Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Ubuntu 10.10: Addressing Critical DoS Vulnerabilities in Xulrunner

ubuntu
Calendar Grey February 8, 2012
Scroller Ubuntu
Security vulnerabilities addressed in Ubuntu 10.10 & 10.04 LTS for Xulrunner, mitigating potential Denial of Service or code execution threats.
Several security issues were fixed in Xulrunner.

Summary

Several security issues were fixed in Xulrunner.

Software Description:

- xulrunner-1.9.2: Mozilla Gecko runtime environment

Details:

Jesse Ruderman and Bob Clary discovered memory safety issues affecting the

Gecko Browser engine. If the user were tricked into opening a specially

crafted page, an attacker could exploit these to cause a denial of service

via application crash, or potentially execute code with the privileges of

the user invoking Xulrunner. (CVE-2012-0442)

It was discovered that the Gecko Browser engine did not properly handle

node removal in the DOM. If the user were tricked into opening a specially

crafted page, an attacker could exploit this to cause a denial of service

via application crash, or potentially execute code with the privileges of

the user invoking Xulrunner. (CVE-2011-3659)

It was discovered that memory corruption could occur during the decoding of

Ogg Vorbis files. If the user were tricked into opening a specially crafted

fil...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 10.10:
  xulrunner-1.9.2                 1.9.2.26+build2+nobinonly-0ubuntu0.10.10.1

Ubuntu 10.04 LTS:
  xulrunner-1.9.2                 1.9.2.26+build2+nobinonly-0ubuntu0.10.04.1

After a standard system update you need to restart Yelp or any other
application based on Xulrunner to make all the necessary changes.

References

CVE-2011-3659, CVE-2011-3659, CVE-2011-3670, CVE-2012-0442,

CVE-2012-0444, CVE-2012-0449

Severity
critical
Lowest
Low
Medium
High
Critical

February 08, 2012

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.