{"cves":[{"id":"CVE-2010-1198","published":"2010-06-24T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in Mozilla Firefox 3.5.x before 3.5.10 and\n3.6.x before 3.6.4, and SeaMonkey before 2.0.5, allows remote attackers to\nexecute arbitrary code via vectors involving multiple plugin instances.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"CVEs in Firefox are tracked in the xulrunner source packages. The\nmapping of xulrunner sources to firefox is:\nxulrunner (1.8.0): firefox (1.5) - Ubuntu 6.06 LTS\nxulrunner (1.8.1): firefox (2.0) - Ubuntu 6.10 - 8.04 LTS\nxulrunner-1.9: firefox-3.0\nxulrunner-1.9.1: firefox-3.5\nUbuntu 6.06 LTS and 10.04 LTS uses the embedded xulrunner and not\nthe system xulrunner-1.9.2, so it is tracked in the firefox source package."}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-930-1","https://ubuntu.com/security/notices/USN-930-4","https://www.cve.org/CVERecord?id=CVE-2010-1198"],"bugs":[""],"patches":{"firefox":[],"xulrunner":[],"xulrunner-1.9":[],"xulrunner-1.9.1":[],"xulrunner-1.9.2":[],"seamonkey":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.6.6+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"3.6.7+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"3.6.7+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"3.6.7+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.0.6+build1+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.0.6+build1+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"2.0.6+build1+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"2.0.6+build1+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.5","component":null,"pocket":"security"}]},{"name":"xulrunner","source":"https://ubuntu.com/security/cve?package=xulrunner","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner","debian":"https://tracker.debian.org/pkg/xulrunner","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9","debian":"https://tracker.debian.org/pkg/xulrunner-1.9","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.1","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.1","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.1","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.2","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.2","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.2","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.9.2.6+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.9.2.7+build2+nobinonly-0ubuntu0.9.04.2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.9.2.7+build2+nobinonly-0ubuntu0.9.10.2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.9.2.6+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"1.9.2.7+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"1.9.2.7+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-930-4","USN-930-1"],"notices":[{"id":"USN-930-4","title":"Firefox and Xulrunner vulnerabilities","summary":"Firefox could be made to run programs as your login if it opened a\nspecially crafted file or website.\n","instructions":"Mozilla has changed the support model for Firefox and they no longer\nsupport version 3.0 of the browser and will only support version 3.5 of the\nbrowser for a while longer. As a result, Ubuntu is providing an upgrade to\nFirefox 3.6 for Ubuntu 9.04 and 9.10 users, which is the most current\nstable release of Firefox supported by Mozilla. When upgrading, users\nshould be aware of the following:\n\n- Firefox 3.6 does not support version 5 of the Sun Java plugin. Please use\n icedtea6-plugin or sun-java6-plugin instead.\n- After upgrading to Firefox 3.6.6, users may be prompted to upgrade 3rd\n party Add-Ons. In some cases, an Add-On will not be compatible with\n Firefox 3.6.6 and have no update available. In these cases, Firefox will\n notify the user that it is disabling the Add-On.\n- Font configuration cannot be controlled via Gnome settings. This is a\n known issue being tracked in https://launchpad.net/bugs/559149 and will\n be fixed in a later update.\n- helix-player is not currently supported in Firefox 3.6. This is a known\n issue and may be fixed in a future update.\n- Plugins using external helpers (such as Totem) may not close when using\n the Epiphany browser. This is a known issue being tracked in\n https://launchpad.net/bugs/599796 and will be fixed in a later update.\n This issue only affects Ubuntu 9.04.\n- The OpenJDK java plugin is not available in Ubuntu 9.04 on Sparc\n hardware. This will be fixed in a future update.\n\nAfter a standard system upgrade you need to restart Firefox and any\napplications that use Xulrunner to effect the necessary changes.\n","references":[],"published":"2010-07-23T09:48:19.360663","description":"USN-930-1 fixed vulnerabilities in Firefox and Xulrunner. This update\nprovides the corresponding updates for Ubuntu 9.04 and 9.10, along with\nadditional updates affecting Firefox 3.6.6.\n\nSeveral flaws were discovered in the browser engine of Firefox. If a user\nwere tricked into viewing a malicious site, a remote attacker could use\nthis to crash the browser or possibly run arbitrary code as the user\ninvoking the program. (CVE-2010-1208, CVE-2010-1209, CVE-2010-1211,\nCVE-2010-1212)\n\nAn integer overflow was discovered in how Firefox processed plugin\nparameters. An attacker could exploit this to crash the browser or possibly\nrun arbitrary code as the user invoking the program. (CVE-2010-1214)\n\nA flaw was discovered in the Firefox JavaScript engine. If a user were\ntricked into viewing a malicious site, a remote attacker code execute\narbitrary JavaScript with chrome privileges. (CVE-2010-1215)\n\nAn integer overflow was discovered in how Firefox processed CSS values. An\nattacker could exploit this to crash the browser or possibly run arbitrary\ncode as the user invoking the program. (CVE-2010-2752)\n\nAn integer overflow was discovered in how Firefox interpreted the XUL\n element. If a user were tricked into viewing a malicious site, a\nremote attacker could use this to crash the browser or possibly run\narbitrary code as the user invoking the program. (CVE-2010-2753)\n\nAki Helin discovered that libpng did not properly handle certain malformed\nPNG images. If a user were tricked into opening a crafted PNG file, an\nattacker could cause a denial of service or possibly execute arbitrary code\nwith the privileges of the user invoking the program. (CVE-2010-1205)\n\nYosuke Hasegawa and Vladimir Vukicevic discovered that the same-origin\ncheck in Firefox could be bypassed by utilizing the importScripts Web\nWorker method. If a user were tricked into viewing a malicious website, an\nattacker could exploit this to read data from other domains.\n(CVE-2010-1213, CVE-2010-1207)\n\nO. Andersen that Firefox did not properly map undefined positions within\ncertain 8 bit encodings. An attacker could utilize this to perform\ncross-site scripting attacks. (CVE-2010-1210)\n\nMichal Zalewski discovered flaws in how Firefox processed the HTTP 204 (no\ncontent) code. An attacker could exploit this to spoof the location bar,\nsuch as in a phishing attack. (CVE-2010-1206)\n\nJordi Chancel discovered that Firefox did not properly handle when a server\nresponds to an HTTPS request with plaintext and then processes JavaScript\nhistory events. An attacker could exploit this to spoof the location bar,\nsuch as in a phishing attack. (CVE-2010-2751)\n\nChris Evans discovered that Firefox did not properly process improper CSS\nselectors. If a user were tricked into viewing a malicious website, an\nattacker could exploit this to read data from other domains.\n(CVE-2010-0654)\n\nSoroush Dalili discovered that Firefox did not properly handle script error\noutput. An attacker could use this to access URL parameters from other\ndomains. (CVE-2010-2754)\n\nOriginal advisory details:\n\n If was discovered that Firefox could be made to access freed memory. If a\n user were tricked into viewing a malicious site, a remote attacker could\n cause a denial of service or possibly execute arbitrary code with the\n privileges of the user invoking the program. (CVE-2010-1121)\n \n Several flaws were discovered in the browser engine of Firefox. If a\n user were tricked into viewing a malicious site, a remote attacker could\n cause a denial of service or possibly execute arbitrary code with the\n privileges of the user invoking the program. (CVE-2010-1200, CVE-2010-1201,\n CVE-2010-1202, CVE-2010-1203)\n \n A flaw was discovered in the way plugin instances interacted. An attacker\n could potentially exploit this and use one plugin to access freed memory from a\n second plugin to execute arbitrary code with the privileges of the user\n invoking the program. (CVE-2010-1198)\n \n An integer overflow was discovered in Firefox. If a user were tricked into\n viewing a malicious site, an attacker could overflow a buffer and cause a\n denial of service or possibly execute arbitrary code with the privileges of\n the user invoking the program. (CVE-2010-1196)\n \n Martin Barbella discovered an integer overflow in an XSLT node sorting\n routine. An attacker could exploit this to overflow a buffer and cause a\n denial of service or possibly execute arbitrary code with the privileges of\n the user invoking the program. (CVE-2010-1199)\n \n Michal Zalewski discovered that the focus behavior of Firefox could be\n subverted. If a user were tricked into viewing a malicious site, a remote\n attacker could use this to capture keystrokes. (CVE-2010-1125)\n \n Ilja van Sprundel discovered that the 'Content-Disposition: attachment'\n HTTP header was ignored when 'Content-Type: multipart' was also present.\n Under certain circumstances, this could potentially lead to cross-site\n scripting attacks. (CVE-2010-1197)\n \n Amit Klein discovered that Firefox did not seed its random number generator\n often enough. An attacker could exploit this to identify and track users\n across different web sites. (CVE-2008-5913)\n","is_hidden":false,"release_packages":{"jaunty":[{"name":"firefox-3.0","version":"3.6.7+build2+nobinonly-0ubuntu0.9.04.1","description":"Safe and easy web browser from Mozilla","is_source":true},{"name":"xulrunner-1.9.2","version":"1.9.2.7+build2+nobinonly-0ubuntu0.9.04.2","description":"XUL + XPCOM application runner","is_source":true},{"name":"abrowser","version":"3.6.7+build2+nobinonly-0ubuntu0.9.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.6.7+build2+nobinonly-0ubuntu0.9.04.1"},{"name":"firefox-3.0","version":"3.6.7+build2+nobinonly-0ubuntu0.9.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.6.7+build2+nobinonly-0ubuntu0.9.04.1"},{"name":"xulrunner-1.9.2","version":"1.9.2.7+build2+nobinonly-0ubuntu0.9.