Your submission was sent successfully! Close

CVE-2010-1209

Published: 23 July 2010

Use-after-free vulnerability in the NodeIterator implementation in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to execute arbitrary code via a crafted NodeFilter that detaches DOM nodes, related to the NodeIterator interface and a javascript callback.

Notes

AuthorNote
jdstrand
CVEs in Firefox are tracked in the xulrunner source packages for
builds that use the system xulrunner, and firefox source packages for those
that use a static build
xulrunner (1.8.0): firefox (1.5) - Ubuntu 6.06 LTS (system xul)
xulrunner (1.8.1): firefox (2.0) - Ubuntu 6.10 - 8.04 LTS (system xul)
xulrunner-1.9: (ignored) reverse dependencies no longer process web content
xulrunner-1.9.1: (ignored) reverese dependencies no longer process web content
xulrunner-1.9.2: system xul for reverese dependencies that process web content
firefox: Ubuntu 6.06 LTS (static build)
firefox: Ubuntu 10.04 LTS and higher (static build of 3.6.x or higher)
firefox-3.0: Ubuntu 8.04 LTS, 9.04 (static build of 3.6.x)
firefox-3.5: Ubuntu 9.04 (ignored, uses system xul 1.9.1. Use 3.0 instead)
firefox-3.5: Ubuntu 9.10 (static build of 3.6.x)
Priority

Medium

Status

Package Release Status
firefox
Launchpad, Ubuntu, Debian
dapper Ignored
(reached end-of-life)
hardy Ignored
(uses system xulrunner)
jaunty Does not exist

karmic Does not exist

lucid
Released (3.6.7+build2+nobinonly-0ubuntu0.10.04.1)
upstream Needs triage

firefox-3.0
Launchpad, Ubuntu, Debian
dapper Does not exist

hardy
Released (3.6.7+build2+nobinonly-0ubuntu0.8.04.1)
jaunty
Released (3.6.7+build2+nobinonly-0ubuntu0.9.04.1)
karmic Does not exist

lucid Does not exist

upstream Needs triage
(Ubuntu source uses 3.6.x)
firefox-3.5
Launchpad, Ubuntu, Debian
dapper Does not exist

hardy Does not exist

jaunty Ignored

karmic
Released (3.6.7+build2+nobinonly-0ubuntu0.9.10.1)
lucid Does not exist

upstream Needs triage
(Ubuntu source uses 3.6.x)
xulrunner-1.9.2
Launchpad, Ubuntu, Debian
dapper Does not exist

hardy
Released (1.9.2.7+build2+nobinonly-0ubuntu0.8.04.2)
jaunty
Released (1.9.2.7+build2+nobinonly-0ubuntu0.9.04.2)
karmic
Released (1.9.2.7+build2+nobinonly-0ubuntu0.9.10.2)
lucid
Released (1.9.2.7+build2+nobinonly-0ubuntu0.10.04.1)
upstream Needs triage