CVE-2010-0176

NameCVE-2010-0176
DescriptionMozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2; Thunderbird before 3.0.4; and SeaMonkey before 2.0.4 do not properly manage reference counts for option elements in a XUL tree optgroup, which might allow remote attackers to execute arbitrary code via unspecified vectors that trigger access to deleted elements, related to a "dangling pointer vulnerability."
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-2027-1

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
iceapesourcelenny(not affected)
iceapesource(unstable)2.0.4-1
icedovesourcelenny(unfixed)end-of-life
icedovesource(unstable)3.0.4-1
iceweaselsourcelenny(not affected)
iceweaselsource(unstable)3.5.11-2
xulrunnersourcelenny1.9.0.19-1DSA-2027-1
xulrunnersource(unstable)1.9.1.9-1

Notes

[lenny] - iceweasel <not-affected> (Iceweasel in Lenny links against xulrunner)
[lenny] - iceape <not-affected> (Only a stub package)

Search for package or bug name: Reporting problems