Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Several security issues were fixed in Firefox.
Software Description:
- xulrunner-1.9.2: Mozilla Gecko runtime environment
Details:
It was discovered that a flaw in the Mozilla SVG implementation could
result in an out-of-bounds memory access if SVG elements were removed
during a DOMAttrModified event handler. If the user were tricked into
opening a specially crafted page, an attacker could exploit this to cause a
denial of service via application crash. (CVE-2011-3658)
Atte Kettunen discovered a use-after-free vulnerability in the Gecko
Rendering Engine's handling of SVG animations. An attacker could
potentially exploit this to execute arbitrary code with the privileges of
the user invoking the Xulrunner based application. (CVE-2012-0457)
Atte Kettunen discovered an out of bounds read vulnerability in the Gecko
Rendering Engine's handling of SVG Filters. An attacker could potentially
exploit this to make data from the user's memory accessible to the page
...
The problem can be corrected by updating your system to the following package versions: Ubuntu 10.10: xulrunner-1.9.2 1.9.2.28+build1+nobinonly-0ubuntu0.10.10.1 Ubuntu 10.04 LTS: xulrunner-1.9.2 1.9.2.28+build1+nobinonly-0ubuntu0.10.04.1 After a standard system update you need to restart any application based on Xulrunner such as Yelp or Conkeror to make all the necessary changes.
https://ubuntu.com/security/notices/USN-1401-1
CVE-2011-3658, CVE-2012-0455, CVE-2012-0456, CVE-2012-0457,
CVE-2012-0458, CVE-2012-0461, CVE-2012-0464, https://bugs.launchpad.net/ubuntu/+source/xulrunner-1.9.2/+bug/953736
Get the latest Linux and open source security news straight to your inbox.