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2/1.9.2.7+build2+nobinonly-0ubuntu0.9.04.2"}],"karmic":[{"name":"firefox-3.5","version":"3.6.7+build2+nobinonly-0ubuntu0.9.10.1","description":"Safe and easy web browser from Mozilla","is_source":true},{"name":"xulrunner-1.9.2","version":"1.9.2.7+build2+nobinonly-0ubuntu0.9.10.2","description":"empty transitional upgrade package for xulrunner-1.9","is_source":true},{"name":"firefox-3.5","version":"3.6.7+build2+nobinonly-0ubuntu0.9.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.5","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.5/3.6.7+build2+nobinonly-0ubuntu0.9.10.1"},{"name":"xulrunner-1.9.2","version":"1.9.2.7+build2+nobinonly-0ubuntu0.9.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2/1.9.2.7+build2+nobinonly-0ubuntu0.9.10.2"}]},"type":"USN","cves_ids":["CVE-2008-5913","CVE-2010-1121","CVE-2010-1125","CVE-2010-1196","CVE-2010-1197","CVE-2010-1198","CVE-2010-1199","CVE-2010-1200","CVE-2010-1201","CVE-2010-1202","CVE-2010-1203","CVE-2010-1208","CVE-2010-1209","CVE-2010-1211","CVE-2010-1212","CVE-2010-1214","CVE-2010-1215","CVE-2010-2752","CVE-2010-2753","CVE-2010-1205","CVE-2010-1213","CVE-2010-1207","CVE-2010-1210","CVE-2010-1206","CVE-2010-2751","CVE-2010-0654","CVE-2010-2754"]},{"id":"USN-930-1","title":"Firefox and Xulrunner vulnerabilities","summary":"Firefox could be made to run programs as your login if it opened a\nspecially crafted file or website.\n","instructions":"Mozilla has changed the support model for Firefox and they no longer\nsupport version 3.0 of the browser. As a result, Ubuntu is providing an\nupgrade to Firefox 3.6 for Ubuntu 8.04 LTS users, which is the most current\nstable release of Firefox supported by Mozilla. When upgrading, users\nshould be aware of the following:\n\n- Firefox 3.6 does not support version 5 of the Sun Java plugin. Please use\n icedtea-java7-plugin or sun-java6-plugin instead.\n- After upgrading to Firefox 3.6.6, users may be prompted to upgrade 3rd\n party Add-Ons. In some cases, an Add-On will not be compatible with\n Firefox 3.6.6 and have no update available. In these cases, Firefox will\n notify the user that it is disabling the Add-On.\n- Upgrades to Ubuntu 8.10 from Ubuntu 8.04 LTS may break the browser.\n Ubuntu 8.10 is no longer officially supported and users are required to\n upgrade to 9.04 to receive active security support and a functional browser.\n- Font configuration cannot be controlled via Gnome settings. This is a\n known issue being tracked in https://launchpad.net/bugs/559149 and will\n be fixed in a later update.\n- helix-player is not currently supported in Firefox 3.6. This is a known\n issue and may be fixed in a future update.\n- RealAudio via the totem plugin is no longer supported in Firefox 3.6 in\n Ubuntu 8.04 LTS. Affected users navigating to Real content will be\n prompted to install optional community supported packages.\n- In Ubuntu 8.04 LTS the xine plugin is non-functional. After upgrading to\n Firefox 3.6, the plugin may cause the browser to crash, while in Firefox\n 3.0 it would be silently ignored. Users are advised to uninstall\n xine-plugin and/or gxineplugin.\n- Plugins using external helpers (such as Totem) may not close when using\n the Epiphany browser. This is a known issue being tracked in\n https://launchpad.net/bugs/599796 and will be fixed in a later update.\n This issue only affects Ubuntu 8.04 LTS.\n\nAfter a standard system upgrade you need to restart Firefox and any\napplications that use Xulrunner to effect the necessary changes.\n","references":[],"published":"2010-06-29T20:41:25.775109","description":"If was discovered that Firefox could be made to access freed memory. If a\nuser were tricked into viewing a malicious site, a remote attacker could\ncause a denial of service or possibly execute arbitrary code with the\nprivileges of the user invoking the program. This issue only affected\nUbuntu 8.04 LTS. (CVE-2010-1121)\n\nSeveral flaws were discovered in the browser engine of Firefox. If a\nuser were tricked into viewing a malicious site, a remote attacker could\ncause a denial of service or possibly execute arbitrary code with the\nprivileges of the user invoking the program. (CVE-2010-1200, CVE-2010-1201,\nCVE-2010-1202, CVE-2010-1203)\n\nA flaw was discovered in the way plugin instances interacted. An attacker\ncould potentially exploit this and use one plugin to access freed memory from a\nsecond plugin to execute arbitrary code with the privileges of the user\ninvoking the program. (CVE-2010-1198)\n\nAn integer overflow was discovered in Firefox. If a user were tricked into\nviewing a malicious site, an attacker could overflow a buffer and cause a\ndenial of service or possibly execute arbitrary code with the privileges of\nthe user invoking the program. (CVE-2010-1196)\n\nMartin Barbella discovered an integer overflow in an XSLT node sorting\nroutine. An attacker could exploit this to overflow a buffer and cause a\ndenial of service or possibly execute arbitrary code with the privileges of\nthe user invoking the program. (CVE-2010-1199)\n\nMichal Zalewski discovered that the focus behavior of Firefox could be\nsubverted. If a user were tricked into viewing a malicious site, a remote\nattacker could use this to capture keystrokes. (CVE-2010-1125)\n\nIlja van Sprundel discovered that the 'Content-Disposition: attachment'\nHTTP header was ignored when 'Content-Type: multipart' was also present.\nUnder certain circumstances, this could potentially lead to cross-site\nscripting attacks. (CVE-2010-1197)\n\nAmit Klein discovered that Firefox did not seed its random number generator\noften enough. An attacker could exploit this to identify and track users\nacross different web sites. (CVE-2008-5913)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"firefox-3.0","version":"3.6.6+nobinonly-0ubuntu0.8.04.1","description":"Safe and easy web browser from Mozilla","is_source":true},{"name":"xulrunner-1.9.2","version":"1.9.2.6+nobinonly-0ubuntu0.8.04.1","description":"XUL + XPCOM application runner","is_source":true},{"name":"firefox","version":"3.6.6+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.6.6+nobinonly-0ubuntu0.8.04.1"},{"name":"xulrunner-1.9.2","version":"1.9.2.6+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2/1.9.2.6+nobinonly-0ubuntu0.8.04.1"}],"lucid":[{"name":"firefox","version":"3.6.6+nobinonly-0ubuntu0.10.04.1","description":"Safe and easy web browser from Mozilla","is_source":true},{"name":"xulrunner-1.9.2","version":"1.9.2.6+nobinonly-0ubuntu0.10.04.1","description":"XUL + XPCOM application runner","is_source":true},{"name":"abrowser","version":"3.6.6+nobinonly-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/3.6.6+nobinonly-0ubuntu0.10.04.1"},{"name":"firefox","version":"3.6.6+nobinonly-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/3.6.6+nobinonly-0ubuntu0.10.04.1"},{"name":"xulrunner-1.9.2","version":"1.9.2.6+nobinonly-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2/1.9.2.6+nobinonly-0ubuntu0.10.04.1"}]},"type":"USN","cves_ids":["CVE-2010-1121","CVE-2010-1200","CVE-2010-1201","CVE-2010-1202","CVE-2010-1203","CVE-2010-1198","CVE-2010-1196","CVE-2010-1199","CVE-2010-1125","CVE-2010-1197","CVE-2008-5913"]}]},{"id":"CVE-2010-1197","published":"2010-06-24T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey\nbefore 2.0.5, does not properly handle situations in which both\n\"Content-Disposition: attachment\" and \"Content-Type: multipart\" are present\nin HTTP headers, which allows remote attackers to conduct cross-site\nscripting (XSS) attacks via an uploaded HTML document.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"CVEs in Firefox are tracked in the xulrunner source packages. The\nmapping of xulrunner sources to firefox is:\nxulrunner (1.8.0): firefox (1.5) - Ubuntu 6.06 LTS\nxulrunner (1.8.1): firefox (2.0) - Ubuntu 6.10 - 8.04 LTS\nxulrunner-1.9: firefox-3.0\nxulrunner-1.9.1: firefox-3.5\nUbuntu 6.06 LTS and 10.04 LTS uses the embedded xulrunner and not\nthe system xulrunner-1.9.2, so it is tracked in the firefox source package."}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-930-1","https://ubuntu.com/security/notices/USN-930-4","https://www.cve.org/CVERecord?id=CVE-2010-1197"],"bugs":[""],"patches":{"firefox":[],"xulrunner":[],"xulrunner-1.9":[],"xulrunner-1.9.1":[],"xulrunner-1.9.2":[],"seamonkey":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.6.6+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"3.6.7+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"3.6.7+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"3.6.7+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.0.6+build1+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.0.6+build1+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"2.0.6+build1+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"2.0.6+build1+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.5","component":null,"pocket":"security"}]},{"name":"xulrunner","source":"https://ubuntu.com/security/cve?package=xulrunner","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner","debian":"https://tracker.debian.org/pkg/xulrunner","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9","debian":"https://tracker.debian.org/pkg/xulrunner-1.9","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.1","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.1","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.1","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.2","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.2","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.2","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.9.2.6+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.9.2.7+build2+nobinonly-0ubuntu0.9.04.2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.9.2.7+build2+nobinonly-0ubuntu0.9.10.2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.9.2.6+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"1.9.2.7+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"1.9.2.7+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-930-4","USN-930-1"],"notices":[{"id":"USN-930-4","title":"Firefox and Xulrunner vulnerabilities","summary":"Firefox could be made to run programs as your login if it opened a\nspecially crafted file or website.\n","instructions":"Mozilla has changed the support model for Firefox and they no longer\nsupport version 3.0 of the browser and will only support version 3.5 of the\nbrowser for a while longer. As a result, Ubuntu is providing an upgrade to\nFirefox 3.6 for Ubuntu 9.04 and 9.10 users, which is the most current\nstable release of Firefox supported by Mozilla. When upgrading, users\nshould be aware of the following:\n\n- Firefox 3.6 does not support version 5 of the Sun Java plugin. Please use\n icedtea6-plugin or sun-java6-plugin instead.