Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Debian: DSA-1751-1 Critical: Xulrunner Remote Code Execution

debian
Calendar Grey March 22, 2009
Scroller Debian
Latest xulrunner updates fortify Debian's defenses by tackling multiple online vulnerabilities proficiently.
Several remote vulnerabilities have been discovered in Xulrunner, a runtime environment for XUL applications, such as the Iceweasel web browser

Summary

Several remote vulnerabilities have been discovered in Xulrunner, a
runtime environment for XUL applications, such as the Iceweasel web
browser. The Common Vulnerabilities and Exposures project identifies
the following problems:

CVE-2009-0771

Martijn Wargers, Jesse Ruderman and Josh Soref discovered crashes
in the layout engine, which might allow the execution of arbitrary
code.

CVE-2009-0772

Jesse Ruderman discovered crashes in the layout engine, which
might allow the execution of arbitrary code.

CVE-2009-0773

Gary Kwong, and Timothee Groleau discovered crashes in the
Javascript engine, which might allow the execution of arbitrary code.

CVE-2009-0774

Gary Kwong discovered crashes in the Javascript engine, which
might allow the execution of arbitrary code.

CVE-2009-0775

It was discovered that incorrect memory management in the DOM
element handling may lead to the execution of arbitrary code.

CVE-2009-0776

Georgi Guninski discovered a violation of the sam...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: xulrunner
CVE ID: CVE-2009-0771 CVE-2009-0772 CVE-2009-0773 CVE-2009-0774 CVE-2009-0775 CVE-2009-0776

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.