PublicDate: 2005-05-02 04:00:00 UTC Candidate: CVE-2005-0989 References: https://ubuntu.com/security/notices/USN-157-1 https://ubuntu.com/security/notices/USN-149-3 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0989 Description: The find_replen function in jsstr.c in the Javascript engine for Mozilla Suite 1.7.6, Firefox 1.0.1 and 1.0.2, and Netscape 7.2 allows remote attackers to read portions of heap memory in a Javascript string via the lambda replace method. Ubuntu-Description: Notes: Priority: untriaged Discovered-by: Assigned-to: CVSS: Bugs: dapper_mozilla-thunderbird: released (1.5.0.13-0ubuntu0.6.06) edgy_mozilla-thunderbird: released (1.5.0.13-0ubuntu0.6.10) feisty_mozilla-thunderbird: released (1.5.0.13-0ubuntu0.7.04) devel_mozilla-thunderbird: DNE dapper_mozilla: released (1.7.12-1.1ubuntu2) edgy_mozilla: released (1.7.12-1.1ubuntu2) feisty_mozilla: DNE devel_mozilla: DNE upstream_mozilla: needs-triage upstream_mozilla-thunderbird: needs-triage