Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Debian: DSA-2313-1 Moderate: Iceweasel Remote Code Execution

debian
Calendar Grey September 29, 2011
Debian Logo
Ubuntu Security Notice USN-4392-1 addresses several security flaws in Firefox that might allow for unauthorized access; upgrade promptly for safety.
Several vulnerabilities have been found in Iceweasel, a web browser based on Firefox: CVE-2011-2372

Summary

Several vulnerabilities have been found in Iceweasel, a web browser
based on Firefox:

CVE-2011-2372

Mariusz Mlynski discovered that websites could open a download
dialog - which has "open" as the default action -, while a user
presses the ENTER key.

CVE-2011-2995

Benjamin Smedberg, Bob Clary and Jesse Ruderman discovered crashes
in the rendering engine, which could lead to the execution of
arbitrary code.

CVE-2011-2998

Mark Kaplan discovered an integer underflow in the javascript
engine, which could lead to the execution of arbitrary code.

CVE-2011-2999

Boris Zbarsky discovered that incorrect handling of the
window.location object could lead to bypasses of the same-origin
policy.

CVE-2011-3000

Ian Graham discovered that multiple Location headers might lead to
CRLF injection.

For the oldstable distribution (lenny), this problem has been fixed in
version 1.9.0.19-14 of the xulrunner source package. This update also
marks the compromised DigiNotar root certs as revoked...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Package: iceweasel
CVE ID: CVE-2011-2372 CVE-2011-2995 CVE-2011-2998 CVE-2011-2999

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here