CVE-2009-0773

Publication date 5 March 2009

Last updated 24 July 2024


Ubuntu priority

The JavaScript engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a splice of an array that contains "some non-set elements," which causes jsarray.cpp to pass an incorrect argument to the ResizeSlots function, which triggers memory corruption; (2) vectors related to js_DecompileValueGenerator, jsopcode.cpp, __defineSetter__, and watch, which triggers an assertion failure or a segmentation fault; and (3) vectors related to gczeal, __defineSetter__, and watch, which triggers a hang.

Status

Package Ubuntu Release Status
firefox 9.04 jaunty Not in release
8.10 intrepid Not in release
8.04 LTS hardy
Not affected
7.10 gutsy
Not affected
6.06 LTS dapper
Not affected
firefox-3.0 9.04 jaunty
Fixed 3.0.7+nobinonly-0ubuntu1
8.10 intrepid
Fixed 3.0.7+nobinonly-0ubuntu0.8.10.1
8.04 LTS hardy
Fixed 3.0.7+nobinonly-0ubuntu0.8.04.1
7.10 gutsy Ignored end of life, was needed
6.06 LTS dapper Not in release
firefox-3.5 9.04 jaunty
Fixed 3.5+nobinonly-0ubuntu0.9.04.1
8.10 intrepid Not in release
8.04 LTS hardy Not in release
7.10 gutsy Not in release
6.06 LTS dapper Not in release
iceape 9.04 jaunty Not in release
8.10 intrepid Not in release
8.04 LTS hardy Not in release
7.10 gutsy
Not affected
6.06 LTS dapper Not in release
icedove 9.04 jaunty Not in release
8.10 intrepid Not in release
8.04 LTS hardy Not in release
7.10 gutsy Not in release
6.06 LTS dapper Not in release
iceweasel 9.04 jaunty Not in release
8.10 intrepid Not in release
8.04 LTS hardy Not in release
7.10 gutsy Not in release
6.06 LTS dapper Not in release
mozilla-thunderbird 9.04 jaunty Not in release
8.10 intrepid Not in release
8.04 LTS hardy Not in release
7.10 gutsy Not in release
6.06 LTS dapper
Not affected
seamonkey 9.04 jaunty
Not affected
8.10 intrepid
Not affected
8.04 LTS hardy
Not affected
7.10 gutsy Not in release
6.06 LTS dapper Not in release
thunderbird 9.04 jaunty
Not affected
8.10 intrepid
Not affected
8.04 LTS hardy
Not affected
7.10 gutsy
Not affected
6.06 LTS dapper Not in release
xulrunner 9.04 jaunty
Not affected
8.10 intrepid
Not affected
8.04 LTS hardy
Not affected
7.10 gutsy
Not affected
6.06 LTS dapper Not in release
xulrunner-1.9 9.04 jaunty
Fixed 1.9.0.7+nobinonly-0ubuntu1
8.10 intrepid
Fixed 1.9.0.7+nobinonly-0ubuntu0.8.10.1
8.04 LTS hardy
Fixed 1.9.0.7+nobinonly-0ubuntu0.8.04.1
7.10 gutsy Ignored end of life, was needed
6.06 LTS dapper Not in release
xulrunner-1.9.1 9.04 jaunty
Fixed 1.9.1+nobinonly-0ubuntu0.9.04.1
8.10 intrepid Not in release
8.04 LTS hardy Not in release
7.10 gutsy Not in release
6.06 LTS dapper Not in release

References

Related Ubuntu Security Notices (USN)

    • USN-728-1
    • Firefox and Xulrunner vulnerabilities
    • 5 March 2009

Other references