New User, Welcome!     Login

Vladimir Vukicevic

[USN-853-1] Firefox and Xulrunner vulnerabilities

tricked into opening a crafted media file, a remote attacker could cause a
denial of service or possibly execute arbitrary code with the privileges of the
user invoking the program. This issue only affected Ubuntu 9.10.
(CVE-2009-3377)

Vladimir Vukicevic, Jesse Ruderman, Martijn Wargers, Daniel Banchero, David
Keeler, Boris Zbarsky, Thomas Frederiksen, Marcia Knous, Carsten Book, Kevin
Brosnan, David Anderson and Jeff Walden discovered various flaws in the browser
and JavaScript engines of Firefox. If a user were tricked into viewing a
malicious website, a remote attacker could cause a denial of service or
possibly execute arbitrary code with the privileges of the user invoking the

[ MDVSA-2009:290 ] firefox

 Mozilla developers and community members identified and fixed
 several stability bugs in the browser engine used in Firefox and
 other Mozilla-based products. Some of these crashes showed evidence
 of memory corruption under certain circumstances and we presume that
 with enough effort at least some of these could be exploited to run
 arbitrary code. Vladimir Vukicevic, Jesse Ruderman, Martijn Wargers,
 Daniel Banchero, David Keeler, and Boris Zbarsky reported crashes
 in the browser engine which affected both Firefox 3 and Firefox 3.5
 (CVE-2009-3380). Carsten Book reported a crash in the browser engine
 which affected only Firefox 3 (CVE-2009-3382).
 

[USN-930-5] ant, apturl, Epiphany, gluezilla, gnome-python-extras, liferea, mozvoikko, OpenJDK, packagekit, ubufox, webfav, yelp update

 Aki Helin discovered that libpng did not properly handle certain malformed
 PNG images. If a user were tricked into opening a crafted PNG file, an
 attacker could cause a denial of service or possibly execute arbitrary code
 with the privileges of the user invoking the program. (CVE-2010-1205)
 
 Yosuke Hasegawa and Vladimir Vukicevic discovered that the same-origin
 check in Firefox could be bypassed by utilizing the importScripts Web
 Worker method. If a user were tricked into viewing a malicious website, an
 attacker could exploit this to read data from other domains.
 (CVE-2010-1213, CVE-2010-1207)
 

[USN-853-2] Firefox and Xulrunner regression

 tricked into opening a crafted media file, a remote attacker could cause a
 denial of service or possibly execute arbitrary code with the privileges of the
 user invoking the program. This issue only affected Ubuntu 9.10.
 (CVE-2009-3377)
 
 Vladimir Vukicevic, Jesse Ruderman, Martijn Wargers, Daniel Banchero, David
 Keeler, Boris Zbarsky, Thomas Frederiksen, Marcia Knous, Carsten Book, Kevin
 Brosnan, David Anderson and Jeff Walden discovered various flaws in the browser
 and JavaScript engines of Firefox. If a user were tricked into viewing a
 malicious website, a remote attacker could cause a denial of service or
 possibly execute arbitrary code with the privileges of the user invoking the

[USN-930-4] Firefox and Xulrunner vulnerabilities

Aki Helin discovered that libpng did not properly handle certain malformed
PNG images. If a user were tricked into opening a crafted PNG file, an
attacker could cause a denial of service or possibly execute arbitrary code
with the privileges of the user invoking the program. (CVE-2010-1205)

Yosuke Hasegawa and Vladimir Vukicevic discovered that the same-origin
check in Firefox could be bypassed by utilizing the importScripts Web
Worker method. If a user were tricked into viewing a malicious website, an
attacker could exploit this to read data from other domains.
(CVE-2010-1213, CVE-2010-1207)


[ MDVSA-2009:290-1 ] firefox

 Mozilla developers and community members identified and fixed
 several stability bugs in the browser engine used in Firefox and
 other Mozilla-based products. Some of these crashes showed evidence
 of memory corruption under certain circumstances and we presume that
 with enough effort at least some of these could be exploited to run
 arbitrary code. Vladimir Vukicevic, Jesse Ruderman, Martijn Wargers,
 Daniel Banchero, David Keeler, and Boris Zbarsky reported crashes
 in the browser engine which affected both Firefox 3 and Firefox 3.5
 (CVE-2009-3380). Carsten Book reported a crash in the browser engine
 which affected only Firefox 3 (CVE-2009-3382).
 

[USN-957-1] Firefox and Xulrunner vulnerabilities

Aki Helin discovered that libpng did not properly handle certain malformed
PNG images. If a user were tricked into opening a crafted PNG file, an
attacker could cause a denial of service or possibly execute arbitrary code
with the privileges of the user invoking the program. (CVE-2010-1205)

Yosuke Hasegawa and Vladimir Vukicevic discovered that the same-origin
check in Firefox could be bypassed by utilizing the importScripts Web
Worker method. If a user were tricked into viewing a malicious website, an
attacker could exploit this to read data from other domains.
(CVE-2010-1213, CVE-2010-1207)


[SECURITY] [DSA 1922-1] New xulrunner packages fix several vulnerabilities

browser. The Common Vulnerabilities and Exposures project identifies
the following problems:

CVE-2009-3380

    Vladimir Vukicevic, Jesse Ruderman, Martijn Wargers, Daniel
    Banchero, David Keeler and Boris Zbarsky reported crashes in
    layout engine, which might allow the execution of arbitrary code.

CVE-2009-3382


[USN-957-2] Firefox and Xulrunner vulnerability

 Aki Helin discovered that libpng did not properly handle certain malformed
 PNG images. If a user were tricked into opening a crafted PNG file, an
 attacker could cause a denial of service or possibly execute arbitrary code
 with the privileges of the user invoking the program. (CVE-2010-1205)
 
 Yosuke Hasegawa and Vladimir Vukicevic discovered that the same-origin
 check in Firefox could be bypassed by utilizing the importScripts Web
 Worker method. If a user were tricked into viewing a malicious website, an
 attacker could exploit this to read data from other domains.
 (CVE-2010-1213, CVE-2010-1207)
 



Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!