An anonymous security researcher, via TippingPoint's Zero Day Initiative, reported that the columns of a XUL tree element could be manipulated in a particular way which would leave a pointer owned by the column pointing to freed memory. An attacker could potentially use this vulnerability to crash a victim's browser and run arbitrary code on the victim's computer.
This issue has been addressed in following products: Red Hat Enterprise Linux 4 Red Hat Enterprise Linux 5 Via RHSA-2009:1430 https://rhn.redhat.com/errata/RHSA-2009-1430.html
This issue has been addressed in following products: Red Hat Enterprise Linux 4 Via RHSA-2009:1431 https://rhn.redhat.com/errata/RHSA-2009-1431.html
This issue has been addressed in following products: Red Hat Enterprise Linux 3 Via RHSA-2009:1432 https://rhn.redhat.com/errata/RHSA-2009-1432.html
epiphany-extensions-2.24.3-5.fc10, epiphany-2.24.3-10.fc10, Miro-2.0.5-4.fc10, ruby-gnome2-0.19.1-2.fc10, blam-1.8.5-14.fc10, evolution-rss-0.1.4-3.fc10, gecko-sharp2-0.13-12.fc10, gnome-web-photo-0.3-22.fc10, gnome-python2-extras-2.19.1-34.fc10, kazehakase-0.5.6-4.fc10.6, mozvoikko-0.9.5-14.fc10, google-gadgets-0.10.5-10.fc10, pcmanx-gtk2-0.3.8-13.fc10, mugshot-1.2.2-13.fc10, yelp-2.24.0-13.fc10, perl-Gtk2-MozEmbed-0.08-6.fc10.5, firefox-3.0.14-1.fc10, xulrunner-1.9.0.14-1.fc10 has been pushed to the Fedora 10 stable repository. If problems still persist, please make note of it in this bug report.
eclipse-3.4.2-15.fc11, epiphany-extensions-2.26.1-6.fc11, monodevelop-2.0-5.fc11, seahorse-plugins-2.26.2-5.fc11, epiphany-2.26.3-4.fc11, blam-1.8.5-14.fc11, chmsee-1.0.1-11.fc11, pcmanx-gtk2-0.3.8-8.fc11, gnome-web-photo-0.7-6.fc11, galeon-2.0.7-14.fc11, evolution-rss-0.1.4-3.fc11, gnome-python2-extras-2.25.3-7.fc11, hulahop-0.4.9-8.fc11, mozvoikko-0.9.7-0.7.rc1.fc11, google-gadgets-0.11.0-5.fc11, kazehakase-0.5.7-2.fc11, perl-Gtk2-MozEmbed-0.08-6.fc11.5, Miro-2.5.2-4.fc11, yelp-2.26.0-7.fc11, ruby-gnome2-0.19.1-2.fc11, firefox-3.5.3-1.fc11, xulrunner-1.9.1.3-1.fc11 has been pushed to the Fedora 11 stable repository. If problems still persist, please make note of it in this bug report.
This issue has been addressed in following products: Red Hat Enterprise Linux 5 Via RHSA-2010:0153 https://rhn.redhat.com/errata/RHSA-2010-0153.html
This issue has been addressed in following products: Red Hat Enterprise Linux 4 Via RHSA-2010:0154 https://rhn.redhat.com/errata/RHSA-2010-0154.html