Описание
Heap-based buffer overflow in the _cairo_pen_init function in Mozilla Firefox 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, and SeaMonkey before 1.0.8 allows remote attackers to execute arbitrary code via a large stroke-width attribute in the clipPath element in an SVG file.
| Релиз | Статус | Примечание |
|---|---|---|
| dapper | released | 1.5.dfsg+1.5.0.13~prepatch070731-0ubuntu1 |
| devel | not-affected | |
| edgy | released | 2.0.0.6+0dfsg-0ubuntu0.6.10 |
| feisty | released | 2.0.0.6+1-0ubuntu1 |
| gutsy | not-affected | |
| upstream | needs-triage |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| dapper | DNE | |
| devel | DNE | |
| edgy | DNE | |
| feisty | DNE | |
| gutsy | released | 1.1.4-1ubuntu2 |
| upstream | needs-triage |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| dapper | DNE | |
| devel | released | 0.5-0ubuntu4 |
| edgy | DNE | |
| feisty | DNE | |
| gutsy | released | 0.5-0ubuntu4 |
| upstream | needs-triage |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| dapper | DNE | |
| devel | released | 0.1.6b-0ubuntu2 |
| edgy | DNE | |
| feisty | DNE | |
| gutsy | released | 0.1.6b-0ubuntu2 |
| upstream | needs-triage |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| dapper | released | 1.5.0.13-0ubuntu0.6.06 |
| devel | DNE | |
| edgy | released | 1.5.0.13-0ubuntu0.6.10 |
| feisty | released | 1.5.0.13-0ubuntu0.7.04 |
| gutsy | DNE | |
| upstream | needs-triage |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| dapper | DNE | |
| devel | released | 1.8.0.10-3ubuntu1 |
| edgy | ignored | end of life, was needed |
| feisty | released | 1.8.0.10-3ubuntu1 |
| gutsy | released | 1.8.0.10-3ubuntu1 |
| upstream | needs-triage |
Показывать по
9.3 Critical
CVSS2
Связанные уязвимости
Heap-based buffer overflow in the _cairo_pen_init function in Mozilla Firefox 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, and SeaMonkey before 1.0.8 allows remote attackers to execute arbitrary code via a large stroke-width attribute in the clipPath element in an SVG file.
Heap-based buffer overflow in the _cairo_pen_init function in Mozilla ...
Heap-based buffer overflow in the _cairo_pen_init function in Mozilla Firefox 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, and SeaMonkey before 1.0.8 allows remote attackers to execute arbitrary code via a large stroke-width attribute in the clipPath element in an SVG file.
9.3 Critical
CVSS2