Candidate: CVE-2009-3382 PublicDate: 2009-10-29 14:30:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3382 https://ubuntu.com/security/notices/USN-853-1 Description: layout/base/nsCSSFrameConstructor.cpp in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 does not properly handle first-letter frames, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors. Ubuntu-Description: Notes: Bugs: Priority: untriaged Discovered-by: Assigned-to: CVSS: Patches_firefox-3.0: upstream_firefox-3.0: released (3.0.15) dapper_firefox-3.0: DNE hardy_firefox-3.0: released (3.0.15+nobinonly-0ubuntu0.8.04.1) intrepid_firefox-3.0: released (3.0.15+nobinonly-0ubuntu0.8.10.1) jaunty_firefox-3.0: released (3.0.15+nobinonly-0ubuntu0.9.04.1) karmic_firefox-3.0: DNE devel_firefox-3.0: DNE Patches_xulrunner-1.9: upstream_xulrunner-1.9: released (1.9.0.15) dapper_xulrunner-1.9: DNE hardy_xulrunner-1.9: released (1.9.0.15+nobinonly-0ubuntu0.8.04.1) intrepid_xulrunner-1.9: released (1.9.0.15+nobinonly-0ubuntu0.8.10.1) jaunty_xulrunner-1.9: released (1.9.0.15+nobinonly-0ubuntu0.9.04.1) karmic_xulrunner-1.9: DNE devel_xulrunner-1.9: DNE