CVE-2009-1838
Published: 12 June 2009
The garbage-collection implementation in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 sets an element's owner document to null in unspecified circumstances, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via a crafted event handler, related to an incorrect context for this event handler.
Notes
Author | Note |
---|---|
jdstrand | CVEs in Firefox are tracked in the xulrunner source packages. The mapping of xulrunner sources to firefox is: xulrunner (1.8.0): firefox (1.5) - Ubuntu 6.06 LTS xulrunner (1.8.1): firefox (2.0) - Ubuntu 6.10 - 8.04 LTS xulrunner-1.9: firefox-3.0 xulrunner-1.9.1: firefox-3.5 Ubuntu 6.06 LTS and 10.04 LTS uses the embedded xulrunner and not the system xulrunner-1.9.2, so it is tracked in the firefox source package. |
Priority
Status
Package | Release | Status |
---|---|---|
firefox Launchpad, Ubuntu, Debian |
dapper |
Ignored
(reached end-of-life)
|
hardy |
Ignored
(uses system xulrunner)
|
|
intrepid |
Does not exist
|
|
jaunty |
Does not exist
|
|
karmic |
Does not exist
|
|
lucid |
Not vulnerable
|
|
maverick |
Not vulnerable
|
|
natty |
Not vulnerable
|
|
oneiric |
Not vulnerable
|
|
upstream |
Needs triage
|
|
mozilla-thunderbird Launchpad, Ubuntu, Debian |
dapper |
Ignored
(reached end-of-life)
|
hardy |
Does not exist
|
|
intrepid |
Does not exist
|
|
jaunty |
Does not exist
|
|
karmic |
Does not exist
|
|
lucid |
Does not exist
|
|
maverick |
Does not exist
|
|
natty |
Does not exist
|
|
oneiric |
Does not exist
|
|
upstream |
Needs triage
|
|
seamonkey Launchpad, Ubuntu, Debian |
dapper |
Does not exist
|
hardy |
Released
(1.1.17+nobinonly-0ubuntu0.8.04.1)
|
|
intrepid |
Released
(1.1.17+nobinonly-0ubuntu0.8.10.1)
|
|
jaunty |
Released
(1.1.17+nobinonly-0ubuntu0.9.04.1)
|
|
karmic |
Released
(1.1.17+nobinonly-0ubuntu1)
|
|
lucid |
Released
(1.1.17+nobinonly-0ubuntu1)
|
|
maverick |
Released
(1.1.17+nobinonly-0ubuntu1)
|
|
natty |
Released
(1.1.17+nobinonly-0ubuntu1)
|
|
oneiric |
Released
(1.1.17+nobinonly-0ubuntu1)
|
|
upstream |
Needs triage
|
|
thunderbird Launchpad, Ubuntu, Debian |
dapper |
Does not exist
|
hardy |
Released
(2.0.0.22+build1+nobinonly-0ubuntu0.8.04.1)
|
|
intrepid |
Released
(2.0.0.22+build1+nobinonly-0ubuntu0.8.10.1)
|
|
jaunty |
Released
(2.0.0.22+build1+nobinonly-0ubuntu0.9.04.1)
|
|
karmic |
Released
(2.0.0.22+build1+nobinonly-0ubuntu1.nspr474)
|
|
lucid |
Released
(2.0.0.22+build1+nobinonly-0ubuntu1.nspr474)
|
|
maverick |
Released
(2.0.0.22+build1+nobinonly-0ubuntu1.nspr474)
|
|
natty |
Released
(2.0.0.22+build1+nobinonly-0ubuntu1.nspr474)
|
|
oneiric |
Released
(2.0.0.22+build1+nobinonly-0ubuntu1.nspr474)
|
|
upstream |
Needs triage
|
|
xulrunner Launchpad, Ubuntu, Debian |
dapper |
Does not exist
|
hardy |
Ignored
(reached end-of-life)
|
|
intrepid |
Needed
(reached end-of-life)
|
|
jaunty |
Ignored
(reached end-of-life)
|
|
karmic |
Ignored
(reached end-of-life)
|
|
lucid |
Does not exist
|
|
maverick |
Does not exist
|
|
natty |
Does not exist
|
|
oneiric |
Does not exist
|
|
upstream |
Needs triage
|
|
xulrunner-1.9 Launchpad, Ubuntu, Debian |
dapper |
Does not exist
|
hardy |
Released
(1.9.0.11+build2+nobinonly-0ubuntu0.8.04.1)
|
|
intrepid |
Released
(1.9.0.11+build2+nobinonly-0ubuntu0.8.10.2)
|
|
jaunty |
Released
(1.9.0.11+build2+nobinonly-0ubuntu0.9.04.1)
|
|
karmic |
Does not exist
|
|
lucid |
Does not exist
|
|
maverick |
Does not exist
|
|
natty |
Does not exist
|
|
oneiric |
Does not exist
|
|
upstream |
Needs triage
|
|
xulrunner-1.9.1 Launchpad, Ubuntu, Debian |
dapper |
Does not exist
|
hardy |
Does not exist
|
|
intrepid |
Does not exist
|
|
jaunty |
Released
(1.9.1+nobinonly-0ubuntu0.9.04.1)
|
|
karmic |
Released
(1.9.1~rc2+nobinonly-0ubuntu1)
|
|
lucid |
Does not exist
|
|
maverick |
Does not exist
|
|
natty |
Does not exist
|
|
oneiric |
Does not exist
|
|
upstream |
Needs triage
|