CVE-2009-2662

Publication date 4 August 2009

Last updated 24 July 2024


Ubuntu priority

The browser engine in Mozilla Firefox 3.5.x before 3.5.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the TraceRecorder::snapshot function in js/src/jstracer.cpp, and unspecified other vectors.

Status

Package Ubuntu Release Status
firefox 9.10 karmic Not in release
9.04 jaunty Not in release
8.10 intrepid Not in release
8.04 LTS hardy
Not affected
6.06 LTS dapper Ignored end of life
xulrunner-1.9 9.10 karmic Not in release
9.04 jaunty
Not affected
8.10 intrepid
Not affected
8.04 LTS hardy
Not affected
6.06 LTS dapper Not in release
xulrunner-1.9.1 9.10 karmic
Not affected
9.04 jaunty
Fixed 1.9.1.3+build1+nobinonly-0ubuntu0.9.04.2
8.10 intrepid Not in release
8.04 LTS hardy Not in release
6.06 LTS dapper Not in release