CVE-2010-0175

Publication date 5 April 2010

Last updated 24 July 2024


Ubuntu priority

Use-after-free vulnerability in the nsTreeSelection implementation in Mozilla Firefox before 3.0.19 and 3.5.x before 3.5.9, Thunderbird before 3.0.4, and SeaMonkey before 2.0.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors that trigger a call to the handler for the select event for XUL tree items.

Read the notes from the security team

Status

Package Ubuntu Release Status
firefox 10.04 LTS lucid
Fixed 3.6.3+nobinonly-0ubuntu2
9.10 karmic Not in release
9.04 jaunty Not in release
8.10 intrepid Not in release
8.04 LTS hardy
Not affected
6.06 LTS dapper Ignored end of life
seamonkey 10.04 LTS lucid
Fixed 2.0.8+build1+nobinonly-0ubuntu0.10.04.1
9.10 karmic
Fixed 2.0.8+build1+nobinonly-0ubuntu0.9.10.1
9.04 jaunty
Fixed 2.0.8+build1+nobinonly-0ubuntu0.9.04.1
8.10 intrepid Ignored end of life, was needed
8.04 LTS hardy
Fixed 2.0.8+build1+nobinonly-0ubuntu0.8.04.1
6.06 LTS dapper Not in release
thunderbird 10.04 LTS lucid
Fixed 3.0.4+nobinonly-0ubuntu1
9.10 karmic Ignored
9.04 jaunty Ignored
8.10 intrepid Ignored
8.04 LTS hardy Ignored
6.06 LTS dapper Not in release
xulrunner-1.9 10.04 LTS lucid Not in release
9.10 karmic Not in release
9.04 jaunty
Fixed 1.9.0.19+nobinonly-0ubuntu0.9.04.1
8.10 intrepid
Fixed 1.9.0.19+nobinonly-0ubuntu0.8.10.1
8.04 LTS hardy
Fixed 1.9.0.19+nobinonly-0ubuntu0.8.04.1
6.06 LTS dapper Not in release
xulrunner-1.9.1 10.04 LTS lucid Not in release
9.10 karmic
Fixed 1.9.1.9+nobinonly-0ubuntu0.9.10.1
9.04 jaunty
Fixed 1.9.1.9+nobinonly-0ubuntu0.9.04.1
8.10 intrepid Not in release
8.04 LTS hardy Not in release
6.06 LTS dapper Not in release

Notes


jdstrand

per Chris Coulson, tbird requires javascript to be enabled

References

Related Ubuntu Security Notices (USN)

    • USN-920-1
    • Firefox 3.0 and Xulrunner vulnerabilities
    • 9 April 2010
    • USN-921-1
    • Firefox 3.5 and Xulrunner vulnerabilities
    • 9 April 2010

Other references