CVE-2009-1571

NameCVE-2009-1571
DescriptionUse-after-free vulnerability in the HTML parser in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, Thunderbird before 3.0.2, and SeaMonkey before 2.0.3 allows remote attackers to execute arbitrary code via unspecified method calls that attempt to access freed objects in low-memory situations.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-1999-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
icedove (PTS)jessie1:52.3.0-4~deb8u2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
iceapesourcelenny(not affected)
iceapesource(unstable)2.0.3-1
icedovesource(unstable)3.0.2-1
xulrunnersourceetch(unfixed)end-of-life
xulrunnersourcelenny1.9.0.18-1DSA-1999-1
xulrunnersource(unstable)1.9.1.8-1

Notes

[lenny] - iceape <not-affected> (Lenny package only provide xpcom stubs)

Search for package or bug name: Reporting problems