Oval Definition:oval:org.mitre.oval:def:7955
Revision Date:2014-06-23Version:18
Title:DSA-1532 xulrunner -- several vulnerabilities
Description:Several remote vulnerabilities have been discovered in Xulrunner, a runtime environment for XUL applications. The Common Vulnerabilities and Exposures project identifies the following problems: Peter Brodersen and Alexander Klink discovered that the autoselection of SSL client certificates could lead to users being tracked, resulting in a loss of privacy. moz_bug_r_a4 discovered that variants of CVE-2007-3738 and CVE-2007-5338 allow the execution of arbitrary code through XPCNativeWrapper. moz_bug_r_a4 discovered that insecure handling of event handlers could lead to cross-site scripting. Boris Zbarsky, Johnny Stenback and moz_bug_r_a4 discovered that incorrect principal handling could lead to cross-site scripting and the execution of arbitrary code. Tom Ferris, Seth Spitzer, Martin Wargers, John Daggett and Mats Palmgren discovered crashes in the layout engine, which might allow the execution of arbitrary code. georgi, tgirmann and Igor Bukanov discovered crashes in the Javascript engine, which might allow the execution of arbitrary code. Gregory Fleischer discovered that HTTP Referrer headers were handled incorrectly in combination with URLs containing Basic Authentication credentials with empty usernames, resulting in potential Cross-Site Request Forgery attacks. Gregory Fleischer discovered that web content fetched through the jar: protocol can use Java to connect to arbitrary ports. This is only an issue in combination with the non-free Java plugin. Chris Thomas discovered that background tabs could generate XUL popups overlaying the current tab, resulting in potential spoofing attacks. The Mozilla products from the old stable distribution (sarge) are no longer supported.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2007-3738
CVE-2007-4879
CVE-2007-5338
CVE-2008-1233
CVE-2008-1234
CVE-2008-1235
CVE-2008-1236
CVE-2008-1237
CVE-2008-1238
CVE-2008-1240
CVE-2008-1241
DSA-1532
Platform(s):Debian GNU/Linux 4.0
Product(s):xulrunner
Definition Synopsis
  • Debian GNU/Linux 4.0 is installed.
  • AND Architecture section
  • Architecture independent section
  • Installed architecture is all
  • AND Packages section
  • libxul-dev is earlier than 1.8.0.15~pre080323b-0etch1
  • OR libmozjs-dev is earlier than 1.8.0.15~pre080323b-0etch1
  • OR libsmjs1 is earlier than 1.8.0.15~pre080323b-0etch1
  • OR libmozillainterfaces-java is earlier than 1.8.0.15~pre080323b-0etch1
  • OR libxul-common is earlier than 1.8.0.15~pre080323b-0etch1
  • OR libsmjs-dev is earlier than 1.8.0.15~pre080323b-0etch1
  • OR libnspr4-dev is earlier than 1.8.0.15~pre080323b-0etch1
  • OR libnss3-dev is earlier than 1.8.0.15~pre080323b-0etch1
  • OR Architecture dependent section
  • Supported architectures section
  • Installed architecture is s390
  • OR Installed architecture is amd64
  • OR Installed architecture is sparc
  • OR Installed architecture is powerpc
  • OR Installed architecture is i386
  • OR Installed architecture is mips
  • OR Installed architecture is ia64
  • OR Installed architecture is alpha
  • OR Installed architecture is mipsel
  • AND Packages section
  • libxul0d is earlier than 1.8.0.15~pre080323b-0etch1
  • OR libnss3-0d-dbg is earlier than 1.8.0.15~pre080323b-0etch1
  • OR libmozjs0d-dbg is earlier than 1.8.0.15~pre080323b-0etch1
  • OR libnss3-0d is earlier than 1.8.0.15~pre080323b-0etch1
  • OR spidermonkey-bin is earlier than 1.8.0.15~pre080323b-0etch1
  • OR libnspr4-0d-dbg is earlier than 1.8.0.15~pre080323b-0etch1
  • OR xulrunner-gnome-support is earlier than 1.8.0.15~pre080323b-0etch1
  • OR libxul0d-dbg is earlier than 1.8.0.15~pre080323b-0etch1
  • OR libmozjs0d is earlier than 1.8.0.15~pre080323b-0etch1
  • OR xulrunner is earlier than 1.8.0.15~pre080323b-0etch1
  • OR libnss3-tools is earlier than 1.8.0.15~pre080323b-0etch1
  • OR python-xpcom is earlier than 1.8.0.15~pre080323b-0etch1
  • OR libnspr4-0d is earlier than 1.8.0.15~pre080323b-0etch1
  • BACK