\n- After upgrading to Firefox 3.6.6, users may be prompted to upgrade 3rd\n party Add-Ons. In some cases, an Add-On will not be compatible with\n Firefox 3.6.6 and have no update available. In these cases, Firefox will\n notify the user that it is disabling the Add-On.\n- Font configuration cannot be controlled via Gnome settings. This is a\n known issue being tracked in https://launchpad.net/bugs/559149 and will\n be fixed in a later update.\n- helix-player is not currently supported in Firefox 3.6. This is a known\n issue and may be fixed in a future update.\n- Plugins using external helpers (such as Totem) may not close when using\n the Epiphany browser. This is a known issue being tracked in\n https://launchpad.net/bugs/599796 and will be fixed in a later update.\n This issue only affects Ubuntu 9.04.\n- The OpenJDK java plugin is not available in Ubuntu 9.04 on Sparc\n hardware. This will be fixed in a future update.\n\nAfter a standard system upgrade you need to restart Firefox and any\napplications that use Xulrunner to effect the necessary changes.\n","references":[],"published":"2010-07-23T09:48:19.360663","description":"USN-930-1 fixed vulnerabilities in Firefox and Xulrunner. This update\nprovides the corresponding updates for Ubuntu 9.04 and 9.10, along with\nadditional updates affecting Firefox 3.6.6.\n\nSeveral flaws were discovered in the browser engine of Firefox. If a user\nwere tricked into viewing a malicious site, a remote attacker could use\nthis to crash the browser or possibly run arbitrary code as the user\ninvoking the program. (CVE-2010-1208, CVE-2010-1209, CVE-2010-1211,\nCVE-2010-1212)\n\nAn integer overflow was discovered in how Firefox processed plugin\nparameters. An attacker could exploit this to crash the browser or possibly\nrun arbitrary code as the user invoking the program. (CVE-2010-1214)\n\nA flaw was discovered in the Firefox JavaScript engine. If a user were\ntricked into viewing a malicious site, a remote attacker code execute\narbitrary JavaScript with chrome privileges. (CVE-2010-1215)\n\nAn integer overflow was discovered in how Firefox processed CSS values. An\nattacker could exploit this to crash the browser or possibly run arbitrary\ncode as the user invoking the program. (CVE-2010-2752)\n\nAn integer overflow was discovered in how Firefox interpreted the XUL\n element. If a user were tricked into viewing a malicious site, a\nremote attacker could use this to crash the browser or possibly run\narbitrary code as the user invoking the program. (CVE-2010-2753)\n\nAki Helin discovered that libpng did not properly handle certain malformed\nPNG images. If a user were tricked into opening a crafted PNG file, an\nattacker could cause a denial of service or possibly execute arbitrary code\nwith the privileges of the user invoking the program. (CVE-2010-1205)\n\nYosuke Hasegawa and Vladimir Vukicevic discovered that the same-origin\ncheck in Firefox could be bypassed by utilizing the importScripts Web\nWorker method. If a user were tricked into viewing a malicious website, an\nattacker could exploit this to read data from other domains.\n(CVE-2010-1213, CVE-2010-1207)\n\nO. Andersen that Firefox did not properly map undefined positions within\ncertain 8 bit encodings. An attacker could utilize this to perform\ncross-site scripting attacks. (CVE-2010-1210)\n\nMichal Zalewski discovered flaws in how Firefox processed the HTTP 204 (no\ncontent) code. An attacker could exploit this to spoof the location bar,\nsuch as in a phishing attack. (CVE-2010-1206)\n\nJordi Chancel discovered that Firefox did not properly handle when a server\nresponds to an HTTPS request with plaintext and then processes JavaScript\nhistory events. An attacker could exploit this to spoof the location bar,\nsuch as in a phishing attack. (CVE-2010-2751)\n\nChris Evans discovered that Firefox did not properly process improper CSS\nselectors. If a user were tricked into viewing a malicious website, an\nattacker could exploit this to read data from other domains.\n(CVE-2010-0654)\n\nSoroush Dalili discovered that Firefox did not properly handle script error\noutput. An attacker could use this to access URL parameters from other\ndomains. (CVE-2010-2754)\n\nOriginal advisory details:\n\n If was discovered that Firefox could be made to access freed memory. If a\n user were tricked into viewing a malicious site, a remote attacker could\n cause a denial of service or possibly execute arbitrary code with the\n privileges of the user invoking the program. (CVE-2010-1121)\n \n Several flaws were discovered in the browser engine of Firefox. If a\n user were tricked into viewing a malicious site, a remote attacker could\n cause a denial of service or possibly execute arbitrary code with the\n privileges of the user invoking the program. (CVE-2010-1200, CVE-2010-1201,\n CVE-2010-1202, CVE-2010-1203)\n \n A flaw was discovered in the way plugin instances interacted. An attacker\n could potentially exploit this and use one plugin to access freed memory from a\n second plugin to execute arbitrary code with the privileges of the user\n invoking the program. (CVE-2010-1198)\n \n An integer overflow was discovered in Firefox. If a user were tricked into\n viewing a malicious site, an attacker could overflow a buffer and cause a\n denial of service or possibly execute arbitrary code with the privileges of\n the user invoking the program. (CVE-2010-1196)\n \n Martin Barbella discovered an integer overflow in an XSLT node sorting\n routine. An attacker could exploit this to overflow a buffer and cause a\n denial of service or possibly execute arbitrary code with the privileges of\n the user invoking the program. (CVE-2010-1199)\n \n Michal Zalewski discovered that the focus behavior of Firefox could be\n subverted. If a user were tricked into viewing a malicious site, a remote\n attacker could use this to capture keystrokes. (CVE-2010-1125)\n \n Ilja van Sprundel discovered that the 'Content-Disposition: attachment'\n HTTP header was ignored when 'Content-Type: multipart' was also present.\n Under certain circumstances, this could potentially lead to cross-site\n scripting attacks. (CVE-2010-1197)\n \n Amit Klein discovered that Firefox did not seed its random number generator\n often enough. An attacker could exploit this to identify and track users\n across different web sites. (CVE-2008-5913)\n","is_hidden":false,"release_packages":{"jaunty":[{"name":"firefox-3.0","version":"3.6.7+build2+nobinonly-0ubuntu0.9.04.1","description":"Safe and easy web browser from Mozilla","is_source":true},{"name":"xulrunner-1.9.2","version":"1.9.2.7+build2+nobinonly-0ubuntu0.9.04.2","description":"XUL + XPCOM application runner","is_source":true},{"name":"abrowser","version":"3.6.7+build2+nobinonly-0ubuntu0.9.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.6.7+build2+nobinonly-0ubuntu0.9.04.1"},{"name":"firefox-3.0","version":"3.6.7+build2+nobinonly-0ubuntu0.9.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.6.7+build2+nobinonly-0ubuntu0.9.04.1"},{"name":"xulrunner-1.9.2","version":"1.9.2.7+build2+nobinonly-0ubuntu0.9.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2/1.9.2.7+build2+nobinonly-0ubuntu0.9.04.2"}],"karmic":[{"name":"firefox-3.5","version":"3.6.7+build2+nobinonly-0ubuntu0.9.10.1","description":"Safe and easy web browser from Mozilla","is_source":true},{"name":"xulrunner-1.9.2","version":"1.9.2.7+build2+nobinonly-0ubuntu0.9.10.2","description":"empty transitional upgrade package for xulrunner-1.9","is_source":true},{"name":"firefox-3.5","version":"3.6.7+build2+nobinonly-0ubuntu0.9.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.5","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.5/3.6.7+build2+nobinonly-0ubuntu0.9.10.1"},{"name":"xulrunner-1.9.2","version":"1.9.2.7+build2+nobinonly-0ubuntu0.9.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2/1.9.2.7+build2+nobinonly-0ubuntu0.9.10.2"}]},"type":"USN","cves_ids":["CVE-2008-5913","CVE-2010-1121","CVE-2010-1125","CVE-2010-1196","CVE-2010-1197","CVE-2010-1198","CVE-2010-1199","CVE-2010-1200","CVE-2010-1201","CVE-2010-1202","CVE-2010-1203","CVE-2010-1208","CVE-2010-1209","CVE-2010-1211","CVE-2010-1212","CVE-2010-1214","CVE-2010-1215","CVE-2010-2752","CVE-2010-2753","CVE-2010-1205","CVE-2010-1213","CVE-2010-1207","CVE-2010-1210","CVE-2010-1206","CVE-2010-2751","CVE-2010-0654","CVE-2010-2754"]},{"id":"USN-930-1","title":"Firefox and Xulrunner vulnerabilities","summary":"Firefox could be made to run programs as your login if it opened a\nspecially crafted file or website.\n","instructions":"Mozilla has changed the support model for Firefox and they no longer\nsupport version 3.0 of the browser. As a result, Ubuntu is providing an\nupgrade to Firefox 3.6 for Ubuntu 8.04 LTS users, which is the most current\nstable release of Firefox supported by Mozilla. When upgrading, users\nshould be aware of the following:\n\n- Firefox 3.6 does not support version 5 of the Sun Java plugin. Please use\n icedtea-java7-plugin or sun-java6-plugin instead.\n- After upgrading to Firefox 3.6.6, users may be prompted to upgrade 3rd\n party Add-Ons. In some cases, an Add-On will not be compatible with\n Firefox 3.6.6 and have no update available. In these cases, Firefox will\n notify the user that it is disabling the Add-On.\n- Upgrades to Ubuntu 8.10 from Ubuntu 8.04 LTS may break the browser.\n Ubuntu 8.10 is no longer officially supported and users are required to\n upgrade to 9.04 to receive active security support and a functional browser.\n- Font configuration cannot be controlled via Gnome settings. This is a\n known issue being tracked in https://launchpad.net/bugs/559149 and will\n be fixed in a later update.\n- helix-player is not currently supported in Firefox 3.6. This is a known\n issue and may be fixed in a future update.\n- RealAudio via the totem plugin is no longer supported in Firefox 3.6 in\n Ubuntu 8.04 LTS. Affected users navigating to Real content will be\n prompted to install optional community supported packages.\n- In Ubuntu 8.04 LTS the xine plugin is non-functional. After upgrading to\n Firefox 3.6, the plugin may cause the browser to crash, while in Firefox\n 3.0 it would be silently ignored. Users are advised to uninstall\n xine-plugin and/or gxineplugin.\n- Plugins using external helpers (such as Totem) may not close when using\n the Epiphany browser. This is a known issue being tracked in\n https://launchpad.net/bugs/599796 and will be fixed in a later update.\n This issue only affects Ubuntu 8.04 LTS.\n\nAfter a standard system upgrade you need to restart Firefox and any\napplications that use Xulrunner to effect the necessary changes.