CVE-2010-0220
Published: 7 January 2010
The nsObserverList::FillObserverArray function in xpcom/ds/nsObserverList.cpp in Mozilla Firefox before 3.5.7 allows remote attackers to cause a denial of service (application crash) via a crafted web site that triggers memory consumption and an accompanying Low Memory alert dialog, and also triggers attempted removal of an observer from an empty observers array.
Notes
Author | Note |
---|---|
jdstrand | per upstream, xulrunner-1.9 not affected |
Priority
Status
Package | Release | Status |
---|---|---|
firefox Launchpad, Ubuntu, Debian |
dapper |
Ignored
(end of life)
|
hardy |
Not vulnerable
|
|
intrepid |
Does not exist
|
|
jaunty |
Does not exist
|
|
karmic |
Does not exist
|
|
upstream |
Needs triage
|
|
xulrunner-1.9 Launchpad, Ubuntu, Debian |
dapper |
Does not exist
|
hardy |
Not vulnerable
|
|
intrepid |
Not vulnerable
|
|
jaunty |
Not vulnerable
|
|
karmic |
Does not exist
|
|
upstream |
Not vulnerable
|
|
xulrunner-1.9.1 Launchpad, Ubuntu, Debian |
dapper |
Does not exist
|
hardy |
Does not exist
|
|
intrepid |
Does not exist
|
|
jaunty |
Released
(1.9.1.9+nobinonly-0ubuntu0.9.04.1)
|
|
karmic |
Released
(1.9.1.9+nobinonly-0ubuntu0.9.10.1)
|
|
upstream |
Released
(1.9.1.7)
|
|
xulrunner-1.9.2 Launchpad, Ubuntu, Debian |
dapper |
Does not exist
|
hardy |
Released
(1.9.2.6+nobinonly-0ubuntu0.8.04.1)
|
|
intrepid |
Does not exist
|
|
jaunty |
Ignored
(end of life, was needs-triage)
|
|
karmic |
Ignored
(end of life, was needs-triage)
|
|
upstream |
Needs triage
|