CVE-2012-0960

Publication date 22 November 2012

Last updated 24 July 2024


Ubuntu priority

Unity integration extension (unity-firefox-extension) before 2.4.1 for Firefox does not properly handle callbacks, which allows remote attackers to cause a denial of service (Firefox crash) and possibly execute arbitrary code via a crafted request.

Status

Package Ubuntu Release Status
unity-firefox-extension 12.10 quantal
Fixed 2.4.1-0ubuntu1.1
12.04 LTS precise Not in release
11.10 oneiric Not in release
10.04 LTS lucid Not in release
8.04 LTS hardy Not in release

References

Related Ubuntu Security Notices (USN)

    • USN-1639-1
    • unity-firefox-extension vulnerability
    • 22 November 2012

Other references