\n","references":[],"published":"2010-06-29T20:41:25.775109","description":"If was discovered that Firefox could be made to access freed memory. If a\nuser were tricked into viewing a malicious site, a remote attacker could\ncause a denial of service or possibly execute arbitrary code with the\nprivileges of the user invoking the program. This issue only affected\nUbuntu 8.04 LTS. (CVE-2010-1121)\n\nSeveral flaws were discovered in the browser engine of Firefox. If a\nuser were tricked into viewing a malicious site, a remote attacker could\ncause a denial of service or possibly execute arbitrary code with the\nprivileges of the user invoking the program. (CVE-2010-1200, CVE-2010-1201,\nCVE-2010-1202, CVE-2010-1203)\n\nA flaw was discovered in the way plugin instances interacted. An attacker\ncould potentially exploit this and use one plugin to access freed memory from a\nsecond plugin to execute arbitrary code with the privileges of the user\ninvoking the program. (CVE-2010-1198)\n\nAn integer overflow was discovered in Firefox. If a user were tricked into\nviewing a malicious site, an attacker could overflow a buffer and cause a\ndenial of service or possibly execute arbitrary code with the privileges of\nthe user invoking the program. (CVE-2010-1196)\n\nMartin Barbella discovered an integer overflow in an XSLT node sorting\nroutine. An attacker could exploit this to overflow a buffer and cause a\ndenial of service or possibly execute arbitrary code with the privileges of\nthe user invoking the program. (CVE-2010-1199)\n\nMichal Zalewski discovered that the focus behavior of Firefox could be\nsubverted. If a user were tricked into viewing a malicious site, a remote\nattacker could use this to capture keystrokes. (CVE-2010-1125)\n\nIlja van Sprundel discovered that the 'Content-Disposition: attachment'\nHTTP header was ignored when 'Content-Type: multipart' was also present.\nUnder certain circumstances, this could potentially lead to cross-site\nscripting attacks. (CVE-2010-1197)\n\nAmit Klein discovered that Firefox did not seed its random number generator\noften enough. An attacker could exploit this to identify and track users\nacross different web sites. (CVE-2008-5913)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"firefox-3.0","version":"3.6.6+nobinonly-0ubuntu0.8.04.1","description":"Safe and easy web browser from Mozilla","is_source":true},{"name":"xulrunner-1.9.2","version":"1.9.2.6+nobinonly-0ubuntu0.8.04.1","description":"XUL + XPCOM application runner","is_source":true},{"name":"firefox","version":"3.6.6+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.6.6+nobinonly-0ubuntu0.8.04.1"},{"name":"xulrunner-1.9.2","version":"1.9.2.6+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2/1.9.2.6+nobinonly-0ubuntu0.8.04.1"}],"lucid":[{"name":"firefox","version":"3.6.6+nobinonly-0ubuntu0.10.04.1","description":"Safe and easy web browser from Mozilla","is_source":true},{"name":"xulrunner-1.9.2","version":"1.9.2.6+nobinonly-0ubuntu0.10.04.1","description":"XUL + XPCOM application runner","is_source":true},{"name":"abrowser","version":"3.6.6+nobinonly-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/3.6.6+nobinonly-0ubuntu0.10.04.1"},{"name":"firefox","version":"3.6.6+nobinonly-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/3.6.6+nobinonly-0ubuntu0.10.04.1"},{"name":"xulrunner-1.9.2","version":"1.9.2.6+nobinonly-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2/1.9.2.6+nobinonly-0ubuntu0.10.04.1"}]},"type":"USN","cves_ids":["CVE-2010-1121","CVE-2010-1200","CVE-2010-1201","CVE-2010-1202","CVE-2010-1203","CVE-2010-1198","CVE-2010-1196","CVE-2010-1199","CVE-2010-1125","CVE-2010-1197","CVE-2008-5913"]}]},{"id":"CVE-2010-1196","published":"2010-06-24T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nInteger overflow in the nsGenericDOMDataNode::SetTextInternal function in\nMozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird\nbefore 3.0.5, and SeaMonkey before 2.0.5 allows remote attackers to execute\narbitrary code via a DOM node with a long text value that triggers a\nheap-based buffer overflow.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"CVEs in Firefox are tracked in the xulrunner source packages. The\nmapping of xulrunner sources to firefox is:\nxulrunner (1.8.0): firefox (1.5) - Ubuntu 6.06 LTS\nxulrunner (1.8.1): firefox (2.0) - Ubuntu 6.10 - 8.04 LTS\nxulrunner-1.9: firefox-3.0\nxulrunner-1.9.1: firefox-3.5\nUbuntu 6.06 LTS and 10.04 LTS uses the embedded xulrunner and not\nthe system xulrunner-1.9.2, so it is tracked in the firefox source package.\nper Chris Coulson, tbird requires javascript to be enabled"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-930-1","https://ubuntu.com/security/notices/USN-943-1","https://ubuntu.com/security/notices/USN-930-4","https://www.cve.org/CVERecord?id=CVE-2010-1196"],"bugs":[""],"patches":{"firefox":[],"xulrunner":[],"xulrunner-1.9":[],"xulrunner-1.9.1":[],"xulrunner-1.9.2":[],"seamonkey":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.6.6+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"3.6.7+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"3.6.7+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"3.6.7+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.0.6+build1+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.0.6+build1+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"2.0.6+build1+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"2.0.6+build1+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.0.5+build2+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"3.0.5+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"3.0.5+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"3.0.5+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.0.5","component":null,"pocket":"security"}]},{"name":"xulrunner","source":"https://ubuntu.com/security/cve?package=xulrunner","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner","debian":"https://tracker.debian.org/pkg/xulrunner","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9","debian":"https://tracker.debian.org/pkg/xulrunner-1.9","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.1","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.1","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.1","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.2","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.2","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.2","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.9.2.6+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.9.2.7+build2+nobinonly-0ubuntu0.9.04.2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.9.2.7+build2+nobinonly-0ubuntu0.9.10.2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.9.2.6+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"1.9.2.7+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"1.9.2.7+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-943-1","USN-930-4","USN-930-1"],"notices":[{"id":"USN-943-1","title":"Thunderbird vulnerabilities","summary":"","instructions":"After a standard system update you need to restart Thunderbird to make\nall the necessary changes.\n","references":[],"published":"2010-07-06T13:01:19.099945","description":"Martin Barbella discovered an integer overflow in an XSLT node sorting\nroutine. An attacker could exploit this to overflow a buffer and cause a\ndenial of service or possibly execute arbitrary code with the privileges of\nthe user invoking the program. (CVE-2010-1199)\n\nAn integer overflow was discovered in Thunderbird. If a user were tricked\ninto viewing malicious content, an attacker could overflow a buffer and\ncause a denial of service or possibly execute arbitrary code with the\nprivileges of the user invoking the program. (CVE-2010-1196)\n\nSeveral flaws were discovered in the browser engine of Thunderbird. If a\nuser were tricked into viewing a malicious site, a remote attacker could\ncause a denial of service or possibly execute arbitrary code with the\nprivileges of the user invoking the program. (CVE-2010-1200, CVE-2010-1201,\nCVE-2010-1202, CVE-2010-1203)\n\nIf was discovered that Thunderbird could be made to access freed memory. If\na user were tricked into viewing a malicious site, a remote attacker could\ncause a denial of service or possibly execute arbitrary code with the\nprivileges of the user invoking the program. (CVE-2010-1121)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"thunderbird","version":"3.0.5+build2+nobinonly-0ubuntu0.10.04.1","description":"","is_source":true},{"name":"thunderbird","version":"3.0.5+build2+nobinonly-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/3.0.5+build2+nobinonly-0ubuntu0.10.04.1"}]},"type":"USN","cves_ids":["CVE-2010-1199","CVE-2010-1196","CVE-2010-1200","CVE-2010-1201","CVE-2010-1202","CVE-2010-1203","CVE-2010-1121"]},{"id":"USN-930-4","title":"Firefox and Xulrunner vulnerabilities","summary":"Firefox could be made to run programs as your login if it opened a\nspecially crafted file or website.\n","instructions":"Mozilla has changed the support model for Firefox and they no longer\nsupport version 3.0 of the browser and will only support version 3.5 of the\nbrowser for a while longer. As a result, Ubuntu is providing an upgrade to\nFirefox 3.6 for Ubuntu 9.04 and 9.10 users, which is the most current\nstable release of Firefox supported by Mozilla. When upgrading, users\nshould be aware of the following:\n\n- Firefox 3.6 does not support version 5 of the Sun Java plugin. Please use\n icedtea6-plugin or sun-java6-plugin instead.\n- After upgrading to Firefox 3.6.6, users may be prompted to upgrade 3rd\n party Add-Ons. In some cases, an Add-On will not be compatible with\n Firefox 3.6.6 and have no update available. In these cases, Firefox will\n notify the user that it is disabling the Add-On.\n- Font configuration cannot be controlled via Gnome settings. This is a\n known issue being tracked in https://launchpad.net/bugs/559149 and will\n be fixed in a later update.\n- helix-player is not currently supported in Firefox 3.6. This is a known\n issue and may be fixed in a future update.\n- Plugins using external helpers (such as Totem) may not close when using\n the Epiphany browser. This is a known issue being tracked in\n https://launchpad.net/bugs/599796 and will be fixed in a later update.\n This issue only affects Ubuntu 9.04.\n- The OpenJDK java plugin is not available in Ubuntu 9.04 on Sparc\n hardware. This will be fixed in a future update.\n\nAfter a standard system upgrade you need to restart Firefox and any\napplications that use Xulrunner to effect the necessary changes.