Oval Definition:oval:org.mitre.oval:def:7945
Revision Date:2014-06-23Version:18
Title:DSA-1922 xulrunner -- several vulnerabilities
Description:Several remote vulnerabilities have been discovered in Xulrunner, a runtime environment for XUL applications, such as the Iceweasel web browser. The Common Vulnerabilities and Exposures project identifies the following problems: Vladimir Vukicevic, Jesse Ruderman, Martijn Wargers, Daniel Banchero, David Keeler and Boris Zbarsky reported crashes in layout engine, which might allow the execution of arbitrary code. Carsten Book reported a crash in the layout engine, which might allow the execution of arbitrary code. Jesse Ruderman and Sid Stamm discovered spoofing vulnerability in the file download dialog. Gregory Fleischer discovered a bypass of the same-origin policy using the document.getSelection() function. "moz_bug_r_a4" discovered a privilege escalation to Chrome status in the XPCOM utility XPCVariant::VariantDataToJS. "regenrecht" discovered a buffer overflow in the GIF parser, which might lead to the execution of arbitrary code. Marco C. discovered that a programming error in the proxy auto configuration code might lead to denial of service or the execution of arbitrary code. Jeremy Brown discovered that the filename of a downloaded file which is opened by the user is predictable, which might lead to tricking the user into a malicious file if the attacker has local access to the system. Paul Stone discovered that history information from web forms could be stolen.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2009-3274
CVE-2009-3370
CVE-2009-3372
CVE-2009-3373
CVE-2009-3374
CVE-2009-3375
CVE-2009-3376
CVE-2009-3380
CVE-2009-3382
DSA-1922
Platform(s):Debian GNU/Linux 5.0
Product(s):xulrunner
Definition Synopsis
  • Debian GNU/Linux 5.0 is installed
  • AND Architecture section
  • Architecture independent section
  • Installed architecture is all
  • AND libmozillainterfaces-java is earlier than 1.9.0.15-0lenny1
  • OR libmozjs-dev is earlier than 1.9.0.15-0lenny1
  • OR spidermonkey-bin is earlier than 1.9.0.15-0lenny1
  • OR xulrunner-1.9-gnome-support is earlier than 1.9.0.15-0lenny1
  • OR xulrunner-1.9 is earlier than 1.9.0.15-0lenny1
  • OR libmozjs1d-dbg is earlier than 1.9.0.15-0lenny1
  • OR libmozjs1d is earlier than 1.9.0.15-0lenny1
  • OR python-xpcom is earlier than 1.9.0.15-0lenny1
  • OR xulrunner-1.9-dbg is earlier than 1.9.0.15-0lenny1
  • OR xulrunner-dev is earlier than 1.9.0.15-0lenny1
  • BACK