CVE-2009-2464
Published: 22 July 2009
The nsXULTemplateQueryProcessorRDF::CheckIsSeparator function in Mozilla Firefox before 3.0.12, SeaMonkey 2.0a1pre, and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to loading multiple RDF files in a XUL tree element.
Notes
Author | Note |
---|---|
jdtrand |
per upstream bug, doesn't affect xul 1.8 |
Priority
Status
Package | Release | Status |
---|---|---|
firefox
Launchpad, Ubuntu, Debian |
dapper |
Ignored
(end of life)
|
hardy |
Ignored
(end of life)
|
|
intrepid |
Does not exist
|
|
jaunty |
Does not exist
|
|
karmic |
Does not exist
|
|
upstream |
Needs triage
|
|
mozilla-thunderbird
Launchpad, Ubuntu, Debian |
dapper |
Ignored
(end of life)
|
hardy |
Does not exist
|
|
intrepid |
Does not exist
|
|
jaunty |
Does not exist
|
|
karmic |
Does not exist
|
|
upstream |
Needs triage
|
|
thunderbird
Launchpad, Ubuntu, Debian |
dapper |
Does not exist
|
hardy |
Not vulnerable
|
|
intrepid |
Not vulnerable
|
|
jaunty |
Not vulnerable
|
|
karmic |
Not vulnerable
|
|
upstream |
Needs triage
|
|
xulrunner
Launchpad, Ubuntu, Debian |
dapper |
Does not exist
|
hardy |
Not vulnerable
|
|
intrepid |
Not vulnerable
|
|
jaunty |
Not vulnerable
|
|
karmic |
Not vulnerable
|
|
upstream |
Needs triage
|
|
xulrunner-1.9
Launchpad, Ubuntu, Debian |
dapper |
Does not exist
|
hardy |
Released
(1.9.0.12+build1+nobinonly-0ubuntu0.8.04.1)
|
|
intrepid |
Released
(1.9.0.12+build1+nobinonly-0ubuntu0.8.10.2)
|
|
jaunty |
Released
(1.9.0.12+build1+nobinonly-0ubuntu0.9.04.1)
|
|
karmic |
Does not exist
|
|
upstream |
Needs triage
|
|
xulrunner-1.9.1
Launchpad, Ubuntu, Debian |
dapper |
Does not exist
|
hardy |
Does not exist
|
|
intrepid |
Does not exist
|
|
jaunty |
Released
(1.9.1.1+build1+nobinonly-0ubuntu0.9.04.1)
|
|
karmic |
Released
(1.9.1.1+build1+nobinonly-0ubuntu1)
|
|
upstream |
Needs triage
|