PublicDateAtUSN: 2010-04-05 Candidate: CVE-2010-0182 PublicDate: 2010-04-05 17:30:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0182 https://ubuntu.com/security/notices/USN-921-1 Description: The XMLDocument::load function in Mozilla Firefox before 3.5.9 and 3.6.x before 3.6.2, Thunderbird before 3.0.4, and SeaMonkey before 2.0.4 does not perform the expected nsIContentPolicy checks during loading of content by XML documents, which allows attackers to bypass intended access restrictions via crafted content. Ubuntu-Description: Notes: jdstrand> CVEs in Firefox are tracked in the xulrunner source packages. The mapping of xulrunner sources to firefox is: xulrunner (1.8.0): firefox (1.5) - Ubuntu 6.06 LTS xulrunner (1.8.1): firefox (2.0) - Ubuntu 6.10 - 8.04 LTS xulrunner-1.9: firefox-3.0 xulrunner-1.9.1: firefox-3.5 jdstrand> Ubuntu 6.06 LTS and 10.04 LTS uses the embedded xulrunner and not the system xulrunner-1.9.2, so it is tracked in the firefox source package. Bugs: https://bugzilla.mozilla.org/show_bug.cgi?id=490790 Priority: low Discovered-by: Assigned-to: chrisccoulson CVSS: Patches_firefox: upstream_firefox: released (3.6.3) dapper_firefox: ignored (reached end-of-life) hardy_firefox: ignored (uses system xulrunner) intrepid_firefox: DNE jaunty_firefox: DNE karmic_firefox: DNE lucid_firefox: released (3.6.3+nobinonly-0ubuntu2) maverick_firefox: released (3.6.3+nobinonly-0ubuntu2) natty_firefox: released (3.6.3+nobinonly-0ubuntu2) oneiric_firefox: released (3.6.3+nobinonly-0ubuntu2) devel_firefox: released (3.6.3+nobinonly-0ubuntu2) Patches_xulrunner: upstream_xulrunner: needs-triage dapper_xulrunner: DNE hardy_xulrunner: ignored (reached end-of-life) intrepid_xulrunner: needed (reached end-of-life) jaunty_xulrunner: ignored (reached end-of-life) karmic_xulrunner: ignored (reached end-of-life) lucid_xulrunner: DNE maverick_xulrunner: DNE natty_xulrunner: DNE oneiric_xulrunner: DNE devel_xulrunner: DNE Patches_xulrunner-1.9: upstream_xulrunner-1.9: released (1.9.0.19) dapper_xulrunner-1.9: DNE hardy_xulrunner-1.9: ignored intrepid_xulrunner-1.9: needed (reached end-of-life) jaunty_xulrunner-1.9: ignored karmic_xulrunner-1.9: DNE lucid_xulrunner-1.9: DNE maverick_xulrunner-1.9: DNE natty_xulrunner-1.9: DNE oneiric_xulrunner-1.9: DNE devel_xulrunner-1.9: DNE Patches_xulrunner-1.9.1: upstream_xulrunner-1.9.1: released (1.9.1.9) dapper_xulrunner-1.9.1: DNE hardy_xulrunner-1.9.1: DNE intrepid_xulrunner-1.9.1: DNE jaunty_xulrunner-1.9.1: released (1.9.1.9+nobinonly-0ubuntu0.9.04.1) karmic_xulrunner-1.9.1: released (1.9.1.9+nobinonly-0ubuntu0.9.10.1) lucid_xulrunner-1.9.1: DNE maverick_xulrunner-1.9.1: DNE natty_xulrunner-1.9.1: DNE oneiric_xulrunner-1.9.1: DNE devel_xulrunner-1.9.1: DNE Patches_seamonkey: upstream_seamonkey: released (2.0.4) dapper_seamonkey: DNE hardy_seamonkey: released (2.0.8+build1+nobinonly-0ubuntu0.8.04.1) intrepid_seamonkey: needed (reached end-of-life) jaunty_seamonkey: released (2.0.8+build1+nobinonly-0ubuntu0.9.04.1) karmic_seamonkey: released (2.0.8+build1+nobinonly-0ubuntu0.9.10.1) lucid_seamonkey: released (2.0.8+build1+nobinonly-0ubuntu0.10.04.1) maverick_seamonkey: not-affected (2.0.4+nobinonly-0ubuntu1) natty_seamonkey: not-affected (2.0.4+nobinonly-0ubuntu1) oneiric_seamonkey: not-affected (2.0.4+nobinonly-0ubuntu1) devel_seamonkey: not-affected (2.0.4+nobinonly-0ubuntu1) Patches_thunderbird: Priority_thunderbird: negligible upstream_thunderbird: released (3.0.4) dapper_thunderbird: DNE hardy_thunderbird: ignored intrepid_thunderbird: needed (reached end-of-life) jaunty_thunderbird: ignored karmic_thunderbird: ignored lucid_thunderbird: released (3.0.4+nobinonly-0ubuntu1) maverick_thunderbird: released (3.0.4+nobinonly-0ubuntu1) natty_thunderbird: released (3.0.4+nobinonly-0ubuntu1) oneiric_thunderbird: released (3.0.4+nobinonly-0ubuntu1) devel_thunderbird: released (3.0.4+nobinonly-0ubuntu1)