CVE-2011-0057

Priority
Low
Description
Use-after-free vulnerability in the Web Workers implementation in Mozilla
Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12,
allows remote attackers to execute arbitrary code via vectors related to a
JavaScript Worker and garbage collection.
References
Package
Upstream:needs-triage (Ubuntu source uses 3.6.x)
Ubuntu 8.04 LTS (Hardy Heron):released (3.6.14+build3+nobinonly-0ubuntu0.8.04.1)
Ubuntu 10.04 LTS (Lucid Lynx):DNE
Ubuntu 11.10 (Oneiric Ocelot):DNE
Ubuntu 12.04 LTS (Precise Pangolin):DNE
Ubuntu 12.10 (Quantal Quetzal):DNE
Ubuntu 13.04 (Raring Ringtail):DNE
Package
Upstream:released (1.9.2.14)
Ubuntu 8.04 LTS (Hardy Heron):released (1.9.2.14+build3+nobinonly-0ubuntu0.8.04.1)
Ubuntu 10.04 LTS (Lucid Lynx):released (1.9.2.14+build3+nobinonly-0ubuntu0.10.04.1)
Ubuntu 11.10 (Oneiric Ocelot):DNE
Ubuntu 12.04 LTS (Precise Pangolin):DNE
Ubuntu 12.10 (Quantal Quetzal):DNE
Ubuntu 13.04 (Raring Ringtail):DNE
Package
Upstream:released (3.6.14)
Ubuntu 8.04 LTS (Hardy Heron):ignored (uses system xulrunner)
Ubuntu 10.04 LTS (Lucid Lynx):released (3.6.14+build3+nobinonly-0ubuntu0.10.04.1)
Ubuntu 11.10 (Oneiric Ocelot):not-affected (4.0~b12+build1+nobinonly-0ubuntu3)
Ubuntu 12.04 LTS (Precise Pangolin):not-affected (4.0~b12+build1+nobinonly-0ubuntu3)
Ubuntu 12.10 (Quantal Quetzal):not-affected (4.0~b12+build1+nobinonly-0ubuntu3)
Ubuntu 13.04 (Raring Ringtail):not-affected (4.0~b12+build1+nobinonly-0ubuntu3)
Package
Upstream:released (2.0.12)
Ubuntu 8.04 LTS (Hardy Heron):ignored (reached end-of-life)
Ubuntu 10.04 LTS (Lucid Lynx):needed
Ubuntu 11.10 (Oneiric Ocelot):not-affected (2.0.13+nobinonly-0ubuntu1)
Ubuntu 12.04 LTS (Precise Pangolin):DNE
Ubuntu 12.10 (Quantal Quetzal):DNE
Ubuntu 13.04 (Raring Ringtail):DNE
Package
Upstream:needs-triage (Ubuntu source uses 3.6.x)
Ubuntu 8.04 LTS (Hardy Heron):DNE
Ubuntu 10.04 LTS (Lucid Lynx):DNE
Ubuntu 11.10 (Oneiric Ocelot):DNE
Ubuntu 12.04 LTS (Precise Pangolin):DNE
Ubuntu 12.10 (Quantal Quetzal):DNE
Ubuntu 13.04 (Raring Ringtail):DNE
More Information

Valid XHTML 1.0 Strict

Updated: 2013-04-25 17:14:22 UTC (commit 6757)