Alerts This Week
Warning Icon 1 562
Alerts This Week
Warning Icon 1 562

Debian DSA-2064-1 Critical: Xulrunner Remote Code Execution

debian
Calendar Grey June 27, 2010
Debian Logo
Ubuntu Security Notice USN-3943-1 identifies multiple vulnerabilities in the openjdk package aimed at bolstering system integrity.
Several remote vulnerabilities have been discovered in Xulrunner, a runtime environment for XUL applications

Summary

Several remote vulnerabilities have been discovered in Xulrunner, a
runtime environment for XUL applications. The Common Vulnerabilities
and Exposures project identifies the following problems:

CVE-2010-0183

"wushi" discovered that incorrect pointer handling in the frame
processing code could lead to the execution of arbitrary code.

CVE-2010-1196

"Nils" discovered that an integer overflow in DOM node parsing could
lead to the execution of arbitrary code.

CVE-2010-1197

Ilja von Sprundel discovered that incorrect parsing of
Content-Disposition headers could lead to cross-site scripting.

CVE-2010-1198

Microsoft engineers discovered that incorrect memory handling in the
interaction of browser plugins could lead to the execution of
arbitrary code.

CVE-2010-1199

Martin Barbella discovered that an integer overflow in XSLT node
parsing could lead to the execution of arbitrary code.

CVE-2010-1200

Olli Pettay, Martijn Wargers, Justin Lebar, Jesse Ruderman, Ben
...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: xulrunner

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here