PT-2009-6653 · Mozilla+1 · Thunderbird+7

Christophe Charron

·

Published

1970-01-01

·

Updated

2018-10-30

·

CVE-2009-2464

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libmozjs1d-dbg versions (affected versions not specified) libmozjs1d versions (affected versions not specified) libmozjs-dev versions (affected versions not specified) libmozillainterfaces-java versions (affected versions not specified) Mozilla Firefox versions prior to 3.0.12 SeaMonkey versions prior to 2.0a1pre Thunderbird versions (affected versions not specified)
Description The issue concerns multiple vulnerabilities in various packages of the Debian GNU/Linux operating system, including libmozjs1d-dbg, libmozjs1d, libmozjs-dev, and libmozillainterfaces-java. These vulnerabilities can be exploited remotely, potentially leading to breaches of confidentiality, integrity, and availability of protected information. Additionally, a specific function, CheckIsSeparator, in Mozilla Firefox, SeaMonkey, and Thunderbird is vulnerable to remote attacks, which can cause a denial of service or possibly execute arbitrary code by loading multiple RDF files in a XUL tree element.
Recommendations For libmozjs1d-dbg, consider disabling the vulnerable package until a patch is available. For libmozjs1d, restrict access to the vulnerable module to minimize the risk of exploitation. For libmozjs-dev, avoid using the vulnerable development package until the issue is resolved. For libmozillainterfaces-java, restrict access to the vulnerable Java interface to minimize the risk of exploitation. For Mozilla Firefox, update to version 3.0.12 or later. For SeaMonkey, update to version 2.0a1pre or later. At the moment, there is no information about a newer version that contains a fix for Thunderbird.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-01736
BDU:2015-01737
BDU:2015-01738
BDU:2015-01739
CVE-2009-2464
DSA-1840-1
RHSA-2009:1162
RHSA-2009_1162

Affected Products

Firefox
Red Hat
Seamonkey
Thunderbird
Libmozillainterfaces-Java
Libmozjs-Dev
Libmozjs1D
Libmozjs1D-Dbg