FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2009-1837

This CVE name corresponds to:

Entered Topic
2009-06-12 mozilla -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2009-1837
Phase Assigned(20090529)

Description

Race condition in the NPObjWrapper_NewResolve function in modules/plugin/base/src/nsJSNPRuntime.cpp in xul.dll in Mozilla Firefox 3 before 3.0.11 might allow remote attackers to execute arbitrary code via a page transition during Java applet loading, related to a use-after-free vulnerability for memory associated with a destroyed Java object.

References

Source Reference
BUGTRAQ 20090612 Secunia Research: Mozilla Firefox Java Applet Loading Vulnerability
MISC http://secunia.com/secunia_research/2009-19/
CONFIRM http://www.mozilla.org/security/announce/2009/mfsa2009-28.html
CONFIRM https://bugzilla.mozilla.org/show_bug.cgi?id=486269
CONFIRM https://bugzilla.redhat.com/show_bug.cgi?id=503579
DEBIAN DSA-1820
FEDORA FEDORA-2009-6366
FEDORA FEDORA-2009-6411
REDHAT RHSA-2009:1095
SLACKWARE SSA:2009-167-01
SUNALERT 264308
BID 35326
BID 35360
OVAL oval:org.mitre.oval:def:10628
SECTRACK 1022386
SECUNIA 34241
SECUNIA 35331
SECUNIA 35431
SECUNIA 35468
SECUNIA 35415
VUPEN ADV-2009-1572