Firefox browser engine crashes
Published Jun 12, 2009
9.3
HIGHCVSS 2.0
EPSS 9.28%
Description
The browser engine in Mozilla Firefox 3 before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) nsEventStateManager::GetContentState and nsNativeTheme::CheckBooleanAttr; (2) UnhookTextRunFromFrames and ClearAllTextRunReferences; (3) nsTextFrame::ClearTextRun; (4) IsPercentageAware; (5) PL_DHashTableFinish; (6) nsListBoxBodyFrame::GetNextItemBox; (7) AtomTableClearEntry, related to the atom table, DOM mutation events, and Unicode surrogates; (8) nsHTMLEditor::HideResizers; and (9) nsWindow::SetCursor, related to changing the cursor; and other vectors.
Affected products
No data.
- 3.0
- 3.0
- 3.0
- 3.0.1
- 3.0.2
- 3.0.3
- 3.0.4
- 3.0.5
- 3.0.6
- 3.0.7
- 3.0.8
- 3.0.9
- 3.0.10
- ≤ 1.1.16
- 1.0
- 1.0
- 1.0
- 1.0
- 1.0
- 1.0
- 1.0.1
- 1.0.3
- 1.0.4
- 1.0.6
- 1.0.8
- 1.0.9
- 1.0.99
- 1.1
- 1.1
- 1.1
- 1.1.1
- 1.1.3
- 1.1.5
- 1.1.5
- 1.1.6
- 1.1.7
- 1.1.8
- 1.1.9
- 1.1.10
- 1.1.11
- 1.1.12
- 1.1.13
- 1.1.15
- ≤ 2.0.0.19
- 0.1
- 0.2
- 0.3
- 0.4
- 0.5
- 0.6
- 0.7
- 0.7.1
- 0.7.2
- 0.7.3
- 0.8
- 0.9
- 1.0
- 1.0.1
- 1.0.2
- 1.0.3
- 1.0.4
- 1.0.5
- 1.0.5
- 1.0.6
- 1.0.7
- 1.0.8
- 1.5
- 1.5
- 1.5.0.1
- 1.5.0.2
- 1.5.0.3
- 1.5.0.4
- 1.5.0.5
- 1.5.0.6
- 1.5.0.7
- 1.5.0.8
- 1.5.0.9
- 1.5.0.10
- 1.5.0.11
- 1.5.0.12
- 1.5.0.13
- 1.5.0.14
- 1.5.1
- 1.5.2
- 1.7.1
- 1.7.3
- 2.0.0.0
- 2.0.0.1
- 2.0.0.2
- 2.0.0.3
- 2.0.0.4
- 2.0.0.5
- 2.0.0.6
- 2.0.0.7
- 2.0.0.8
- 2.0.0.9
- 2.0.0.11
- 2.0.0.12
- 2.0.0.13
- 2.0.0.14
- 2.0.0.15
- 2.0.0.16
- 2.0.0.17
- 2.0.0.18
- 2.0_.4
- 2.0_.5
- 2.0_.6
- 2.0_.9
- 2.0_.12
- 2.0_.13
- 2.0_.14
- 2.0_8
No data.
