CVE-2009-0352

Published: 04 February 2009

Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.6, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the layout engine and destruction of arbitrary layout objects by the nsViewManager::Composite function.

Priority

Medium

Status

Package Release Status
firefox
Launchpad, Ubuntu, Debian
Upstream Not vulnerable

firefox-3.0
Launchpad, Ubuntu, Debian
Upstream
Released (3.0.6)
iceape
Launchpad, Ubuntu, Debian
Upstream Needs triage

icedove
Launchpad, Ubuntu, Debian
Upstream Needs triage

iceweasel
Launchpad, Ubuntu, Debian
Upstream Needs triage

mozilla-thunderbird
Launchpad, Ubuntu, Debian
Upstream Needs triage

seamonkey
Launchpad, Ubuntu, Debian
Upstream
Released (1.1.15)
thunderbird
Launchpad, Ubuntu, Debian
Upstream
Released (2.0.0.21)
xulrunner
Launchpad, Ubuntu, Debian
Upstream Not vulnerable

xulrunner-1.9
Launchpad, Ubuntu, Debian
Upstream
Released (1.9.0.6)