FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2009-1392

This CVE name corresponds to:

Entered Topic
2009-06-12 mozilla -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2009-1392
Phase Assigned(20090423)

Description

The browser engine in Mozilla Firefox 3 before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) nsEventStateManager::GetContentState and nsNativeTheme::CheckBooleanAttr; (2) UnhookTextRunFromFrames and ClearAllTextRunReferences; (3) nsTextFrame::ClearTextRun; (4) IsPercentageAware; (5) PL_DHashTableFinish; (6) nsListBoxBodyFrame::GetNextItemBox; (7) AtomTableClearEntry, related to the atom table, DOM mutation events, and Unicode surrogates; (8) nsHTMLEditor::HideResizers; and (9) nsWindow::SetCursor, related to changing the cursor; and other vectors.

References

Source Reference
CONFIRM http://www.mozilla.org/security/announce/2009/mfsa2009-24.html
CONFIRM https://bugzilla.mozilla.org/show_bug.cgi?id=380359
CONFIRM https://bugzilla.mozilla.org/show_bug.cgi?id=429969
CONFIRM https://bugzilla.mozilla.org/show_bug.cgi?id=431086
CONFIRM https://bugzilla.mozilla.org/show_bug.cgi?id=432068
CONFIRM https://bugzilla.mozilla.org/show_bug.cgi?id=451341
CONFIRM https://bugzilla.mozilla.org/show_bug.cgi?id=472776
CONFIRM https://bugzilla.mozilla.org/show_bug.cgi?id=486398
CONFIRM https://bugzilla.mozilla.org/show_bug.cgi?id=489041
CONFIRM https://bugzilla.mozilla.org/show_bug.cgi?id=490410
CONFIRM https://bugzilla.mozilla.org/show_bug.cgi?id=490425
CONFIRM https://bugzilla.mozilla.org/show_bug.cgi?id=490513
CONFIRM https://bugzilla.redhat.com/show_bug.cgi?id=503568
DEBIAN DSA-1820
DEBIAN DSA-1830
FEDORA FEDORA-2009-6366
FEDORA FEDORA-2009-6411
MANDRIVA MDVSA-2009:141
REDHAT RHSA-2009:1095
REDHAT RHSA-2009:1096
REDHAT RHSA-2009:1125
REDHAT RHSA-2009:1126
SLACKWARE SSA:2009-167-01
SLACKWARE SSA:2009-176-01
SLACKWARE SSA:2009-178-01
SUNALERT 265068
SUNALERT 1020800
UBUNTU USN-782-1
BID 35326
BID 35370
OSVDB 55144
OSVDB 55145
OSVDB 55146
OSVDB 55147
OVAL oval:org.mitre.oval:def:9501
SECTRACK 1022376
SECTRACK 1022397
SECUNIA 35331
SECUNIA 35428
SECUNIA 35431
SECUNIA 35439
SECUNIA 35440
SECUNIA 35468
SECUNIA 35536
SECUNIA 35415
SECUNIA 35561
SECUNIA 35602
VUPEN ADV-2009-1572
VUPEN ADV-2009-2152