CVE-2009-1837
12.06.2009, 21:30
Race condition in the NPObjWrapper_NewResolve function in modules/plugin/base/src/nsJSNPRuntime.cpp in xul.dll in Mozilla Firefox 3 before 3.0.11 might allow remote attackers to execute arbitrary code via a page transition during Java applet loading, related to a use-after-free vulnerability for memory associated with a destroyed Java object.
| Vendor | Product | Version |
|---|---|---|
| mozilla | firefox | 3.0 ≤ 𝑥 < 3.0.11 |
| debian | debian_linux | 5.0 |
| redhat | enterprise_linux | 4.0 |
| redhat | enterprise_linux | 5.0 |
| redhat | enterprise_linux_desktop | 4.0 |
| redhat | enterprise_linux_desktop | 5.0 |
| redhat | enterprise_linux_eus | 4.8 |
| redhat | enterprise_linux_eus | 5.3 |
| redhat | enterprise_linux_server | 4.0 |
| redhat | enterprise_linux_server | 5.0 |
| redhat | enterprise_linux_server_aus | 5.3 |
| redhat | enterprise_linux_workstation | 4.0 |
| redhat | enterprise_linux_workstation | 5.0 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Ubuntu Product | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| firefox |
| ||||||||||
| xulrunner-1.9 |
| ||||||||||
| xulrunner-1.9.1 |
|
References