Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Debian DSA-1840-1 Moderate: Xulrunner Remote Code Execution

debian
Calendar Grey July 23, 2009
Scroller Debian
Uncover the latest enhancements for GeckoDriver tackling several external threats. Update today for improved protection and reliability.
Several remote vulnerabilities have been discovered in Xulrunner, a runtime environment for XUL applications, such as the Iceweasel web browser

Summary

CVE-2009-2462

Martijn Wargers, Arno Renevier, Jesse Ruderman, Olli Pettay and Blake
Kaplan disocvered several issues in the browser engine that could
potentially lead to the execution of arbitrary code. (MFSA 2009-34)

CVE-2009-2463

monarch2020 reported an integer overflow in a base64 decoding function.
(MFSA 2009-34)

CVE-2009-2464

Christophe Charron reported a possibly exploitable crash occuring when
multiple RDF files were loaded in a XUL tree element. (MFSA 2009-34)

CVE-2009-2465

Yongqian Li reported that an unsafe memory condition could be created by
specially crafted document. (MFSA 2009-34)

CVE-2009-2466

Peter Van der Beken, Mike Shaver, Jesse Ruderman, and Carsten Book
discovered seve...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Package: xulrunner
CVE IDs: CVE-2009-2462 CVE-2009-2463 CVE-2009-2464 CVE-2009-2465

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.