CVE-2012-0452

Published: 13 February 2012

Use-after-free vulnerability in Mozilla Firefox 10.x before 10.0.1, Thunderbird 10.x before 10.0.1, and SeaMonkey 2.7 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger failure of an nsXBLDocumentInfo::ReadPrototypeBindings function call, related to the cycle collector's access to a hash table containing a stale XBL binding.

Priority

Medium

Status

Package Release Status
firefox
Launchpad, Ubuntu, Debian
Upstream
Released (10.0.1)
seamonkey
Launchpad, Ubuntu, Debian
Upstream
Released (2.7.1)
thunderbird
Launchpad, Ubuntu, Debian
Upstream
Released (10.0.1)
xulrunner-1.9.2
Launchpad, Ubuntu, Debian
Upstream Not vulnerable

xulrunner-2.0
Launchpad, Ubuntu, Debian
Upstream Not vulnerable