Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Debian 5.0 DSA-2075-1 Critical: Xulrunner Remote Code Threats Fixed

debian
Calendar Grey July 27, 2010
Debian Logo
Uncover solutions for various security gaps in Xulrunner via Debian DSA-2075-1, guaranteeing a safe ecosystem for XUL applications.
Several remote vulnerabilities have been discovered in Xulrunner, a runtime environment for XUL applications

Summary

Several remote vulnerabilities have been discovered in Xulrunner, a
runtime environment for XUL applications. The Common Vulnerabilities
and Exposures project identifies the following problems:

CVE-2010-0182

Wladimir Palant discovered that security checks in XML processing
were insufficiently enforced.

CVE-2010-0654

Chris Evans discovered that insecure CSS handling could lead to
reading data across domain boundaries.

CVE-2010-1205

Aki Helin discovered a buffer overflow in the internal copy of
libpng, which could lead to the execution of arbitrary code.

CVE-2010-1208

"regenrecht" discovered that incorrect memory handling in DOM
parsing could lead to the execution of arbitrary code.

CVE-2010-1211

Jesse Ruderman, Ehsan Akhgari, Mats Palmgren, Igor Bukanov, Gary
Kwong, Tobias Markus and Daniel Holbert discovered crashes in the
layout engine, which might allow the execution of arbitrary code.

CVE-2010-1214

"JS3" discovered an integer overflow in the plugin cod...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: xulrunner

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here