CVE-2009-2479

NameCVE-2009-2479
DescriptionMozilla Firefox 3.0.x, 3.5, and 3.5.1 on Windows allows remote attackers to cause a denial of service (uncaught exception and application crash) via a long Unicode string argument to the write method. NOTE: this was originally reported as a stack-based buffer overflow. NOTE: on Linux and Mac OS X, a crash resulting from this long string reportedly occurs in an operating-system library, not in Firefox.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
xulrunnersourceetch(not affected)
xulrunnersourcelenny(not affected)
xulrunnersource(unstable)1.9.1.1-1

Notes

[etch] - xulrunner <not-affected> (only affects firefox 3.5)
[lenny] - xulrunner <not-affected> (only affects firefox 3.5)

Search for package or bug name: Reporting problems