Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

Debian DSA-1999-1 Critical: Xulrunner Remote Threats Exploited

debian
Calendar Grey February 18, 2010
Debian Logo
The security notice DSA-1999-1 from Debian pertains to severe vulnerabilities found within Xulrunner components, which may enable remote execution of arbitrary code.
Several remote vulnerabilities have been discovered in Xulrunner, a runtime environment for XUL applications, such as the Iceweasel web browser

Summary

Several remote vulnerabilities have been discovered in Xulrunner, a
runtime environment for XUL applications, such as the Iceweasel web
browser. The Common Vulnerabilities and Exposures project identifies
the following problems:

CVE-2009-1571

Alin Rad Pop discovered that incorrect memory handling in the
HTML parser could lead to the execution of arbitrary code.

CVE-2009-3988

Hidetake Jo discovered that the same-origin policy can be
bypassed through window.dialogArguments.

CVE-2010-0159

Henri Sivonen, Boris Zbarsky, Zack Weinberg, Bob Clary, Martijn
Wargers and Paul Nickerson reported crashes in layout engine,
which might allow the execution of arbitrary code.

CVE-2010-0160

Orlando Barrera II discovered that incorrect memory handling in the
implementation of the web worker API could lead to the execution
of arbitrary code.

CVE-2010-0162

Georgi Guninski discovered that the same origin policy can be
bypassed through specially crafted SVG documents.

For the ...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: xulrunner

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here