Bug 566049 - (CVE-2010-0160) CVE-2010-0160 Mozilla implementation of Web Workers can lead to crash with evidence of memory corruption (MFSA 2010-02)
CVE-2010-0160 Mozilla implementation of Web Workers can lead to crash with ev...
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
urgent Severity urgent
: ---
: ---
Assigned To: Red Hat Product Security
impact=critical,source=mozilla,report...
: Security
Depends On: 566693
Blocks:
  Show dependency treegraph
 
Reported: 2010-02-16 19:37 EST by Vincent Danen
Modified: 2010-12-20 13:37 EST (History)
3 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2010-12-20 13:37:48 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:


Attachments (Terms of Use)

  None (edit)
Description Vincent Danen 2010-02-16 19:37:01 EST
Security researcher Orlando Barrera II reported via TippingPoint's Zero Day
Initiative that Mozilla's implementation of Web Workers contained an error in
its handling of array data types when processing posted messages. This error
could be used by an attacker to corrupt heap memory and crash the browser,
potentially running arbitrary code on a victim's computer.
Comment 2 errata-xmlrpc 2010-02-17 16:15:09 EST
This issue has been addressed in following products:

  Red Hat Enterprise Linux 4
  Red Hat Enterprise Linux 5

Via RHSA-2010:0112 https://rhn.redhat.com/errata/RHSA-2010-0112.html
Comment 3 Fedora Update System 2010-02-18 05:07:51 EST
firefox-3.5.8-1.fc12,xulrunner-1.9.1.8-1.fc12 has been submitted as an update for Fedora 12.
http://admin.fedoraproject.org/updates/firefox-3.5.8-1.fc12,xulrunner-1.9.1.8-1.fc12
Comment 4 Fedora Update System 2010-02-18 10:18:16 EST
gnome-python2-extras-2.25.3-16.fc12,perl-Gtk2-MozEmbed-0.08-6.fc12.11,blam-1.8.5-22.fc12,gnome-web-photo-0.9-5.fc12,mozvoikko-1.0-8.fc12,firefox-3.5.8-1.fc12,xulrunner-1.9.1.8-1.fc12 has been submitted as an update for Fedora 12.
http://admin.fedoraproject.org/updates/gnome-python2-extras-2.25.3-16.fc12,perl-Gtk2-MozEmbed-0.08-6.fc12.11,blam-1.8.5-22.fc12,gnome-web-photo-0.9-5.fc12,mozvoikko-1.0-8.fc12,firefox-3.5.8-1.fc12,xulrunner-1.9.1.8-1.fc12
Comment 5 Fedora Update System 2010-02-18 10:27:38 EST
gnome-python2-extras-2.25.3-16.fc12,perl-Gtk2-MozEmbed-0.08-6.fc12.11,blam-1.8.5-22.fc12,gnome-web-photo-0.9-5.fc12,mozvoikko-1.0-8.fc12,firefox-3.5.8-1.fc12,xulrunner-1.9.1.8-1.fc12 has been submitted as an update for Fedora 12.
http://admin.fedoraproject.org/updates/gnome-python2-extras-2.25.3-16.fc12,perl-Gtk2-MozEmbed-0.08-6.fc12.11,blam-1.8.5-22.fc12,gnome-web-photo-0.9-5.fc12,mozvoikko-1.0-8.fc12,firefox-3.5.8-1.fc12,xulrunner-1.9.1.8-1.fc12
Comment 6 Fedora Update System 2010-02-18 10:27:47 EST
gnome-python2-extras-2.25.3-16.fc12,perl-Gtk2-MozEmbed-0.08-6.fc12.11,blam-1.8.5-22.fc12,gnome-web-photo-0.9-5.fc12,mozvoikko-1.0-8.fc12,firefox-3.5.8-1.fc12,xulrunner-1.9.1.8-1.fc12 has been submitted as an update for Fedora 12.
http://admin.fedoraproject.org/updates/gnome-python2-extras-2.25.3-16.fc12,perl-Gtk2-MozEmbed-0.08-6.fc12.11,blam-1.8.5-22.fc12,gnome-web-photo-0.9-5.fc12,mozvoikko-1.0-8.fc12,firefox-3.5.8-1.fc12,xulrunner-1.9.1.8-1.fc12
