Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Several security issues were fixed in Xulrunner.
Software Description:
- xulrunner-1.9.2: Mozilla Gecko runtime environment
Details:
Jesse Ruderman and Bob Clary discovered memory safety issues affecting the
Gecko Browser engine. If the user were tricked into opening a specially
crafted page, an attacker could exploit these to cause a denial of service
via application crash, or potentially execute code with the privileges of
the user invoking Xulrunner. (CVE-2012-0442)
It was discovered that the Gecko Browser engine did not properly handle
node removal in the DOM. If the user were tricked into opening a specially
crafted page, an attacker could exploit this to cause a denial of service
via application crash, or potentially execute code with the privileges of
the user invoking Xulrunner. (CVE-2011-3659)
It was discovered that memory corruption could occur during the decoding of
Ogg Vorbis files. If the user were tricked into opening a specially crafted
fil...
The problem can be corrected by updating your system to the following package versions: Ubuntu 10.10: xulrunner-1.9.2 1.9.2.26+build2+nobinonly-0ubuntu0.10.10.1 Ubuntu 10.04 LTS: xulrunner-1.9.2 1.9.2.26+build2+nobinonly-0ubuntu0.10.04.1 After a standard system update you need to restart Yelp or any other application based on Xulrunner to make all the necessary changes.
CVE-2011-3659, CVE-2011-3659, CVE-2011-3670, CVE-2012-0442,
CVE-2012-0444, CVE-2012-0449
Get the latest Linux and open source security news straight to your inbox.