Oval Definition:oval:org.mitre.oval:def:7832
Revision Date:2014-06-23Version:18
Title:DSA-1840 xulrunner -- several vulnerabilities
Description:Several remote vulnerabilities have been discovered in Xulrunner, a runtime environment for XUL applications, such as the Iceweasel web browser. The Common Vulnerabilities and Exposures project identifies the following problems: Martijn Wargers, Arno Renevier, Jesse Ruderman, Olli Pettay and Blake Kaplan discovered several issues in the browser engine that could potentially lead to the execution of arbitrary code. (MFSA 2009-34) monarch2020 reported an integer overflow in a base64 decoding function. (MFSA 2009-34) Christophe Charron reported a possibly exploitable crash occuring when multiple RDF files were loaded in a XUL tree element. (MFSA 2009-34) Yongqian Li reported that an unsafe memory condition could be created by specially crafted document. (MFSA 2009-34) Peter Van der Beken, Mike Shaver, Jesse Ruderman, and Carsten Book discovered several issues in the JavaScript engine that could possibly lead to the execution of arbitrary JavaScript. (MFSA 2009-34) Attila Suszter discovered an issue related to a specially crafted Flash object, which could be used to run arbitrary code. (MFSA 2009-35) PenPal discovered that it is possible to execute arbitrary code via a specially crafted SVG element. (MFSA 2009-37) Blake Kaplan discovered a flaw in the JavaScript engine that might allow an attacker to execute arbitrary JavaScript with chrome privileges. (MFSA 2009-39) moz_bug_r_a4 discovered an issue in the JavaScript engine that could be used to perform cross-site scripting attacks. (MFSA 2009-40)
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2009-2462
CVE-2009-2463
CVE-2009-2464
CVE-2009-2465
CVE-2009-2466
CVE-2009-2467
CVE-2009-2469
CVE-2009-2471
CVE-2009-2472
DSA-1840
Platform(s):Debian GNU/Linux 5.0
Product(s):xulrunner
Definition Synopsis
  • Debian GNU/Linux 5.0 is installed
  • AND Architecture section
  • Architecture independent section
  • Installed architecture is all
  • AND libmozillainterfaces-java is earlier than 1.9.0.12-0lenny1
  • OR Architecture dependent section
  • Supported architectures section
  • Installed architecture is s390
  • OR Installed architecture is amd64
  • OR Installed architecture is sparc
  • OR Installed architecture is powerpc
  • OR Installed architecture is i386
  • OR Installed architecture is armel
  • OR Installed architecture is ia64
  • OR Installed architecture is alpha
  • OR Installed architecture is hppa
  • AND Packages section
  • libmozjs-dev is earlier than 1.9.0.12-0lenny1
  • OR spidermonkey-bin is earlier than 1.9.0.12-0lenny1
  • OR xulrunner-dev is earlier than 1.9.0.12-0lenny1
  • OR xulrunner-1.9 is earlier than 1.9.0.12-0lenny1
  • OR libmozjs1d-dbg is earlier than 1.9.0.12-0lenny1
  • OR libmozjs1d is earlier than 1.9.0.12-0lenny1
  • OR python-xpcom is earlier than 1.9.0.12-0lenny1
  • OR xulrunner-1.9-dbg is earlier than 1.9.0.12-0lenny1
  • OR xulrunner-1.9-gnome-support is earlier than 1.9.0.12-0lenny1
  • BACK