Bug 448364 (CVE-2008-2419)
Summary: | CVE-2008-2419 firefox: heap corruption during Iframe operations between a JSframe write and a JSframe close | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Tomas Hoger <thoger> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED NOTABUG | QA Contact: | |
Severity: | high | Docs Contact: | |
Priority: | high | ||
Version: | unspecified | CC: | gecko-bugs-nobody, vdanen, walters |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2419 | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2010-04-08 21:45:54 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Tomas Hoger
2008-05-26 09:25:34 UTC
It is possible that this could affect Seamonkey 1.1.x, however there is no further information available on this issue, and it looks like it may only affect Windows. It also looks as though this issue may be more related to the java interpreter than to firefox itself. Regardless, upstream is unable to reproduce or determine this to be security significant in firefox itself. https://bugzilla.mozilla.org/show_bug.cgi?id=323026 https://bugzilla.mozilla.org/show_bug.cgi?id=275783 https://bugzilla.mozilla.org/show_bug.cgi?id=256763 |