CVE-2010-3769
Publication date 10 December 2010
Last updated 24 July 2024
Ubuntu priority
The line-breaking implementation in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird before 3.0.11 and 3.1.x before 3.1.7, and SeaMonkey before 2.0.11 on Windows does not properly handle long strings, which allows remote attackers to execute arbitrary code via a crafted document.write call that triggers a buffer over-read.
Status
Package | Ubuntu Release | Status |
---|---|---|
firefox | ||
firefox-3.0 | ||
firefox-3.5 | ||
seamonkey | ||
thunderbird | ||
xulrunner-1.9.2 | ||
Notes
jdstrand
Ubuntu 11.04 (Natty Narwhal) has 4.0b7. Fixes will be in 4.0b8. thunderbird low (javascript not enabled by default)