Bug 590833 (CVE-2010-1199)

Summary: CVE-2010-1199 Mozilla Integer Overflow in XSLT Node Sorting
Product: [Other] Security Response Reporter: Josh Bressers <bressers>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: urgent Docs Contact:
Priority: urgent    
Version: unspecifiedCC: caillon, gecko-bugs-nobody, jlieskov, security-response-team, stransky, vdanen
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard: public=20100622,reported=20100505,source=mozilla,impact=critical,cvss2=6.8/AV:N/AC:M/Au:N/C:P/I:P/A:P,rhel-4/firefox=affected,rhel-5/firefox=affected,rhel-6/firefox=affected,rhel-3/seamonkey=affected,rhel-4/seamonkey=affected,rhel-5/thunderbird=affected/impact=moderate/cvss2=5.1/AV:N/AC:H/Au:N/C:P/I:P/A:P,rhel-4/thunderbird=affected/impact=moderate/cvss2=5.1/AV:N/AC:H/Au:N/C:P/I:P/A:P,cwe=CWE-190[auto]
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2010-12-20 13:45:41 EST Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Description Josh Bressers 2010-05-10 15:09:05 EDT
Security researcher Martin Barbella reported via TippingPoint's Zero Day
Initiative that an XSLT node sorting routine contained an integer overflow
vulnerability. In cases where one of the nodes to be sorted contained a
very large text value, the integer used to allocate a memory buffer to
store its value would overflow, resulting in too small a buffer being
created. An attacker could use this vulnerability to write data past the
end of the buffer, causing the browser to crash and potentially running
arbitrary code on a victim's computer.
Comment 1 Vincent Danen 2010-06-22 16:42:46 EDT
This issue is now public:

http://www.mozilla.org/security/announce/2010/mfsa2010-30.html
Comment 2 errata-xmlrpc 2010-06-22 17:37:42 EDT
This issue has been addressed in following products:

  Red Hat Enterprise Linux 4
  Red Hat Enterprise Linux 3

Via RHSA-2010:0499 https://rhn.redhat.com/errata/RHSA-2010-0499.html
Comment 3 errata-xmlrpc 2010-06-22 18:01:53 EDT
This issue has been addressed in following products:

  Red Hat Enterprise Linux 4

Via RHSA-2010:0500 https://rhn.redhat.com/errata/RHSA-2010-0500.html
Comment 4 errata-xmlrpc 2010-06-22 18:29:18 EDT
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5

Via RHSA-2010:0501 https://rhn.redhat.com/errata/RHSA-2010-0501.html
Comment 5 Fedora Update System 2010-06-23 09:18:29 EDT
seamonkey-2.0.5-1.fc12 has been submitted as an update for Fedora 12.
http://admin.fedoraproject.org/updates/seamonkey-2.0.5-1.fc12
Comment 6 Fedora Update System 2010-06-23 09:23:40 EDT
seamonkey-2.0.5-1.fc13 has been submitted as an update for Fedora 13.
http://admin.fedoraproject.org/updates/seamonkey-2.0.5-1.fc13
Comment 7 Fedora Update System 2010-06-23 10:19:54 EDT
xulrunner-1.9.2.4-1.fc13,firefox-3.6.4-1.fc13,mozvoikko-1.0-11.fc13,gnome-web-photo-0.9-9.fc13,perl-Gtk2-MozEmbed-0.08-6.fc13.14,gnome-python2-extras-2.25.3-19.fc13,galeon-2.0.7-29.fc13 has been submitted as an update for Fedora 13.
http://admin.fedoraproject.org/updates/xulrunner-1.9.2.4-1.fc13,firefox-3.6.4-1.fc13,mozvoikko-1.0-11.fc13,gnome-web-photo-0.9-9.fc13,perl-Gtk2-MozEmbed-0.08-6.fc13.14,gnome-python2-extras-2.25.3-19.fc13,galeon-2.0.7-29.fc13
Comment 8 Fedora Update System 2010-06-23 10:37:16 EDT
firefox-3.5.10-1.fc12,xulrunner-1.9.1.10-1.fc12,mozvoikko-1.0-10.fc12,gnome-web-photo-0.9-7.fc12,gnome-python2-extras-2.25.3-18.fc12,perl-Gtk2-MozEmbed-0.08-6.fc12.13,galeon-2.0.7-23.fc12 has been submitted as an update for Fedora 12.
http://admin.fedoraproject.org/updates/firefox-3.5.10-1.fc12,xulrunner-1.9.1.10-1.fc12,mozvoikko-1.0-10.fc12,gnome-web-photo-0.9-7.fc12,gnome-python2-extras-2.25.3-18.fc12,perl-Gtk2-MozEmbed-0.08-6.fc12.13,galeon-2.0.7-23.fc12
Comment 9 Fedora Update System 2010-06-24 12:22:36 EDT
seamonkey-2.0.5-1.fc12 has been pushed to the Fedora 12 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 10 Fedora Update System 2010-06-24 12:25:57 EDT
xulrunner-1.9.1.10-1.fc12, mozvoikko-1.0-10.fc12, gnome-web-photo-0.9-7.fc12, gnome-python2-extras-2.25.3-18.fc12, perl-Gtk2-MozEmbed-0.08-6.fc12.13, galeon-2.0.7-23.fc12, firefox-3.5.10-1.fc12 has been pushed to the Fedora 12 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 11 Fedora Update System 2010-06-24 12:30:58 EDT
xulrunner-1.9.2.4-1.fc13, firefox-3.6.4-1.fc13, mozvoikko-1.0-11.fc13, gnome-web-photo-0.9-9.fc13, perl-Gtk2-MozEmbed-0.08-6.fc13.14, gnome-python2-extras-2.25.3-19.fc13, galeon-2.0.7-29.fc13 has been pushed to the Fedora 13 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 12 Fedora Update System 2010-06-24 12:33:49 EDT
seamonkey-2.0.5-1.fc13 has been pushed to the Fedora 13 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 13 errata-xmlrpc 2010-06-25 11:32:47 EDT
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5

Via RHSA-2010:0501 https://rhn.redhat.com/errata/RHSA-2010-0501.html
Comment 14 errata-xmlrpc 2010-07-20 21:18:57 EDT
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5

Via RHSA-2010:0545 https://rhn.redhat.com/errata/RHSA-2010-0545.html
Comment 15 errata-xmlrpc 2010-07-20 21:39:44 EDT
This issue has been addressed in following products:

  Red Hat Enterprise Linux 4

Via RHSA-2010:0544 https://rhn.redhat.com/errata/RHSA-2010-0544.html
Comment 16 Fedora Update System 2010-07-22 22:40:14 EDT
thunderbird-3.0.6-1.fc12, sunbird-1.0-0.23.20090916hg.fc12 has been pushed to the Fedora 12 stable repository.  If problems still persist, please make note of it in this bug report.