Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.64479
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-1840-1)
Summary:The remote host is missing an update for the Debian 'xulrunner' package(s) announced via the DSA-1840-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'xulrunner' package(s) announced via the DSA-1840-1 advisory.

Vulnerability Insight:
Several remote vulnerabilities have been discovered in Xulrunner, a runtime environment for XUL applications, such as the Iceweasel web browser. The Common Vulnerabilities and Exposures project identifies the following problems:

CVE-2009-2462

Martijn Wargers, Arno Renevier, Jesse Ruderman, Olli Pettay and Blake Kaplan discovered several issues in the browser engine that could potentially lead to the execution of arbitrary code. (MFSA 2009-34)

CVE-2009-2463

monarch2020 reported an integer overflow in a base64 decoding function. (MFSA 2009-34)

CVE-2009-2464

Christophe Charron reported a possibly exploitable crash occurring when multiple RDF files were loaded in a XUL tree element. (MFSA 2009-34)

CVE-2009-2465

Yongqian Li reported that an unsafe memory condition could be created by specially crafted document. (MFSA 2009-34)

CVE-2009-2466

Peter Van der Beken, Mike Shaver, Jesse Ruderman, and Carsten Book discovered several issues in the JavaScript engine that could possibly lead to the execution of arbitrary JavaScript. (MFSA 2009-34)

CVE-2009-2467

Attila Suszter discovered an issue related to a specially crafted Flash object, which could be used to run arbitrary code. (MFSA 2009-35)

CVE-2009-2469

PenPal discovered that it is possible to execute arbitrary code via a specially crafted SVG element. (MFSA 2009-37)

CVE-2009-2471

Blake Kaplan discovered a flaw in the JavaScript engine that might allow an attacker to execute arbitrary JavaScript with chrome privileges. (MFSA 2009-39)

CVE-2009-2472

moz_bug_r_a4 discovered an issue in the JavaScript engine that could be used to perform cross-site scripting attacks. (MFSA 2009-40)

For the stable distribution (lenny), these problems have been fixed in version 1.9.0.12-0lenny1.

As indicated in the Etch release notes, security support for the Mozilla products in the oldstable distribution needed to be stopped before the end of the regular Etch security maintenance life cycle. You are strongly encouraged to upgrade to stable or switch to a still supported browser.

For the testing distribution (squeeze), these problems will be fixed soon.

For the unstable distribution (sid), these problems have been fixed in version 1.9.0.12-1.

We recommend that you upgrade your xulrunner packages.

Affected Software/OS:
'xulrunner' package(s) on Debian 5.

Solution:
Please install the updated package(s).

