Mozilla Firefox CVE-2010-0159 Multiple Remote Memory Corruption Vulnerabilities
BID:38286
Info
Mozilla Firefox CVE-2010-0159 Multiple Remote Memory Corruption Vulnerabilities
| Bugtraq ID: | 38286 |
| Class: | Unknown |
| CVE: |
CVE-2010-0159 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 17 2010 12:00AM |
| Updated: | Mar 19 2015 08:25AM |
| Credit: | Henri Sivonen, Boris Zbarsky, Zack Weinberg, Bob Clary, Martijn Wargers, and Paul Nickerson |
| Vulnerable: |
Ubuntu Ubuntu Linux 9.10 sparc Ubuntu Ubuntu Linux 9.10 powerpc Ubuntu Ubuntu Linux 9.10 lpia Ubuntu Ubuntu Linux 9.10 i386 Ubuntu Ubuntu Linux 9.10 amd64 Ubuntu Ubuntu Linux 9.04 sparc Ubuntu Ubuntu Linux 9.04 powerpc Ubuntu Ubuntu Linux 9.04 lpia Ubuntu Ubuntu Linux 9.04 i386 Ubuntu Ubuntu Linux 9.04 amd64 Ubuntu Ubuntu Linux 8.10 sparc Ubuntu Ubuntu Linux 8.10 powerpc Ubuntu Ubuntu Linux 8.10 lpia Ubuntu Ubuntu Linux 8.10 i386 Ubuntu Ubuntu Linux 8.10 amd64 Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 SuSE SUSE Linux Enterprise Server 11 DEBUGINFO SuSE SUSE Linux Enterprise Server 11 SuSE SUSE Linux Enterprise Server 10 SP3 SuSE SUSE Linux Enterprise Server 10 SP2 SuSE SUSE Linux Enterprise SDK 10 SP3 SuSE SUSE Linux Enterprise SDK 10 SP2 SuSE SUSE Linux Enterprise Desktop 11 SuSE SUSE Linux Enterprise Desktop 10 SP3 SuSE SUSE Linux Enterprise Desktop 10 SP2 SuSE SUSE Linux Enterprise 11 SuSE SUSE Linux Enterprise 10 SP3 DEBUGINFO SuSE SUSE Linux Enterprise 10 SP2 DEBUGINFO SuSE openSUSE 11.4 SuSE Moblin 2.1 SuSE Moblin 2.0 Slackware Linux x86_64 -current Slackware Linux 13.0 x86_64 Slackware Linux 13.0 Slackware Linux 12.2 Slackware Linux -current S.u.S.E. openSUSE 11.2 S.u.S.E. openSUSE 11.1 S.u.S.E. openSUSE 11.0 RedHat Enterprise Linux WS 4 RedHat Enterprise Linux WS 3 RedHat Enterprise Linux Optional Productivity Application 5.4.z server RedHat Enterprise Linux Optional Productivity Application 5 server RedHat Enterprise Linux ES 4.8.z RedHat Enterprise Linux ES 4 RedHat Enterprise Linux ES 3 RedHat Enterprise Linux Desktop Workstation 5 client RedHat Desktop 4.0 RedHat Desktop 3.0 Red Hat Fedora 12 Red Hat Fedora 11 Red Hat Enterprise Linux EUS 5.4.z server Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux AS 4.8.z Red Hat Enterprise Linux AS 4 Red Hat Enterprise Linux AS 3 Red Hat Enterprise Linux 5 Server Pardus Linux 2009 0 Mozilla Thunderbird 3.0.1 Mozilla Thunderbird 3.0 Mozilla SeaMonkey 2.0.2 Mozilla SeaMonkey 2.0.1 Mozilla SeaMonkey 2.0 Mozilla Firefox 3.5.7 Mozilla Firefox 3.5.6 Mozilla Firefox 3.5.5 Mozilla Firefox 3.5.4 Mozilla Firefox 3.5.3 Mozilla Firefox 3.5.2 Mozilla Firefox 3.5.1 Mozilla Firefox 3.5 Mozilla Firefox 3.0.17 Mozilla Firefox 3.0.16 Mozilla Firefox 3.0.15 Mozilla Firefox 3.0.14 Mozilla Firefox 3.0.13 Mozilla Firefox 3.0.12 Mozilla Firefox 3.0.11 Mozilla Firefox 3.0.10 Mozilla Firefox 3.0.9 Mozilla Firefox 3.0.8 Mozilla Firefox 3.0.7 Mozilla Firefox 3.0.6 Mozilla Firefox 3.0.5 Mozilla Firefox 3.0.4 Mozilla Firefox 3.0.3 Mozilla Firefox 3.0.2 Mozilla Firefox 3.0.1 Mozilla Firefox 3.0 