CVE-2009-2477

NameCVE-2009-2477
Descriptionjs/src/jstracer.cpp in the Just-in-time (JIT) JavaScript compiler (aka TraceMonkey) in Mozilla Firefox 3.5 before 3.5.1 allows remote attackers to execute arbitrary code via certain use of the escape function that triggers access to uninitialized memory locations, as originally demonstrated by a document containing P and FONT elements.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs537104

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
xulrunnersourceetch(not affected)
xulrunnersourcelenny(not affected)
xulrunnersource(unstable)1.9.1.2-1537104

Notes

[lenny] - xulrunner <not-affected> (vulnerable code introduced in firefox 3.5)
[etch] - xulrunner <not-affected> (vulnerable code introduced in firefox 3.5)

Search for package or bug name: Reporting problems