Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Mozilla Firefox / Seamonkey multiple security vulnerabilities

  Context IS Advisory - Autocomplete Data Theft in Mozilla Firefox

  iDefense Security Advisory 10.28.09: Mozilla Firefox GIF Color Map Parsing Buffer Overflow Vulnerability

  Secunia Research: Mozilla Firefox Floating Point Memory Allocation Vulnerability

  Mozilla Firefox 3.5.3 Local Download Manager Exploit

From:MOZILLA
Date:28.10.2009
Subject:Mozilla Foundation Security Advisory 2009-55

Mozilla Foundation Security Advisory 2009-55

Title: Crash in proxy auto-configuration regexp parsing
Impact: Moderate
Announced: October 27, 2009
Reporter: Marco C.
Products: Firefox, SeaMonkey

Fixed in: Firefox 3.5.4
 Firefox 3.0.15
 SeaMonkey 2.0
Description

Security researcher Marco C. reported a flaw in the parsing of regular expressions used in Proxy Auto-configuration (PAC) files. In certain cases this flaw could be used by an attacker to crash a victim's browser and run arbitrary code on their computer. Since this vulnerability requires the victim to have PAC configured in their environment with specific regular expresssions which can trigger the crash, the severity of the issue was determined to be moderate.
Workaround

Disable JavaScript until a version containing these fixes can be installed.
References

   * https://bugzilla.mozilla.org/show_bug.cgi?id=500644
   * CVE-2009-3372

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server