Comment 7 Fedora Update System 2010-02-18 10:30:12 EST
galeon-2.0.7-20.fc12,gnome-python2-extras-2.25.3-16.fc12,perl-Gtk2-MozEmbed-0.08-6.fc12.11,blam-1.8.5-22.fc12,gnome-web-photo-0.9-5.fc12,mozvoikko-1.0-8.fc12,firefox-3.5.8-1.fc12,xulrunner-1.9.1.8-1.fc12 has been submitted as an update for Fedora 12.
http://admin.fedoraproject.org/updates/galeon-2.0.7-20.fc12,gnome-python2-extras-2.25.3-16.fc12,perl-Gtk2-MozEmbed-0.08-6.fc12.11,blam-1.8.5-22.fc12,gnome-web-photo-0.9-5.fc12,mozvoikko-1.0-8.fc12,firefox-3.5.8-1.fc12,xulrunner-1.9.1.8-1.fc12
Comment 8 Fedora Update System 2010-02-18 11:40:42 EST
chmsee-1.0.1-15.fc11,epiphany-2.26.3-8.fc11,blam-1.8.5-18.fc11,pcmanx-gtk2-0.3.9-2.20100210svn.fc11,galeon-2.0.7-20.fc11,hulahop-0.4.9-12.fc11,eclipse-3.4.2-20.fc11,evolution-rss-0.1.4-10.fc11,gnome-web-photo-0.7-10.fc11,gnome-python2-extras-2.25.3-11.fc11,monodevelop-2.0-9.fc11,Miro-2.5.4-2.fc11,kazehakase-0.5.8-5.fc11,mozvoikko-0.9.7-0.11.rc1.fc11,google-gadgets-0.11.1-5.fc11,perl-Gtk2-MozEmbed-0.08-6.fc11.9,ruby-gnome2-0.19.3-6.fc11,yelp-2.26.0-11.fc11,epiphany-extensions-2.26.1-10.fc11,firefox-3.5.8-1.fc11,xulrunner-1.9.1.8-1.fc11 has been submitted as an update for Fedora 11.
http://admin.fedoraproject.org/updates/chmsee-1.0.1-15.fc11,epiphany-2.26.3-8.fc11,blam-1.8.5-18.fc11,pcmanx-gtk2-0.3.9-2.20100210svn.fc11,galeon-2.0.7-20.fc11,hulahop-0.4.9-12.fc11,eclipse-3.4.2-20.fc11,evolution-rss-0.1.4-10.fc11,gnome-web-photo-0.7-10.fc11,gnome-python2-extras-2.25.3-11.fc11,monodevelop-2.0-9.fc11,Miro-2.5.4-2.fc11,kazehakase-0.5.8-5.fc11,mozvoikko-0.9.7-0.11.rc1.fc11,google-gadgets-0.11.1-5.fc11,perl-Gtk2-MozEmbed-0.08-6.fc11.9,ruby-gnome2-0.19.3-6.fc11,yelp-2.26.0-11.fc11,epiphany-extensions-2.26.1-10.fc11,firefox-3.5.8-1.fc11,xulrunner-1.9.1.8-1.fc11
Comment 10 Fedora Update System 2010-02-19 19:13:00 EST
seamonkey-2.0.3-1.fc12 has been pushed to the Fedora 12 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 11 Fedora Update System 2010-02-19 19:14:01 EST
firefox-3.5.8-1.fc11, xulrunner-1.9.1.8-1.fc11, chmsee-1.0.1-15.fc11, epiphany-2.26.3-8.fc11, blam-1.8.5-18.fc11, pcmanx-gtk2-0.3.9-2.20100210svn.fc11, galeon-2.0.7-20.fc11, hulahop-0.4.9-12.fc11, eclipse-3.4.2-20.fc11, evolution-rss-0.1.4-10.fc11, gnome-web-photo-0.7-10.fc11, gnome-python2-extras-2.25.3-11.fc11, monodevelop-2.0-9.fc11, Miro-2.5.4-2.fc11, kazehakase-0.5.8-5.fc11, mozvoikko-0.9.7-0.11.rc1.fc11, google-gadgets-0.11.1-5.fc11, perl-Gtk2-MozEmbed-0.08-6.fc11.9, ruby-gnome2-0.19.3-6.fc11, yelp-2.26.0-11.fc11, epiphany-extensions-2.26.1-10.fc11 has been pushed to the Fedora 11 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 12 Fedora Update System 2010-02-19 19:28:22 EST
firefox-3.5.8-1.fc12, xulrunner-1.9.1.8-1.fc12, gnome-python2-extras-2.25.3-16.fc12, perl-Gtk2-MozEmbed-0.08-6.fc12.11, blam-1.8.5-22.fc12, gnome-web-photo-0.9-5.fc12, mozvoikko-1.0-8.fc12, galeon-2.0.7-20.fc12 has been pushed to the Fedora 12 stable repository.  If problems still persist, please make note of it in this bug report.

Note You need to log in before you can comment on or make changes to this bug.