\n","references":[],"published":"2010-07-23T09:48:19.360663","description":"USN-930-1 fixed vulnerabilities in Firefox and Xulrunner. This update\nprovides the corresponding updates for Ubuntu 9.04 and 9.10, along with\nadditional updates affecting Firefox 3.6.6.\n\nSeveral flaws were discovered in the browser engine of Firefox. If a user\nwere tricked into viewing a malicious site, a remote attacker could use\nthis to crash the browser or possibly run arbitrary code as the user\ninvoking the program. (CVE-2010-1208, CVE-2010-1209, CVE-2010-1211,\nCVE-2010-1212)\n\nAn integer overflow was discovered in how Firefox processed plugin\nparameters. An attacker could exploit this to crash the browser or possibly\nrun arbitrary code as the user invoking the program. (CVE-2010-1214)\n\nA flaw was discovered in the Firefox JavaScript engine. If a user were\ntricked into viewing a malicious site, a remote attacker code execute\narbitrary JavaScript with chrome privileges. (CVE-2010-1215)\n\nAn integer overflow was discovered in how Firefox processed CSS values. An\nattacker could exploit this to crash the browser or possibly run arbitrary\ncode as the user invoking the program. (CVE-2010-2752)\n\nAn integer overflow was discovered in how Firefox interpreted the XUL\n element. If a user were tricked into viewing a malicious site, a\nremote attacker could use this to crash the browser or possibly run\narbitrary code as the user invoking the program. (CVE-2010-2753)\n\nAki Helin discovered that libpng did not properly handle certain malformed\nPNG images. If a user were tricked into opening a crafted PNG file, an\nattacker could cause a denial of service or possibly execute arbitrary code\nwith the privileges of the user invoking the program. (CVE-2010-1205)\n\nYosuke Hasegawa and Vladimir Vukicevic discovered that the same-origin\ncheck in Firefox could be bypassed by utilizing the importScripts Web\nWorker method. If a user were tricked into viewing a malicious website, an\nattacker could exploit this to read data from other domains.\n(CVE-2010-1213, CVE-2010-1207)\n\nO. Andersen that Firefox did not properly map undefined positions within\ncertain 8 bit encodings. An attacker could utilize this to perform\ncross-site scripting attacks. (CVE-2010-1210)\n\nMichal Zalewski discovered flaws in how Firefox processed the HTTP 204 (no\ncontent) code. An attacker could exploit this to spoof the location bar,\nsuch as in a phishing attack. (CVE-2010-1206)\n\nJordi Chancel discovered that Firefox did not properly handle when a server\nresponds to an HTTPS request with plaintext and then processes JavaScript\nhistory events. An attacker could exploit this to spoof the location bar,\nsuch as in a phishing attack. (CVE-2010-2751)\n\nChris Evans discovered that Firefox did not properly process improper CSS\nselectors. If a user were tricked into viewing a malicious website, an\nattacker could exploit this to read data from other domains.\n(CVE-2010-0654)\n\nSoroush Dalili discovered that Firefox did not properly handle script error\noutput. An attacker could use this to access URL parameters from other\ndomains. (CVE-2010-2754)\n\nOriginal advisory details:\n\n If was discovered that Firefox could be made to access freed memory. If a\n user were tricked into viewing a malicious site, a remote attacker could\n cause a denial of service or possibly execute arbitrary code with the\n privileges of the user invoking the program. (CVE-2010-1121)\n \n Several flaws were discovered in the browser engine of Firefox. If a\n user were tricked into viewing a malicious site, a remote attacker could\n cause a denial of service or possibly execute arbitrary code with the\n privileges of the user invoking the program. (CVE-2010-1200, CVE-2010-1201,\n CVE-2010-1202, CVE-2010-1203)\n \n A flaw was discovered in the way plugin instances interacted. An attacker\n could potentially exploit this and use one plugin to access freed memory from a\n second plugin to execute arbitrary code with the privileges of the user\n invoking the program. (CVE-2010-1198)\n \n An integer overflow was discovered in Firefox. If a user were tricked into\n viewing a malicious site, an attacker could overflow a buffer and cause a\n denial of service or possibly execute arbitrary code with the privileges of\n the user invoking the program. (CVE-2010-1196)\n \n Martin Barbella discovered an integer overflow in an XSLT node sorting\n routine. An attacker could exploit this to overflow a buffer and cause a\n denial of service or possibly execute arbitrary code with the privileges of\n the user invoking the program. (CVE-2010-1199)\n \n Michal Zalewski discovered that the focus behavior of Firefox could be\n subverted. If a user were tricked into viewing a malicious site, a remote\n attacker could use this to capture keystrokes. (CVE-2010-1125)\n \n Ilja van Sprundel discovered that the 'Content-Disposition: attachment'\n HTTP header was ignored when 'Content-Type: multipart' was also present.\n Under certain circumstances, this could potentially lead to cross-site\n scripting attacks. (CVE-2010-1197)\n \n Amit Klein discovered that Firefox did not seed its random number generator\n often enough. An attacker could exploit this to identify and track users\n across different web sites. (CVE-2008-5913)\n","is_hidden":false,"release_packages":{"jaunty":[{"name":"firefox-3.0","version":"3.6.7+build2+nobinonly-0ubuntu0.9.04.1","description":"Safe and easy web browser from Mozilla","is_source":true},{"name":"xulrunner-1.9.2","version":"1.9.2.7+build2+nobinonly-0ubuntu0.9.04.2","description":"XUL + XPCOM application runner","is_source":true},{"name":"abrowser","version":"3.6.7+build2+nobinonly-0ubuntu0.9.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.6.7+build2+nobinonly-0ubuntu0.9.04.1"},{"name":"firefox-3.0","version":"3.6.7+build2+nobinonly-0ubuntu0.9.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.6.7+build2+nobinonly-0ubuntu0.9.04.1"},{"name":"xulrunner-1.9.2","version":"1.9.2.7+build2+nobinonly-0ubuntu0.9.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2/1.9.2.7+build2+nobinonly-0ubuntu0.9.04.2"}],"karmic":[{"name":"firefox-3.5","version":"3.6.7+build2+nobinonly-0ubuntu0.9.10.1","description":"Safe and easy web browser from Mozilla","is_source":true},{"name":"xulrunner-1.9.2","version":"1.9.2.7+build2+nobinonly-0ubuntu0.9.10.2","description":"empty transitional upgrade package for xulrunner-1.9","is_source":true},{"name":"firefox-3.5","version":"3.6.7+build2+nobinonly-0ubuntu0.9.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.5","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.5/3.6.7+build2+nobinonly-0ubuntu0.9.10.1"},{"name":"xulrunner-1.9.2","version":"1.9.2.7+build2+nobinonly-0ubuntu0.9.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2/1.9.2.7+build2+nobinonly-0ubuntu0.9.10.2"}]},"type":"USN","cves_ids":["CVE-2008-5913","CVE-2010-1121","CVE-2010-1125","CVE-2010-1196","CVE-2010-1197","CVE-2010-1198","CVE-2010-1199","CVE-2010-1200","CVE-2010-1201","CVE-2010-1202","CVE-2010-1203","CVE-2010-1208","CVE-2010-1209","CVE-2010-1211","CVE-2010-1212","CVE-2010-1214","CVE-2010-1215","CVE-2010-2752","CVE-2010-2753","CVE-2010-1205","CVE-2010-1213","CVE-2010-1207","CVE-2010-1210","CVE-2010-1206","CVE-2010-2751","CVE-2010-0654","CVE-2010-2754"]},{"id":"USN-930-1","title":"Firefox and Xulrunner vulnerabilities","summary":"Firefox could be made to run programs as your login if it opened a\nspecially crafted file or website.\n","instructions":"Mozilla has changed the support model for Firefox and they no longer\nsupport version 3.0 of the browser. As a result, Ubuntu is providing an\nupgrade to Firefox 3.6 for Ubuntu 8.04 LTS users, which is the most current\nstable release of Firefox supported by Mozilla. When upgrading, users\nshould be aware of the following:\n\n- Firefox 3.6 does not support version 5 of the Sun Java plugin. Please use\n icedtea-java7-plugin or sun-java6-plugin instead.\n- After upgrading to Firefox 3.6.6, users may be prompted to upgrade 3rd\n party Add-Ons. In some cases, an Add-On will not be compatible with\n Firefox 3.6.6 and have no update available. In these cases, Firefox will\n notify the user that it is disabling the Add-On.\n- Upgrades to Ubuntu 8.10 from Ubuntu 8.04 LTS may break the browser.\n Ubuntu 8.10 is no longer officially supported and users are required to\n upgrade to 9.04 to receive active security support and a functional browser.\n- Font configuration cannot be controlled via Gnome settings. This is a\n known issue being tracked in https://launchpad.net/bugs/559149 and will\n be fixed in a later update.\n- helix-player is not currently supported in Firefox 3.6. This is a known\n issue and may be fixed in a future update.\n- RealAudio via the totem plugin is no longer supported in Firefox 3.6 in\n Ubuntu 8.04 LTS. Affected users navigating to Real content will be\n prompted to install optional community supported packages.\n- In Ubuntu 8.04 LTS the xine plugin is non-functional. After upgrading to\n Firefox 3.6, the plugin may cause the browser to crash, while in Firefox\n 3.0 it would be silently ignored. Users are advised to uninstall\n xine-plugin and/or gxineplugin.\n- Plugins using external helpers (such as Totem) may not close when using\n the Epiphany browser. This is a known issue being tracked in\n https://launchpad.net/bugs/599796 and will be fixed in a later update.\n This issue only affects Ubuntu 8.04 LTS.\n\nAfter a standard system upgrade you need to restart Firefox and any\napplications that use Xulrunner to effect the necessary changes.\n","references":[],"published":"2010-06-29T20:41:25.775109","description":"If was discovered that Firefox could be made to access freed memory. If a\nuser were tricked into viewing a malicious site, a remote attacker could\ncause a denial of service or possibly execute arbitrary code with the\nprivileges of the user invoking the program. This issue only affected\nUbuntu 8.04 LTS. (CVE-2010-1121)\n\nSeveral flaws were discovered in the browser engine of Firefox. If a\nuser were tricked into viewing a malicious site, a remote attacker could\ncause a denial of service or possibly execute arbitrary code with the\nprivileges of the user invoking the program. (CVE-2010-1200, CVE-2010-1201,\nCVE-2010-1202, CVE-2010-1203)\n\nA flaw was discovered in the way plugin instances interacted. An attacker\ncould potentially exploit this and use one plugin to access freed memory from a\nsecond plugin to execute arbitrary code with the privileges of the user\ninvoking the program. (CVE-2010-1198)\n\nAn integer overflow was discovered in Firefox. If a user were tricked into\nviewing a malicious site, an attacker could overflow a buffer and cause a\ndenial of service or possibly execute arbitrary code with the privileges of\nthe user invoking the program. (CVE-2010-1196)\n\nMartin Barbella discovered an integer overflow in an XSLT node sorting\nroutine. An attacker could exploit this to overflow a buffer and cause a\ndenial of service or possibly execute arbitrary code with the privileges of\nthe user invoking the program. (CVE-2010-1199)\n\nMichal Zalewski discovered that the focus behavior of Firefox could be\nsubverted. If a user were tricked into viewing a malicious site, a remote\nattacker could use this to capture keystrokes. (CVE-2010-1125)\n\nIlja van Sprundel discovered that the 'Content-Disposition: attachment'\nHTTP header was ignored when 'Content-Type: multipart' was also present.