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2009-2462
1020800
http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020800.1-1
265068
http://sunsolve.sun.com/search/document.do?assetkey=1-26-265068-1
35758
http://www.securityfocus.com/bid/35758
35914
http://secunia.com/advisories/35914
35943
http://secunia.com/advisories/35943
35944
http://secunia.com/advisories/35944
35947
http://secunia.com/advisories/35947
36005
http://secunia.com/advisories/36005
36145
http://secunia.com/advisories/36145
ADV-2009-1972
http://www.vupen.com/english/advisories/2009/1972
ADV-2009-2152
http://www.vupen.com/english/advisories/2009/2152
ADV-2010-0650
http://www.vupen.com/english/advisories/2010/0650
FEDORA-2009-7961
https://www.redhat.com/archives/fedora-package-announce/2009-July/msg01032.html
RHSA-2009:1162
http://rhn.redhat.com/errata/RHSA-2009-1162.html
RHSA-2009:1163
http://rhn.redhat.com/errata/RHSA-2009-1163.html
RHSA-2010:0153
http://www.redhat.com/support/errata/RHSA-2010-0153.html
RHSA-2010:0154
http://www.redhat.com/support/errata/RHSA-2010-0154.html
SUSE-SA:2009:039
http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00005.html
SUSE-SA:2009:042
http://lists.opensuse.org/opensuse-security-announce/2009-08/msg00002.html
http://www.mozilla.org/security/announce/2009/mfsa2009-34.html
https://bugzilla.mozilla.org/show_bug.cgi?id=413085
https://bugzilla.mozilla.org/show_bug.cgi?id=442227
https://bugzilla.mozilla.org/show_bug.cgi?id=445177
https://bugzilla.mozilla.org/show_bug.cgi?id=461861
https://bugzilla.mozilla.org/show_bug.cgi?id=463350
https://bugzilla.mozilla.org/show_bug.cgi?id=466763
https://bugzilla.mozilla.org/show_bug.cgi?id=468211
https://bugzilla.mozilla.org/show_bug.cgi?id=472668
https://bugzilla.mozilla.org/show_bug.cgi?id=472950
https://bugzilla.mozilla.org/show_bug.cgi?id=491134
oval:org.mitre.oval:def:10906
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10906
Common Vulnerability Exposure (CVE) ID: CVE-2009-2464
https://bugzilla.mozilla.org/show_bug.cgi?id=441785
oval:org.mitre.oval:def:9594
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9594
Common Vulnerability Exposure (CVE) ID: CVE-2009-2465
https://bugzilla.mozilla.org/show_bug.cgi?id=482578
https://bugzilla.mozilla.org/show_bug.cgi?id=489050
oval:org.mitre.oval:def:10402
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10402
Common Vulnerability Exposure (CVE) ID: CVE-2009-2466
https://bugzilla.mozilla.org/show_bug.cgi?id=454704
https://bugzilla.mozilla.org/show_bug.cgi?id=465980
https://bugzilla.mozilla.org/show_bug.cgi?id=493281
https://bugzilla.mozilla.org/show_bug.cgi?id=494445
oval:org.mitre.oval:def:9820
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9820
Common Vulnerability Exposure (CVE) ID: CVE-2009-2467
266148
http://sunsolve.sun.com/search/document.do?assetkey=1-66-266148-1
http://www.mozilla.org/security/announce/2009/mfsa2009-35.html
https://bugzilla.mozilla.org/show_bug.cgi?id=493601
oval:org.mitre.oval:def:10473
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10473
Common Vulnerability Exposure (CVE) ID: CVE-2009-2469
http://www.mozilla.org/security/announce/2009/mfsa2009-37.html
https://bugzilla.mozilla.org/show_bug.cgi?id=488995
oval:org.mitre.oval:def:10030
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10030
Common Vulnerability Exposure (CVE) ID: CVE-2009-2470
1022665
http://www.securitytracker.com/id?1022665
35925
http://www.securityfocus.com/bid/35925
36126
http://secunia.com/advisories/36126
ADV-2009-2142
http://www.vupen.com/english/advisories/2009/2142
FEDORA-2009-8279
https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00198.html
FEDORA-2009-8288
https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00261.html
firefox-socks5-dos(52252)
https://exchange.xforce.ibmcloud.com/vulnerabilities/52252
http://www.mozilla.org/security/announce/2009/mfsa2009-38.html
https://bugzilla.mozilla.org/show_bug.cgi?id=459524
oval:org.mitre.oval:def:10197
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10197
Common Vulnerability Exposure (CVE) ID: CVE-2009-2471
http://www.mozilla.org/security/announce/2009/mfsa2009-39.html
https://bugzilla.mozilla.org/show_bug.cgi?id=460882
oval:org.mitre.oval:def:10572
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10572
Common Vulnerability Exposure (CVE) ID: CVE-2009-2472
http://www.mozilla.org/security/announce/2009/mfsa2009-40.html
https://bugzilla.mozilla.org/show_bug.cgi?id=479288
https://bugzilla.mozilla.org/show_bug.cgi?id=481434
https://bugzilla.mozilla.org/show_bug.cgi?id=497102
oval:org.mitre.oval:def:9497
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9497
CopyrightCopyright (C) 2009 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.