|Description||Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.6, Thunderbird before 188.8.131.52, and SeaMonkey before 1.1.15 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the layout engine and destruction of arbitrary layout objects by the nsViewManager::Composite function.|
|Source||CVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)|
|NVD severity||high (attack range: remote)|
Vulnerable and fixed packages
The table below lists information on source packages.
|jessie (security), jessie||1:45.2.0-1~deb8u1||fixed|
|iceweasel (PTS)||wheezy (security), wheezy||38.8.0esr-1~deb7u1||fixed|
|xulrunner (PTS)||wheezy (security), wheezy||24.8.1esr-2~deb7u1||fixed|
The information below is based on the following data on fixed versions.
[etch] - iceweasel <end-of-life> (Etch Packages no longer covered by security support)
Iceweasel in Lenny links against Xulrunner
[etch] - xulrunner <end-of-life> (Etch Packages no longer covered by security support)
[etch] - iceape <end-of-life> (Etch Packages no longer covered by security support)
Iceape in Lenny only provides XPCOM libs