CVE-2011-3002

Publication date 30 September 2011

Last updated 24 July 2024


Ubuntu priority

Almost Native Graphics Layer Engine (ANGLE), as used in Mozilla Firefox before 7.0 and SeaMonkey before 2.4, does not validate the return value of a GrowAtomTable function call, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger a memory-allocation error and a resulting buffer overflow.

Status

Package Ubuntu Release Status
firefox 11.04 natty
Fixed 7.0.1+build1+nobinonly-0ubuntu0.11.04.1
10.10 maverick
Not affected
10.04 LTS lucid
Not affected
8.04 LTS hardy Ignored end of life

References

Related Ubuntu Security Notices (USN)

    • USN-1222-1
    • Firefox vulnerabilities
    • 29 September 2011

Other references