Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2010-0556

Опубликовано: 26 июл. 2010
Источник: oracle-oval
Платформа: Oracle Linux 5

Описание

ELSA-2010-0556: firefox security update (CRITICAL)

firefox:

[3.6.7-3.0.1.el5]

  • Add firefox-oracle-default-prefs.js and firefox-oracle-default-bookmarks.html and remove the corresponding Red Hat ones

[3.6.7-3]

  • Rebuild

xulrunner:

[1.9.2.7-3.0.1.el5]

  • Added xulrunner-oracle-default-prefs.js and removed the corresponding RedHat one.

[1.9.2.7-3]

  • Include fix for 575836

Обновленные пакеты

Oracle Linux 5

Oracle Linux ia64

firefox

3.6.7-3.0.1.el5

xulrunner

1.9.2.7-3.0.1.el5

xulrunner-devel

1.9.2.7-3.0.1.el5

Oracle Linux x86_64

firefox

3.6.7-3.0.1.el5

xulrunner

1.9.2.7-3.0.1.el5

xulrunner-devel

1.9.2.7-3.0.1.el5

Oracle Linux i386

firefox

3.6.7-3.0.1.el5

xulrunner

1.9.2.7-3.0.1.el5

xulrunner-devel

1.9.2.7-3.0.1.el5

Связанные CVE

Связанные уязвимости

ubuntu
почти 15 лет назад

layout/generic/nsObjectFrame.cpp in Mozilla Firefox 3.6.7 does not properly free memory in the parameter array of a plugin instance, which allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted HTML document, related to the DATA and SRC attributes of an OBJECT element. NOTE: this vulnerability exists because of an incorrect fix for CVE-2010-1214.

redhat
почти 15 лет назад

layout/generic/nsObjectFrame.cpp in Mozilla Firefox 3.6.7 does not properly free memory in the parameter array of a plugin instance, which allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted HTML document, related to the DATA and SRC attributes of an OBJECT element. NOTE: this vulnerability exists because of an incorrect fix for CVE-2010-1214.

nvd
почти 15 лет назад

layout/generic/nsObjectFrame.cpp in Mozilla Firefox 3.6.7 does not properly free memory in the parameter array of a plugin instance, which allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted HTML document, related to the DATA and SRC attributes of an OBJECT element. NOTE: this vulnerability exists because of an incorrect fix for CVE-2010-1214.

debian
почти 15 лет назад

layout/generic/nsObjectFrame.cpp in Mozilla Firefox 3.6.7 does not pro ...

github
около 3 лет назад

layout/generic/nsObjectFrame.cpp in Mozilla Firefox 3.6.7 does not properly free memory in the parameter array of a plugin instance, which allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted HTML document, related to the DATA and SRC attributes of an OBJECT element. NOTE: this vulnerability exists because of an incorrect fix for CVE-2010-1214.