Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:22698
HistoryOct 28, 2009 - 12:00 a.m.

Mozilla Foundation Security Advisory 2009-55

2009-10-2800:00:00
vulners.com
19

Mozilla Foundation Security Advisory 2009-55

Title: Crash in proxy auto-configuration regexp parsing
Impact: Moderate
Announced: October 27, 2009
Reporter: Marco C.
Products: Firefox, SeaMonkey

Fixed in: Firefox 3.5.4
Firefox 3.0.15
SeaMonkey 2.0
Description

Security researcher Marco C. reported a flaw in the parsing of regular expressions used in Proxy Auto-configuration (PAC) files. In certain cases this flaw could be used by an attacker to crash a victim's browser and run arbitrary code on their computer. Since this vulnerability requires the victim to have PAC configured in their environment with specific regular expresssions which can trigger the crash, the severity of the issue was determined to be moderate.
Workaround

Disable JavaScript until a version containing these fixes can be installed.
References

* https://bugzilla.mozilla.org/show_bug.cgi?id=500644
* CVE-2009-3372