Jump to content

Advisories MDVSA-2010:147: firefox


paul
 Share

Recommended Posts

Security issues were identified and fixed in firefox:

 

layout/generic/nsObjectFrame.cpp in Mozilla Firefox 3.6.7 does not

properly free memory in the parameter array of a plugin instance,

which allows remote attackers to cause a denial of service (memory

corruption) or possibly execute arbitrary code via a crafted

HTML document, related to the DATA and SRC attributes of an OBJECT

element. NOTE: this vulnerability exists because of an incorrect fix

for CVE-2010-1214 (CVE-2010-2755).

 

Packages for 2008.0 and 2009.0 are provided as of the Extended

Maintenance Program. Please visit this link to learn more:

http://store.mandriva.com/product_info.php?cPath=149&products_id=490

 

Additionally, some packages which require so, have been rebuilt and

are being provided as updates. The python packages contained a small

dependency problem on 2008.0/2009.0/MES5 that is addressed as well

with this advisory.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...