Executive Summary

Summary
TitleNew icedove/iceweasel packages fix regression
Informations
NameDSA-2457First vendor Publication2012-04-24
VendorDebianLast vendor Modification2012-05-13
Severity (Vendor) N/ARevision2

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:C/I:C/A:C)
Cvss Base Score10Attack RangeNetwork
Cvss Impact Score10Attack ComplexityLow
Cvss Expoit Score10AuthentificationNone Required
Calculate full CVSS 2.0 Vectors scores

Detail

The updates DSA-2457 and DSA-2458 for Iceweasel and Icedove introduced a regression, which could lead to crashes when interpreting some Javascript statements.

For the stable distribution (squeeze), this problem has been fixed in version 3.5.16-15 for Iceweasel and 2.0.11-12 for Icedove.

The unstable distribution (sid) is not affected.

We recommend that you upgrade your iceweasel and icedove packages.

Original Source

Url : http://www.debian.org/security/2012/dsa-2457

CWE : Common Weakness Enumeration

idName
CWE-79Failure to Preserve Web Page Structure ('Cross-site Scripting')
CWE-119Failure to Constrain Operations within the Bounds of a Memory Buffer

CPE : Common Platform Enumeration

TypeDescriptionCount
Application29
Application4
Application113
Application15
Application5