Alerts This Week
Warning Icon 1 684
Alerts This Week
Warning Icon 1 684

Debian Iceweasel DSA-2565-1 Critical Remote Code Threat Advisory

debian
Calendar Grey October 23, 2012
Debian Logo
Uncover various security flaws in Iceweasel, the Debian web browser, alongside the appropriate patches to safeguard your system.
Multiple vulnerabilities have been discovered in Iceweasel, Debian's version of the Mozilla Firefox web browser

Summary

Multiple vulnerabilities have been discovered in Iceweasel, Debian's
version of the Mozilla Firefox web browser. The Common
Vulnerabilities and Exposures project identifies the following
problems:

CVE-2012-3982
Multiple unspecified vulnerabilities in the browser engine
allow remote attackers to cause a denial of service (memory
corruption and application crash) or possibly execute
arbitrary code via unknown vectors.

CVE-2012-3986
Iceweasel does not properly restrict calls to DOMWindowUtils
methods, which allows remote attackers to bypass intended
access restrictions via crafted JavaScript code.

CVE-2012-3990
A Use-after-free vulnerability in the IME State Manager
implementation allows remote attackers to execute arbitrary
code via unspecified vectors, related to the
nsIContent::GetNameSpaceID function.

CVE-2012-3991
Iceweasel does not properly restrict JSAPI access to the
GetProperty function, which allows remote attackers to bypass
the Same Origin Policy and possibly have u...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: iceweasel
CVE ID: CVE-2012-3982 CVE-2012-3986 CVE-2012-3990 CVE-2012-3991

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here