\nUnder certain circumstances, this could potentially lead to cross-site\nscripting attacks. (CVE-2010-1197)\n\nAmit Klein discovered that Firefox did not seed its random number generator\noften enough. An attacker could exploit this to identify and track users\nacross different web sites. (CVE-2008-5913)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"firefox-3.0","version":"3.6.6+nobinonly-0ubuntu0.8.04.1","description":"Safe and easy web browser from Mozilla","is_source":true},{"name":"xulrunner-1.9.2","version":"1.9.2.6+nobinonly-0ubuntu0.8.04.1","description":"XUL + XPCOM application runner","is_source":true},{"name":"firefox","version":"3.6.6+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.6.6+nobinonly-0ubuntu0.8.04.1"},{"name":"xulrunner-1.9.2","version":"1.9.2.6+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2/1.9.2.6+nobinonly-0ubuntu0.8.04.1"}],"lucid":[{"name":"firefox","version":"3.6.6+nobinonly-0ubuntu0.10.04.1","description":"Safe and easy web browser from Mozilla","is_source":true},{"name":"xulrunner-1.9.2","version":"1.9.2.6+nobinonly-0ubuntu0.10.04.1","description":"XUL + XPCOM application runner","is_source":true},{"name":"abrowser","version":"3.6.6+nobinonly-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/3.6.6+nobinonly-0ubuntu0.10.04.1"},{"name":"firefox","version":"3.6.6+nobinonly-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/3.6.6+nobinonly-0ubuntu0.10.04.1"},{"name":"xulrunner-1.9.2","version":"1.9.2.6+nobinonly-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2/1.9.2.6+nobinonly-0ubuntu0.10.04.1"}]},"type":"USN","cves_ids":["CVE-2010-1121","CVE-2010-1200","CVE-2010-1201","CVE-2010-1202","CVE-2010-1203","CVE-2010-1198","CVE-2010-1196","CVE-2010-1199","CVE-2010-1125","CVE-2010-1197","CVE-2008-5913"]}]},{"id":"CVE-2010-2432","published":"2010-06-22T20:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe cupsDoAuthentication function in auth.c in the client in CUPS before\n1.4.4, when HAVE_GSSAPI is omitted, does not properly handle a demand for\nauthorization, which allows remote CUPS servers to cause a denial of\nservice (infinite loop) via HTTP_UNAUTHORIZED responses.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"hardy and more recent are compiled with HAVE_GSSAPI support, so\nwe're not affected by this. Dapper doesn't seem to bail out\nafter a certain number of renegotiation attempts. This may be\na problem, need to investigate."}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://cups.org/articles.php?L596","https://www.cve.org/CVERecord?id=CVE-2010-2432"],"bugs":["http://cups.org/str.php?L3518"],"patches":{"cups":[],"cupsys":[]},"tags":{},"packages":[{"name":"cups","source":"https://ubuntu.com/security/cve?package=cups","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=cups","debian":"https://tracker.debian.org/pkg/cups","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.4.4","component":null,"pocket":"security"}]},{"name":"cupsys","source":"https://ubuntu.com/security/cve?package=cupsys","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=cupsys","debian":"https://tracker.debian.org/pkg/cupsys","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.4.4","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2431","published":"2010-06-22T20:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe cupsFileOpen function in CUPS before 1.4.4 allows local users, with lp\ngroup membership, to overwrite arbitrary files via a symlink attack on the\n(1) /var/cache/cups/remote.cache or (2) /var/cache/cups/job.cache file.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-2431"],"bugs":[""],"patches":{"cups":[],"cupsys":[]},"tags":{},"packages":[{"name":"cups","source":"https://ubuntu.com/security/cve?package=cups","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=cups","debian":"https://tracker.debian.org/pkg/cups","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.3.9-17ubuntu3.9","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.4.1-5ubuntu2.6","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.4.3-1ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.4.4","component":null,"pocket":"security"}]},{"name":"cupsys","source":"https://ubuntu.com/security/cve?package=cupsys","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=cupsys","debian":"https://tracker.debian.org/pkg/cupsys","statuses":[{"release_codename":"dapper","status":"released","description":"1.2.2-0ubuntu0.6.06.19","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.3.7-1ubuntu3.11","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.4.4","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-1757","published":"2010-06-22T20:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit in Apple iOS before 4 on the iPhone and iPod touch does not enforce\nthe expected boundary restrictions on content display by an IFRAME element,\nwhich allows remote attackers to spoof the user interface via a crafted\nHTML document.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit is a fork of khtml from kdelibs. kdelibs5 is farther from\nit, while qt4-x11 attempts to unify khtml and webkit."},{"author":"mdeslaur","note":"webkitkde is a wrapper around qt4-x11's webkit.\niphone specific"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-1757"],"bugs":[""],"patches":{"webkit":[],"qt4-x11":[],"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"qt4-x11","source":"https://ubuntu.com/security/cve?package=qt4-x11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qt4-x11","debian":"https://tracker.debian.org/pkg/qt4-x11","statuses":[{"release_codename":"dapper","status":"not-affected","description":"no webkit","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"no webkit","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-1632","published":"2010-06-22T20:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nApache Axis2 before 1.5.2, as used in IBM WebSphere Application Server\n(WAS) 7.0 through 7.0.0.12, IBM Feature Pack for Web Services 6.1.0.9\nthrough 6.1.0.32, IBM Feature Pack for Web 2.0 1.0.1.0, Apache Synapse,\nApache ODE, Apache Tuscany, Apache Geronimo, and other products, does not\nproperly reject DTDs in SOAP messages, which allows remote attackers to\nread arbitrary files, send HTTP requests to intranet servers, or cause a\ndenial of service (CPU and memory consumption) via a crafted DTD, as\ndemonstrated by an entity declaration in a request to the Synapse\nSimpleStockQuoteService.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-1632"],"bugs":[""],"patches":{"axis2c":[]},"tags":{},"packages":[{"name":"axis2c","source":"https://ubuntu.com/security/cve?package=axis2c","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=axis2c","debian":"https://tracker.debian.org/pkg/axis2c","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"1.6.0-0ubuntu7","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.6.0-0ubuntu8","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.6.0-0ubuntu8","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.5.2, 1.6.0","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-1407","published":"2010-06-22T20:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit in Apple iOS before 4 on the iPhone and iPod touch does not properly\nimplement the history.replaceState method in certain situations involving\nIFRAME elements, which allows remote attackers to obtain sensitive\ninformation via a crafted HTML document.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"qt4-x11 unmaintained upstream (see README.webkit for details)\nwebkit is a fork of khtml from kdelibs. kdelibs5 is farther from\nit, while qt4-x11 attempts to unify khtml and webkit."},{"author":"mdeslaur","note":"webkitkde is a wrapper around qt4-x11's webkit."}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1006-1","https://www.cve.org/CVERecord?id=CVE-2010-1407"],"bugs":["https://bugs.webkit.org/show_bug.cgi?id=36435"],"patches":{"webkit":["upstream: http://trac.webkit.org/changeset/56365"],"qt4-x11":[],"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"qt4-x11","source":"https://ubuntu.com/security/cve?package=qt4-x11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qt4-x11","debian":"https://tracker.debian.org/pkg/qt4-x11","statuses":[{"release_codename":"dapper","status":"not-affected","description":"no webkit","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"no webkit","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.2.5-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.2.5-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.2.4-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.2.4-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.2.4-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-1637","published":"2010-06-22T17:30:00","updated_at":"2025-08-25T19:56:19.104511+00:00","description":"\nThe Mail Fetch plugin in SquirrelMail 1.4.20 and earlier allows remote\nauthenticated users to bypass firewall restrictions and use SquirrelMail as\na proxy to scan internal networks via a modified POP3 port number.