First published: Thu Mar 05 2009(Updated: )
The layout engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain vectors that trigger memory corruption and assertion failures.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla SeaMonkey | =1.1.10 | |
Mozilla SeaMonkey | =1.0.3 | |
Firefox | =2.0.0.12 | |
Thunderbird | =2.0.0.4 | |
Mozilla SeaMonkey | =1.1.8 | |
Mozilla SeaMonkey | =1.0.1 | |
Mozilla SeaMonkey | =1.1.7 | |
Thunderbird | =2.0.0.6 | |
Mozilla SeaMonkey | =1.0.6 | |
Firefox | =1.5.0.6 | |
Mozilla SeaMonkey | =1.0.9 | |
Mozilla SeaMonkey | <=1.1.14 | |
Mozilla SeaMonkey | =1.1.3 | |
Firefox | =2.0.0.2 | |
Firefox | =1.5.0.10 | |
Firefox | =1.5.0.3 | |
Mozilla SeaMonkey | =1.0 | |
Firefox | =1.5.0.11 | |
Thunderbird | =2.0.0.18 | |
Thunderbird | =2.0.0.9 | |
Mozilla SeaMonkey | =1.1.5 | |
Mozilla SeaMonkey | =1.0.7 | |
Firefox | =1.0.2 | |
Firefox | =3.0.4 | |
Mozilla SeaMonkey | =1.1-alpha | |
Thunderbird | =2.0.0.16 | |
Firefox | =3.0.5 | |
Firefox | =1.5 | |
Firefox | =1.0.4 | |
Firefox | =2.0.0.7 | |
Firefox | =1.0.7 | |
Mozilla SeaMonkey | =1.1.12 | |
Mozilla SeaMonkey | =1.1 | |
Firefox | =2.0.0.9 | |
Firefox | =2.0.0.16 | |
Thunderbird | <=2.0.0.20 | |
Firefox | =2.0.0.17 | |
Mozilla SeaMonkey | =1.1.2 | |
Firefox | =2.0.0.15 | |
Mozilla SeaMonkey | =1.0.2 | |
Mozilla SeaMonkey | =1.0.8 | |
Thunderbird | =2.0.0.0 | |
Mozilla SeaMonkey | =1.1.11 | |
Firefox | =1.0 | |
Firefox | =3.0.3 | |
Mozilla SeaMonkey | =1.1-beta | |
Mozilla SeaMonkey | =1.1.1 | |
Firefox | =1.5.0.7 | |
Thunderbird | =2.0.0.12 | |
Firefox | =2.0 | |
Firefox | =1.0.1 | |
Firefox | =2.0.0.14 | |
Mozilla SeaMonkey | =1.0.5 | |
Thunderbird | =2.0.0.14 | |
Firefox | =1.5.0.8 | |
Firefox | =2.0.0.3 | |
Firefox | =1.5.0.9 | |
Thunderbird | =2.0.0.17 | |
Firefox | =1.5.0.5 | |
Firefox | =1.5.0.12 | |
Firefox | =2.0.0.6 | |
Mozilla SeaMonkey | =1.1.6 | |
Firefox | =3.0 | |
Firefox | =2.0.0.11 | |
Firefox | =1.5.0.2 | |
Firefox | =1.0.3 | |
Firefox | =3.0.1 | |
Firefox | =2.0.0.4 | |
Firefox | =2.0.0.13 | |
Firefox | =2.0.0.18 | |
Firefox | <=3.0.6 | |
Firefox | =2.0.0.1 | |
Firefox | =3.0.2 | |
Thunderbird | =2.0.0.5 | |
Mozilla SeaMonkey | =1.1.9 | |
Mozilla SeaMonkey | =1.1.13 | |
Firefox | =2.0.0.20 | |
Firefox | =2.0.0.8 | |
Firefox | =2.0.0.19 | |
Firefox | =1.5.0.4 | |
Firefox | =1.5.0.1 | |
Firefox | =1.0.5 | |
Firefox | =2.0.0.5 | |
Firefox | =2.0.0.10 | |
Thunderbird | =2.0.0.19 | |
Firefox | =1.0.6 | |
Mozilla SeaMonkey | =1.1.4 | |
Firefox | =1.0.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-0771 is classified with a severity rating that indicates it can cause denial of service and may lead to arbitrary code execution.
To remediate CVE-2009-0771, upgrade your Mozilla Firefox, Thunderbird, or SeaMonkey to versions that are not affected, specifically versions 3.0.7 or newer for Firefox, 2.0.0.21 or newer for Thunderbird, and 1.1.15 or newer for SeaMonkey.
CVE-2009-0771 affects Mozilla Firefox versions 1.0 through 3.0.6, Thunderbird up to version 2.0.0.20, and SeaMonkey versions 1.0 through 1.1.14.
CVE-2009-0771 is a memory corruption vulnerability that can trigger crashes or potential arbitrary code execution.
Mitigations for CVE-2009-0771 include disabling the affected applications or ensuring users upgrade to the latest versions immediately.