Mandriva Linux Mandrake 2010.0 x86_64 Mandriva Linux Mandrake 2010.0 Mandriva Linux Mandrake 2009.1 x86_64 Mandriva Linux Mandrake 2009.1 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 Hitachi uCosminexus Developer Standard 06-71-/B (Windows) Debian Linux 5.0 sparc Debian Linux 5.0 s/390 Debian Linux 5.0 powerpc Debian Linux 5.0 mipsel Debian Linux 5.0 mips Debian Linux 5.0 m68k Debian Linux 5.0 ia-64 Debian Linux 5.0 ia-32 Debian Linux 5.0 hppa Debian Linux 5.0 armel Debian Linux 5.0 arm Debian Linux 5.0 amd64 Debian Linux 5.0 alpha Debian Linux 5.0 Avaya Messaging Storage Server MM3.0 Avaya Messaging Storage Server 5.2 Avaya Messaging Storage Server 5.1 Avaya Messaging Storage Server 5.0 Avaya Messaging Storage Server 4.0 Avaya Messaging Storage Server 3.1 Avaya Messaging Storage Server 2.0 Avaya Messaging Storage Server 1.0 Avaya Messaging Storage Server Avaya Message Networking 5.2 Avaya Message Networking 3.1 Avaya Message Networking Avaya Intuity AUDIX LX R1.1 Avaya Intuity AUDIX LX 2.0 SP2 Avaya Intuity AUDIX LX 2.0 SP1 Avaya Intuity AUDIX LX 2.0 Avaya Intuity AUDIX LX 1.0 |
| Not Vulnerable: |
Mozilla Thunderbird 3.0.2 Mozilla SeaMonkey 2.0.3 Mozilla Firefox 3.5.8 Mozilla Firefox 3.0.18 Mozilla Firefox 3.6 Avaya Message Networking 5.2 |
Discussion
Mozilla Firefox CVE-2010-0159 Multiple Remote Memory Corruption Vulnerabilities
Mozilla Firefox, Thunderbird, and SeaMonkey are prone to multiple remote memory-corruption vulnerabilities.
Successful exploits may allow an attacker to execute arbitrary code in the context of the user running the affected application. Failed exploit attempts will result in a denial-of-service condition.
Mozilla Firefox, Thunderbird, and SeaMonkey are prone to multiple remote memory-corruption vulnerabilities.
Successful exploits may allow an attacker to execute arbitrary code in the context of the user running the affected application. Failed exploit attempts will result in a denial-of-service condition.
Exploit / POC
Mozilla Firefox CVE-2010-0159 Multiple Remote Memory Corruption Vulnerabilities
To exploit some of these issues, attackers may use readily available tools or entice an unsuspecting victim to follow a malicious link or view a malicious webpage.
Currently we are not aware of any working exploits for the issues that require an exploit. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
To exploit some of these issues, attackers may use readily available tools or entice an unsuspecting victim to follow a malicious link or view a malicious webpage.
Currently we are not aware of any working exploits for the issues that require an exploit. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Mozilla Firefox CVE-2010-0159 Multiple Remote Memory Corruption Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Slackware Linux 12.2
S.u.S.E. openSUSE 11.0
Slackware Linux x86_64 -current
S.u.S.E. openSUSE 11.1
Slackware Linux 13.0 x86_64
S.u.S.E. openSUSE 11.2
Slackware Linux -current
Solution:
Updates are available. Please see the references for more information.