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-1637"],"bugs":[""],"patches":{"squirrelmail":["debdiff: https://bugs.launchpad.net/ubuntu/+source/squirrelmail/+bug/598077"]},"tags":{},"packages":[{"name":"squirrelmail","source":"https://ubuntu.com/security/cve?package=squirrelmail","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=squirrelmail","debian":"https://tracker.debian.org/pkg/squirrelmail","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2:1.4.13-2ubuntu1.6","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2:1.4.15-4ubuntu0.4","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2:1.4.19-1ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2:1.4.20-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2350","published":"2010-06-21T19:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nHeap-based buffer overflow in the PNG decoder in Ziproxy 3.1.0 allows\nremote attackers to cause a denial of service (crash) and possibly execute\narbitrary code via a crafted PNG file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-2350"],"bugs":[""],"patches":{"ziproxy":[]},"tags":{},"packages":[{"name":"ziproxy","source":"https://ubuntu.com/security/cve?package=ziproxy","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ziproxy","debian":"https://tracker.debian.org/pkg/ziproxy","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.2.0-2","component":null,"pocket":"security"},{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.1.1-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"3.2.0-2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.2.0-2]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-1168","published":"2010-06-21T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe Safe (aka Safe.pm) module before 2.25 for Perl allows context-dependent\nattackers to bypass intended (1) Safe::reval and (2) Safe::rdo access\nrestrictions, and inject and execute arbitrary code, via vectors involving\nimplicitly called methods and implicitly blessed objects, as demonstrated\nby the (a) DESTROY and (b) AUTOLOAD methods, related to \"automagic\nmethods.\"","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"debian bug says upstream 2.27 contains regressions...should\nupdate to 2.25, but 2.25 doesn't fix CVE-2010-1447."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://blogs.perl.org/users/rafael_garcia-suarez/2010/03/new-safepm-fixes-security-hole.html","https://ubuntu.com/security/notices/USN-1129-1","https://www.cve.org/CVERecord?id=CVE-2010-1168"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=582978"],"patches":{"perl":["upstream: http://search.cpan.org/~rgarcia/Safe-2.27/Safe.pm"]},"tags":{},"packages":[{"name":"perl","source":"https://ubuntu.com/security/cve?package=perl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=perl","debian":"https://tracker.debian.org/pkg/perl","statuses":[{"release_codename":"dapper","status":"released","description":"5.8.7-10ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"5.8.8-12ubuntu0.5","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"5.10.1-8ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"5.10.1-12ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"5.10.1-17ubuntu4.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1129-1"],"notices":[{"id":"USN-1129-1","title":"Perl vulnerabilities","summary":"An attacker could send crafted input to Perl and bypass intended\nrestrictions.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2011-05-03T14:19:22.484572","description":"It was discovered that the Safe.pm Perl module incorrectly handled\nSafe::reval and Safe::rdo access restrictions. An attacker could use this\nflaw to bypass intended restrictions and possibly execute arbitrary code.\n(CVE-2010-1168, CVE-2010-1447)\n\nIt was discovered that the CGI.pm Perl module incorrectly handled certain\nMIME boundary strings. An attacker could use this flaw to inject arbitrary\nHTTP headers and perform HTTP response splitting and cross-site scripting\nattacks. This issue only affected Ubuntu 6.06 LTS, 8.04 LTS, 10.04 LTS and\n10.10. (CVE-2010-2761, CVE-2010-4411)\n\nIt was discovered that the CGI.pm Perl module incorrectly handled newline\ncharacters. An attacker could use this flaw to inject arbitrary HTTP\nheaders and perform HTTP response splitting and cross-site scripting\nattacks. This issue only affected Ubuntu 6.06 LTS, 8.04 LTS, 10.04 LTS and\n10.10. (CVE-2010-4410)\n\nIt was discovered that the lc, lcfirst, uc, and ucfirst functions did not\nproperly apply the taint attribute when processing tainted input. An\nattacker could use this flaw to bypass intended restrictions. This issue\nonly affected Ubuntu 8.04 LTS, 10.04 LTS and 10.10. (CVE-2011-1487)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"perl","version":"5.8.8-12ubuntu0.5","description":"Larry Wall's Practical Extraction and Report Language","is_source":true},{"name":"perl","version":"5.8.8-12ubuntu0.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/perl","version_link":"https://launchpad.net/ubuntu/+source/perl/5.8.8-12ubuntu0.5"}],"dapper":[{"name":"perl","version":"5.8.7-10ubuntu1.3","description":"Larry Wall's Practical Extraction and Report Language","is_source":true},{"name":"perl","version":"5.8.7-10ubuntu1.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/perl","version_link":"https://launchpad.net/ubuntu/+source/perl/5.8.7-10ubuntu1.3"}],"maverick":[{"name":"perl","version":"5.10.1-12ubuntu2.1","description":"Larry Wall's Practical Extraction and Report Language","is_source":true},{"name":"perl","version":"5.10.1-12ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/perl","version_link":"https://launchpad.net/ubuntu/+source/perl/5.10.1-12ubuntu2.1"}],"lucid":[{"name":"perl","version":"5.10.1-8ubuntu2.1","description":"Larry Wall's Practical Extraction and Report Language","is_source":true},{"name":"perl","version":"5.10.1-8ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/perl","version_link":"https://launchpad.net/ubuntu/+source/perl/5.10.1-8ubuntu2.1"}],"natty":[{"name":"perl","version":"5.10.1-17ubuntu4.1","description":"Larry Wall's Practical Extraction and Report Language","is_source":true},{"name":"perl","version":"5.10.1-17ubuntu4.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/perl","version_link":"https://launchpad.net/ubuntu/+source/perl/5.10.1-17ubuntu4.1"}]},"type":"USN","cves_ids":["CVE-2010-2761","CVE-2010-4410","CVE-2011-1487","CVE-2010-1168","CVE-2010-1447","CVE-2010-4411"]}]},{"id":"CVE-2010-2322","published":"2010-06-18T18:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAbsolute path traversal vulnerability in the extract_jar function in\njartool.c in FastJar 0.98 allows remote attackers to create or overwrite\narbitrary files via a full pathname for a file within a .jar archive, a\nrelated issue to CVE-2010-0831. NOTE: this vulnerability exists because of\nan incomplete fix for CVE-2006-3619.","ubuntu_description":"","notes":[{"author":"kees","note":"I think this was fixed along with CVE-2010-0831 in USN-953-1"},{"author":"mdeslaur","note":"confirmed, it was fixed with USN-953-1\nfor jar in openjdk-6, see CVE-2005-1080"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-2322"],"bugs":[""],"patches":{"fastjar":[]},"tags":{},"packages":[{"name":"fastjar","source":"https://ubuntu.com/security/cve?package=fastjar","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=fastjar","debian":"https://tracker.debian.org/pkg/fastjar","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2:0.95-1ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2:0.97-3ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2:0.98-1ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2:0.98-1ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2192","published":"2010-06-18T16:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe make_lockdir_name function in policy.c in pmount 0.9.18 allow local\nusers to overwrite arbitrary files via a symlink attack on a file in\n/var/lock/.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-2192"],"bugs":[""],"patches":{"pmount":["vendor: http://www.debian.org/security/2010/dsa-2063","other: https://bugs.launchpad.net/ubuntu/jaunty/+source/pmount/+bug/574809"]},"tags":{},"packages":[{"name":"pmount","source":"https://ubuntu.com/security/cve?package=pmount","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pmount","debian":"https://tracker.debian.org/pkg/pmount","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"0.9.16-4ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"0.9.18-2+lenny1build0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"0.9.19-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"0.9.20-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.9.23","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2068","published":"2010-06-18T16:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nmod_proxy_http.c in mod_proxy_http in the Apache HTTP Server 2.2.9 through\n2.2.15, 2.3.4-alpha, and 2.3.5-alpha on Windows, NetWare, and OS/2, in\ncertain configurations involving proxy worker pools, does not properly\ndetect timeouts, which allows remote attackers to obtain a potentially\nsensitive response intended for a different client in opportunistic\ncircumstances via a normal HTTP request.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-2068"],"bugs":[""],"patches":{"apache2":[]},"tags":{},"packages":[{"name":"apache2","source":"https://ubuntu.com/security/cve?package=apache2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=apache2","debian":"https://tracker.debian.org/pkg/apache2","statuses":[{"release_codename":"dapper","status":"not-affected","description":"Windows only","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"Windows only","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"Windows only","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"Windows only","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"Windows only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-1769","published":"2010-06-18T16:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit in Apple iTunes before 9.2 on Windows, and Apple iOS before 4 on the\niPhone and iPod touch, accesses out-of-bounds memory during the handling of\ntables, which allows remote attackers to execute arbitrary code or cause a\ndenial of service (application crash) via a crafted HTML document, a\ndifferent vulnerability than CVE-2010-1387 and CVE-2010-1763.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit is a fork of khtml from kdelibs. kdelibs5 is farther from\nit, while qt4-x11 attempts to unify khtml and webkit."},{"author":"mdeslaur","note":"webkitkde is a wrapper around qt4-x11's webkit.\nthis looks like an ipod specific dupe of CVE-2010-1774."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-1769"],"bugs":[""],"patches":{"webkit":[],"qt4-x11":[],"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"qt4-x11","source":"https://ubuntu.com/security/cve?package=qt4-x11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qt4-x11","debian":"https://tracker.debian.org/pkg/qt4-x11","statuses":[{"release_codename":"dapper","status":"not-affected","description":"no webkit","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"no webkit","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-1763","published":"2010-06-18T16:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in WebKit in Apple iTunes before 9.2 on Windows\nhas unknown impact and attack vectors, a different vulnerability than\nCVE-2010-1387 and CVE-2010-1769.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"qt4-x11 unmaintained upstream (see README.webkit for details)\nwebkit is a fork of khtml from kdelibs. kdelibs5 is farther from\nit, while qt4-x11 attempts to unify khtml and webkit."