.5
xulrunner-1.9.1
Definition Synopsis
  • Ubuntu 9.10 is installed
  • AND Architecture section
  • Architecture independet section
  • Installed architecture is all
  • AND Packages section
  • firefox-3.1-gnome-support DPKG is earlier than 3.5.9+nobinonly-0ubuntu0.9.10.1
  • OR firefox-3.0 DPKG is earlier than 3.5.9+nobinonly-0ubuntu0.9.10.1
  • OR firefox-3.0-venkman DPKG is earlier than 3.5.9+nobinonly-0ubuntu0.9.10.1
  • OR firefox DPKG is earlier than 3.5.9+nobinonly-0ubuntu0.9.10.1
  • OR firefox-3.1-dev DPKG is earlier than 3.5.9+nobinonly-0ubuntu0.9.10.1
  • OR firefox-gnome-support DPKG is earlier than 3.5.9+nobinonly-0ubuntu0.9.10.1
  • OR firefox-3.0-branding DPKG is earlier than 3.5.9+nobinonly-0ubuntu0.9.10.1
  • OR firefox-dom-inspector DPKG is earlier than 3.5.9+nobinonly-0ubuntu0.9.10.1
  • OR firefox-3.1 DPKG is earlier than 3.5.9+nobinonly-0ubuntu0.9.10.1
  • OR abrowser-3.5 DPKG is earlier than 3.5.9+nobinonly-0ubuntu0.9.10.1
  • OR firefox-3.1-dbg DPKG is earlier than 3.5.9+nobinonly-0ubuntu0.9.10.1
  • OR firefox-3.0-gnome-support DPKG is earlier than 3.5.9+nobinonly-0ubuntu0.9.10.1
  • OR abrowser-3.1 DPKG is earlier than 3.5.9+nobinonly-0ubuntu0.9.10.1
  • OR abrowser-3.1-branding DPKG is earlier than 3.5.9+nobinonly-0ubuntu0.9.10.1
  • OR abrowser-3.0-branding DPKG is earlier than 3.5.9+nobinonly-0ubuntu0.9.10.1
  • OR firefox-3.0-dom-inspector DPKG is earlier than 3.5.9+nobinonly-0ubuntu0.9.10.1
  • OR firefox-3.1-branding DPKG is earlier than 3.5.9+nobinonly-0ubuntu0.9.10.1
  • OR abrowser DPKG is earlier than 3.5.9+nobinonly-0ubuntu0.9.10.1
  • OR firefox-3.0-dev DPKG is earlier than 3.5.9+nobinonly-0ubuntu0.9.10.1
  • OR abrowser-3.0 DPKG is earlier than 3.5.9+nobinonly-0ubuntu0.9.10.1
  • OR Architecture depended section
  • Supported architectures section
  • Installed architecture is amd64
  • OR Installed architecture is i386
  • OR Installed architecture is powerpc
  • OR Installed architecture is sparc
  • OR Installed architecture is lpia
  • AND Packages section
  • firefox-3.5-branding DPKG is earlier than 3.5.9+nobinonly-0ubuntu0.9.10.1
  • OR xulrunner-1.9.1-dbg DPKG is earlier than 1.9.1.9+nobinonly-0ubuntu0.9.10.1
  • OR xulrunner-1.9.1-testsuite DPKG is earlier than 1.9.1.9+nobinonly-0ubuntu0.9.10.1
  • OR firefox-3.5 DPKG is earlier than 3.5.9+nobinonly-0ubuntu0.9.10.1
  • OR xulrunner-dev DPKG is earlier than 1.9.1.9+nobinonly-0ubuntu0.9.10.1
  • OR firefox-3.5-dev DPKG is earlier than 3.5.9+nobinonly-0ubuntu0.9.10.1
  • OR xulrunner-1.9.1-testsuite-dev DPKG is earlier than 1.9.1.9+nobinonly-0ubuntu0.9.10.1
  • OR firefox-3.5-gnome-support DPKG is earlier than 3.5.9+nobinonly-0ubuntu0.9.10.1
  • OR firefox-3.5-dbg DPKG is earlier than 3.5.9+nobinonly-0ubuntu0.9.10.1
  • OR xulrunner-1.9.1 DPKG is earlier than 1.9.1.9+nobinonly-0ubuntu0.9.10.1
  • OR xulrunner-1.9.1-dev DPKG is earlier than 1.9.1.9+nobinonly-0ubuntu0.9.10.1
  • OR abrowser-3.5-branding DPKG is earlier than 3.5.9+nobinonly-0ubuntu0.9.10.1
  • OR xulrunner-1.9.1-gnome-support DPKG is earlier than 1.9.1.9+nobinonly-0ubuntu0.9.10.1
  • BACK