CVE-2011-0084
Publication date 17 August 2011
Last updated 24 July 2024
Ubuntu priority
Description
The SVGTextElement.getCharNumAtPosition function in Mozilla Firefox before 3.6.20, and 4.x through 5; Thunderbird 3.x before 3.1.12 and other versions before 6; SeaMonkey 2.x before 2.3; and possibly other products does not properly handle SVG text, which allows remote attackers to execute arbitrary code via unspecified vectors that lead to a "dangling pointer."
Status
| Package | Ubuntu Release | Status | 
|---|---|---|
| firefox | ||
| firefox-3.0 | ||
| firefox-3.5 | ||
| seamonkey | ||
| thunderbird | ||
| xulrunner-1.9.2 | ||
| xulrunner-2.0 | ||
References
Related Ubuntu Security Notices (USN)
- USN-1185-1
 - Thunderbird vulnerabilities
 - 26 August 2011
 - USN-1192-1
 - Firefox vulnerabilities
 - 17 August 2011
 - USN-1184-1
 - Firefox and Xulrunner vulnerabilities
 - 19 August 2011