Slackware Linux 12.2
-
Slackware mozilla-firefox-3.0.18-i686-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-12.2/patches/packages/ mozilla-firefox-3.0.18-i686-1.tgz -
Slackware seamonkey-2.0.3-i486-1_slack12.2.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-12.2/patches/packages/ seamonkey-2.0.3-i486-1_slack12.2.tgz
S.u.S.E. openSUSE 11.0
-
SuSE mozilla-xulrunner190-1.9.0.18-0.1.i586.rpm
http://download.opensuse.org/update/11.0/rpm/i586/mozilla-xulrunner190 -1.9.0.18-0.1.i586.rpm -
SuSE mozilla-xulrunner190-translations-1.9.0.18-0.1.i586.rpm
http://download.opensuse.org/update/11.0/rpm/i586/mozilla-xulrunner190 -translations-1.9.0.18-0.1.i586.rpm -
SuSE mozilla-xulrunner190-translations-1.9.0.18-0.1.ppc.rpm
http://download.opensuse.org/update/11.0/rpm/ppc/mozilla-xulrunner190- translations-1.9.0.18-0.1.ppc.rpm -
SuSE MozillaFirefox-translations-3.0.18-0.1.ppc.rpm
http://download.opensuse.org/update/11.0/rpm/ppc/MozillaFirefox-transl ations-3.0.18-0.1.ppc.rpm
Slackware Linux x86_64 -current
-
Slackware seamonkey-2.0.3-x86_64-1.txz
ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/ xap/seamonkey-2.0.3-x86_64-1.txz -
Slackware seamonkey-solibs-2.0.3-x86_64-1.txz
ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/ l/seamonkey-solibs-2.0.3-x86_64-1.txz
S.u.S.E. openSUSE 11.1
-
SuSE mozilla-xulrunner190-debugsource-1.9.0.18-0.1.1.i586.rpm
http://download.opensuse.org/debug/update/11.1/rpm/i586/mozilla-xulrun ner190-debugsource-1.9.0.18-0.1.1.i586.rpm -
SuSE mozilla-xulrunner190-debugsource-1.9.0.18-0.1.1.ppc.rpm
http://download.opensuse.org/debug/update/11.1/rpm/ppc/mozilla-xulrunn er190-debugsource-1.9.0.18-0.1.1.ppc.rpm -
SuSE mozilla-xulrunner190-translations-1.9.0.18-0.1.1.x86_64.rpm
http://download.opensuse.org/update/11.1/rpm/x86_64/mozilla-xulrunner1 90-translations-1.9.0.18-0.1.1.x86_64.rpm
Slackware Linux 13.0 x86_64
-
Slackware seamonkey-2.0.3-x86_64-1_slack13.0.txz
ftp://ftp.slackware.com/pub/slackware/slackware64-13.0/patches/package s/seamonkey-2.0.3-x86_64-1_slack13.0.txz -
Slackware seamonkey-solibs-2.0.3-x86_64-1_slack13.0.txz
ftp://ftp.slackware.com/pub/slackware/slackware64-13.0/patches/package s/seamonkey-solibs-2.0.3-x86_64-1_slack13.0.txz
S.u.S.E. openSUSE 11.2
-
SuSE MozillaFirefox-3.5.8-0.1.1.x86_64.rpm
http://download.opensuse.org/update/11.2/rpm/x86_64/MozillaFirefox-3.5 .8-0.1.1.x86_64.rpm -
SuSE python-xpcom191-1.9.1.8-0.1.1.i586.rpm
http://download.opensuse.org/update/11.2/rpm/i586/python-xpcom191-1.9. 1.8-0.1.1.i586.rpm -
SuSE seamonkey-debuginfo-2.0.3-0.1.1.x86_64.rpm
http://download.opensuse.org/debug/update/11.2/rpm/x86_64/seamonkey-de buginfo-2.0.3-0.1.1.x86_64.rpm -
SuSE seamonkey-irc-2.0.3-0.1.1.i586.rpm
http://download.opensuse.org/update/11.2/rpm/i586/seamonkey-irc-2.0.3- 0.1.1.i586.rpm
Slackware Linux -current
-
Slackware seamonkey-2.0.3-i486-1.txz
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/xap/ seamonkey-2.0.3-i486-1.txz -
Slackware seamonkey-solibs-2.0.3-i486-1.txz
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/l/se amonkey-solibs-2.0.3-i486-1.txz
References
Mozilla Firefox CVE-2010-0159 Multiple Remote Memory Corruption Vulnerabilities
References:
References:
- Mozilla Homepage (Mozilla Foundation)
- ASA-2010-056 seamonkey security update (RHSA-2010-0113) (Avaya)
- ASA-2010-058 firefox security update (RHSA-2010-0112) (Avaya)
- MFSA 2010-01: Crashes with evidence of memory corruption (rv:1.9.1.8/ 1.9.0.18) (Mozilla)
- RHSA-2010:0112 firefox security update (Red Hat)
- RHSA-2010:0113 seamonkey security update (Red Hat)
- RHSA-2010:0153 thunderbird security update (Red Hat)
- RHSA-2010:0154 thunderbird security update (Red Hat)
- Ubuntu Security Notice USN-895-1 (Ubuntu)
- Ubuntu Security Notice USN-896-1 (Ubuntu)