Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Debian: DSA-2268-1 Moderate: Iceweasel Remote Code Execution

debian
Calendar Grey July 1, 2011
Scroller Debian
Enhance Iceweasel to address urgent security flaws affecting its functionality and user experience.
Several vulnerabilities have been found in Iceweasel, a web browser based on Firefox: CVE-2011-0083 / CVE-2011-2363

Summary

Several vulnerabilities have been found in Iceweasel, a web browser
based on Firefox:

CVE-2011-0083 / CVE-2011-2363

"regenrecht" discovered two use-after-frees in SVG processing, which
could lead to the execution of arbitrary code.

CVE-2011-0085

"regenrecht" discovered a use-after-free in XUL processing, which
could lead to the execution of arbitrary code.

CVE-2011-2362

David Chan discovered that cookies were insufficiently isolated.

CVE-2011-2371

Chris Rohlf and Yan Ivnitskiy discovered an integer overflow in the
Javascript engine, which could lead to the execution of arbitrary
code.

CVE-2011-2373

Martin Barbella discovered a use-after-free in XUL processing,
which could lead to the execution of arbitrary code.

CVE-2011-2374

Bob Clary, Kevin Brosnan, Nils, Gary Kwong, Jesse Ruderman and
Christian Biesinger discovered memory corruption bugs, which may
lead to the execution of arbitrary code.

CVE-2011-2376

Luke Wagner and Gary Kwong discovered memory corruption b...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Package: iceweasel
CVE ID: CVE-2011-0083 CVE-2011-0085 CVE-2011-2362 CVE-2011-2363

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.