The browser engine in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, Thunderbird before 3.0.2, and SeaMonkey before 2.0.3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the nsBlockFrame::StealFrame function in layout/generic/nsBlockFrame.cpp, and unspecified other vectors.
| Software | From | Fixed in |
|---|---|---|
| mozilla / firefox | 3.0 | 3.0.18 |
| mozilla / firefox | 3.5 | 3.5.8 |
| mozilla / thunderbird | - | 3.0.2 |
| mozilla / seamonkey | - | 2.0.3 |
| debian / debian_linux | 5.0 | 5.0.x |
| canonical / ubuntu_linux | 9.04 | 9.04.x |
| canonical / ubuntu_linux | 8.04 | 8.04.x |
| canonical / ubuntu_linux | 8.10 | 8.10.x |
| canonical / ubuntu_linux | 9.10 | 9.10.x |