Red Hat Enterprise Linux 3
seamonkey-0:1.0.9-0.38.el3
Fixed · RHSA-2009:1096
Red Hat Enterprise Linux 4
firefox-0:3.0.11-4.el4
Fixed · RHSA-2009:1095
Red Hat Enterprise Linux 4
seamonkey-0:1.0.9-43.el4_8
Fixed · RHSA-2009:1096
Red Hat Enterprise Linux 4
thunderbird-0:1.5.0.12-23.el4
Fixed · RHSA-2009:1125
Red Hat Enterprise Linux 5
firefox-0:3.0.11-2.el5_3
Fixed · RHSA-2009:1095
Red Hat Enterprise Linux 5
thunderbird-0:2.0.0.22-2.el5_3
Fixed · RHSA-2009:1126
Red Hat Enterprise Linux 5
xulrunner-0:1.9.0.11-3.el5_3
Fixed · RHSA-2009:1095
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 3 | seamonkey-0:1.0.9-0.38.el3 | Fixed | RHSA-2009:1096 |
| Red Hat Enterprise Linux 4 | firefox-0:3.0.11-4.el4 | Fixed | RHSA-2009:1095 |
| Red Hat Enterprise Linux 4 | seamonkey-0:1.0.9-43.el4_8 | Fixed | RHSA-2009:1096 |
| Red Hat Enterprise Linux 4 | thunderbird-0:1.5.0.12-23.el4 | Fixed | RHSA-2009:1125 |
| Red Hat Enterprise Linux 5 | firefox-0:3.0.11-2.el5_3 | Fixed | RHSA-2009:1095 |
| Red Hat Enterprise Linux 5 | thunderbird-0:2.0.0.22-2.el5_3 | Fixed | RHSA-2009:1126 |
| Red Hat Enterprise Linux 5 | xulrunner-0:1.9.0.11-3.el5_3 | Fixed | RHSA-2009:1095 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (52)
- http://osvdb.org/55144 vdb-entryx_refsource_OSVDB
- http://osvdb.org/55145 vdb-entryx_refsource_OSVDB
- http://osvdb.org/55146 vdb-entryx_refsource_OSVDB
- http://osvdb.org/55147 vdb-entryx_refsource_OSVDB
- http://rhn.redhat.com/errata/RHSA-2009-1096.html vendor-advisoryx_refsource_REDHATPatchVendor Advisory
- http://secunia.com/advisories/35331 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/35415 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/35428 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/35431 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/35439 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/35440 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/35468 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/35536 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/35561 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/35602 third-party-advisoryx_refsource_SECUNIA
- http://securitytracker.com/id?1022376 vdb-entryx_refsource_SECTRACKPatch
- http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.372468 vendor-advisoryx_refsource_SLACKWARE
- http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.425408 vendor-advisoryx_refsource_SLACKWARE
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-265068-1 vendor-advisoryx_refsource_SUNALERT
- http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020800.1-1 vendor-advisoryx_refsource_SUNALERT
- http://www.debian.org/security/2009/dsa-1820 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2009/dsa-1830 vendor-advisoryx_refsource_DEBIAN
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:141 vendor-advisoryx_refsource_MANDRIVA
- http://www.mozilla.org/security/announce/2009/mfsa2009-24.html x_refsource_CONFIRMVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2009-1125.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2009-1126.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/bid/35326 vdb-entryx_refsource_BID
- http://www.securityfocus.com/bid/35370 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id?1022397 vdb-entryx_refsource_SECTRACK
- http://www.slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.454275 vendor-advisoryx_refsource_SLACKWARE
- http://www.ubuntu.com/usn/usn-782-1 vendor-advisoryx_refsource_UBUNTU
- http://www.vupen.com/english/advisories/2009/1572 vdb-entryx_refsource_VUPENPatchVendor Advisory
- http://www.vupen.com/english/advisories/2009/2152 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2009-1392 Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=380359 x_refsource_CONFIRMExploit
- https://bugzilla.mozilla.org/show_bug.cgi?id=429969 x_refsource_CONFIRMExploit
- https://bugzilla.mozilla.org/show_bug.cgi?id=431086 x_refsource_CONFIRMExploit
- https://bugzilla.mozilla.org/show_bug.cgi?id=432068 x_refsource_CONFIRMExploit
- https://bugzilla.mozilla.org/show_bug.cgi?id=451341 x_refsource_CONFIRMExploit
- https://bugzilla.mozilla.org/show_bug.cgi?id=472776 x_refsource_CONFIRMExploit
- https://bugzilla.mozilla.org/show_bug.cgi?id=486398 x_refsource_CONFIRMExploit
- https://bugzilla.mozilla.org/show_bug.cgi?id=489041 x_refsource_CONFIRMExploit
- https://bugzilla.mozilla.org/show_bug.cgi?id=490410 x_refsource_CONFIRMExploit
- https://bugzilla.mozilla.org/show_bug.cgi?id=490425 x_refsource_CONFIRM
- https://bugzilla.mozilla.org/show_bug.cgi?id=490513 x_refsource_CONFIRMExploit
- https://bugzilla.redhat.com/show_bug.cgi?id=503568 x_refsource_CONFIRMExploitIssue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2009-1392
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9501 vdb-entrysignaturex_refsource_OVAL
- https://rhn.redhat.com/errata/RHSA-2009-1095.html vendor-advisoryx_refsource_REDHATPatchVendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2009-1392
- https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00574.html vendor-advisoryx_refsource_FEDORA
- https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00657.html vendor-advisoryx_refsource_FEDORA
Change history (0)
No recorded changes yet.