},{"author":"mdeslaur","note":"webkitkde is a wrapper around qt4-x11's webkit.\nintroduced in http://trac.webkit.org/changeset/58950"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-1763"],"bugs":["https://bugs.webkit.org/show_bug.cgi?id=39008"],"patches":{"webkit":["upstream: http://trac.webkit.org/changeset/59486"],"qt4-x11":[],"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"qt4-x11","source":"https://ubuntu.com/security/cve?package=qt4-x11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qt4-x11","debian":"https://tracker.debian.org/pkg/qt4-x11","statuses":[{"release_codename":"dapper","status":"not-affected","description":"no webkit","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"no webkit","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-1387","published":"2010-06-18T16:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in JavaScriptCore in WebKit in Apple iTunes\nbefore 9.2 on Windows, and Apple iOS before 4 on the iPhone and iPod touch,\nallows remote attackers to execute arbitrary code or cause a denial of\nservice (application crash) via vectors related to page transitions, a\ndifferent vulnerability than CVE-2010-1763 and CVE-2010-1769.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"qt4-x11 unmaintained upstream (see README.webkit for details)\nwebkit is a fork of khtml from kdelibs. kdelibs5 is farther from\nit, while qt4-x11 attempts to unify khtml and webkit."},{"author":"mdeslaur","note":"webkitkde is a wrapper around qt4-x11's webkit."}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1006-1","https://www.cve.org/CVERecord?id=CVE-2010-1387"],"bugs":["https://bugs.webkit.org/show_bug.cgi?id=34321"],"patches":{"webkit":["upstream: http://trac.webkit.org/changeset/54129","upstream: http://trac.webkit.org/changeset/54141","upstream: http://trac.webkit.org/changeset/54265"],"qt4-x11":[],"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"qt4-x11","source":"https://ubuntu.com/security/cve?package=qt4-x11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qt4-x11","debian":"https://tracker.debian.org/pkg/qt4-x11","statuses":[{"release_codename":"dapper","status":"not-affected","description":"no webkit","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"no webkit","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.2.5-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.2.0-1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.2.4-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.2.4-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.2.4-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-0407","published":"2010-06-18T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple buffer overflows in the MSGFunctionDemarshall function in\nwinscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE\nPCSC-Lite before 1.5.4 allow local users to gain privileges via crafted\nmessage data, which is improperly demarshalled.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-969-1","https://www.cve.org/CVERecord?id=CVE-2010-0407"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/pcsc-lite/+bug/603657"],"patches":{"pcsc-lite":["vendor: http://www.debian.org/security/2010/dsa-2059","vendor: http://lwn.net/Articles/394855/"]},"tags":{},"packages":[{"name":"pcsc-lite","source":"https://ubuntu.com/security/cve?package=pcsc-lite","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pcsc-lite","debian":"https://tracker.debian.org/pkg/pcsc-lite","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.4.102-1ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.5.3-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.5.3-1ubuntu4.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.5.5-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.5.5-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.5.5-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.5.5","component":null,"pocket":"security"}]}],"notices_ids":["USN-969-1"],"notices":[{"id":"USN-969-1","title":"PCSC-Lite vulnerability","summary":"Multiple buffer overflows in PC/SC service.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2010-08-05T20:39:15.819558","description":"It was discovered that the PC/SC service did not correctly handle\nmalformed messages. A local attacker could exploit this to execute\narbitrary code with root privileges.\n","is_hidden":false,"release_packages":{"lucid":[{"name":"pcsc-lite","version":"1.5.3-1ubuntu4.1","description":"Middleware to access a smart card using PC/SC","is_source":true},{"name":"pcscd","version":"1.5.3-1ubuntu4.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/pcsc-lite","version_link":"https://launchpad.net/ubuntu/+source/pcsc-lite/1.5.3-1ubuntu4.1"}],"jaunty":[{"name":"pcsc-lite","version":"1.4.102-1ubuntu2.1","description":"Middleware to access a smart card using PC/SC","is_source":true},{"name":"pcscd","version":"1.4.102-1ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/pcsc-lite","version_link":"https://launchpad.net/ubuntu/+source/pcsc-lite/1.4.102-1ubuntu2.1"}],"karmic":[{"name":"pcsc-lite","version":"1.5.3-1ubuntu1.1","description":"Middleware to access a smart card using PC/SC","is_source":true},{"name":"pcscd","version":"1.5.3-1ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/pcsc-lite","version_link":"https://launchpad.net/ubuntu/+source/pcsc-lite/1.5.3-1ubuntu1.1"}]},"type":"USN","cves_ids":["CVE-2010-0407","CVE-2009-4901","CVE-2009-4902"]}]},{"id":"CVE-2009-4902","published":"2010-06-18T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBuffer overflow in the MSGFunctionDemarshall function in winscard_svc.c in\nthe PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite 1.5.4 and\nearlier might allow local users to gain privileges via crafted\nSCARD_CONTROL message data, which is improperly demarshalled. NOTE: this\nvulnerability exists because of an incorrect fix for CVE-2010-0407.","ubuntu_description":"","notes":[{"author":"kees","note":"only exists if CVE-2010-0407 is fixed incorrectly"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-969-1","https://www.cve.org/CVERecord?id=CVE-2009-4902"],"bugs":[""],"patches":{"pcsc-lite":[]},"tags":{},"packages":[{"name":"pcsc-lite","source":"https://ubuntu.com/security/cve?package=pcsc-lite","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pcsc-lite","debian":"https://tracker.debian.org/pkg/pcsc-lite","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.5.5","component":null,"pocket":"security"}]}],"notices_ids":["USN-969-1"],"notices":[{"id":"USN-969-1","title":"PCSC-Lite vulnerability","summary":"Multiple buffer overflows in PC/SC service.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2010-08-05T20:39:15.819558","description":"It was discovered that the PC/SC service did not correctly handle\nmalformed messages. A local attacker could exploit this to execute\narbitrary code with root privileges.\n","is_hidden":false,"release_packages":{"lucid":[{"name":"pcsc-lite","version":"1.5.3-1ubuntu4.1","description":"Middleware to access a smart card using PC/SC","is_source":true},{"name":"pcscd","version":"1.5.3-1ubuntu4.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/pcsc-lite","version_link":"https://launchpad.net/ubuntu/+source/pcsc-lite/1.5.3-1ubuntu4.1"}],"jaunty":[{"name":"pcsc-lite","version":"1.4.102-1ubuntu2.1","description":"Middleware to access a smart card using PC/SC","is_source":true},{"name":"pcscd","version":"1.4.102-1ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/pcsc-lite","version_link":"https://launchpad.net/ubuntu/+source/pcsc-lite/1.4.102-1ubuntu2.1"}],"karmic":[{"name":"pcsc-lite","version":"1.5.3-1ubuntu1.1","description":"Middleware to access a smart card using PC/SC","is_source":true},{"name":"pcscd","version":"1.5.3-1ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/pcsc-lite","version_link":"https://launchpad.net/ubuntu/+source/pcsc-lite/1.5.3-1ubuntu1.1"}]},"type":"USN","cves_ids":["CVE-2010-0407","CVE-2009-4901","CVE-2009-4902"]}]},{"id":"CVE-2009-4901","published":"2010-06-18T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart\nCard daemon (aka PCSCD) in MUSCLE PCSC-Lite before 1.5.4 might allow local\nusers to cause a denial of service (daemon crash) via crafted\nSCARD_SET_ATTRIB message data, which is improperly demarshalled and\ntriggers a buffer over-read, a related issue to CVE-2010-0407.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-969-1","https://www.cve.org/CVERecord?id=CVE-2009-4901"],"bugs":[""],"patches":{"pcsc-lite":[]},"tags":{},"packages":[{"name":"pcsc-lite","source":"https://ubuntu.com/security/cve?package=pcsc-lite","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pcsc-lite","debian":"https://tracker.debian.org/pkg/pcsc-lite","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.4.102-1ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.5.3-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.5.3-1ubuntu4.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.5.5-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.5.5-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.5.5-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.5.5","component":null,"pocket":"security"}]}],"notices_ids":["USN-969-1"],"notices":[{"id":"USN-969-1","title":"PCSC-Lite vulnerability","summary":"Multiple buffer overflows in PC/SC service.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2010-08-05T20:39:15.819558","description":"It was discovered that the PC/SC service did not correctly handle\nmalformed messages. A local attacker could exploit this to execute\narbitrary code with root privileges.\n","is_hidden":false,"release_packages":{"lucid":[{"name":"pcsc-lite","version":"1.5.3-1ubuntu4.1","description":"Middleware to access a smart card using PC/SC","is_source":true},{"name":"pcscd","version":"1.5.3-1ubuntu4.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/pcsc-lite","version_link":"https://launchpad.net/ubuntu/+source/pcsc-lite/1.5.3-1ubuntu4.1"}],"jaunty":[{"name":"pcsc-lite","version":"1.4.102-1ubuntu2.1","description":"Middleware to access a smart card using PC/SC","is_source":true},{"name":"pcscd","version":"1.4.102-1ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/pcsc-lite","version_link":"https://launchpad.net/ubuntu/+source/pcsc-lite/1.4.102-1ubuntu2.1"}],"karmic":[{"name":"pcsc-lite","version":"1.5.3-1ubuntu1.1","description":"Middleware to access a smart card using PC/SC","is_source":true},{"name":"pcscd","version":"1.5.3-1ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/pcsc-lite","version_link":"https://launchpad.net/ubuntu/+source/pcsc-lite/1.5.3-1ubuntu1.1"}]},"type":"USN","cves_ids":["CVE-2010-0407","CVE-2009-4901","CVE-2009-4902"]}]}],"offset":72680,"limit":20,"total_results":79316}