[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247974

 
 

909

 
 

194654

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-3201-1 iceweasel -- iceweasel

ID: oval:org.secpod.oval:def:602005Date: (C)2015-03-26   (M)2023-12-07
Class: PATCHFamily: unix




Multiple security issues have been found in Iceweasel, Debian"s version of the Mozilla Firefox web browser. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2015-0817 ilxu1a reported a flaw in Mozilla"s implementation of typed array bounds checking in JavaScript just-in-time compilation and its management of bounds checking for heap access. This flaw can be leveraged into the reading and writing of memory allowing for arbitary code execution on the local system. CVE-2015-0818 Mariusz Mlynski discovered a method to run arbitrary scripts in a privileged context. This bypassed the same-origin policy protections by using a flaw in the processing of SVG format content navigation.

Platform:
Debian 7.0
Product:
iceweasel
Reference:
DSA-3201-1
CVE-2015-0817
CVE-2015-0818
CVE    2
CVE-2015-0817
CVE-2015-0818
CPE    2
cpe:/a:gnu:iceweasel
cpe:/o:debian:debian_linux:7.x

© SecPod Technologies