Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Mozilla Firefox / Seamonkey multiple security vulnerabilities

  Context IS Advisory - Autocomplete Data Theft in Mozilla Firefox

  iDefense Security Advisory 10.28.09: Mozilla Firefox GIF Color Map Parsing Buffer Overflow Vulnerability

  Secunia Research: Mozilla Firefox Floating Point Memory Allocation Vulnerability

  Mozilla Firefox 3.5.3 Local Download Manager Exploit

From:MOZILLA
Date:28.10.2009
Subject:Mozilla Foundation Security Advisory 2009-63

Mozilla Foundation Security Advisory 2009-63

Title: Upgrade media libraries to fix memory safety bugs
Impact: Critical
Announced: October 27, 2009
Reporter: Mozilla community and developers
Products: Firefox

Fixed in: Firefox 3.5.4
Description

Mozilla upgraded several third party libraries used in media rendering to address multiple memory safety and stability bugs identified by members of the Mozilla community. Some of the bugs discovered could potentially be used by an attacker to crash a victim's browser and execute arbitrary code on their computer. liboggz, libvorbis, and liboggplay were all upgraded to address these issues.

Audio and video capabilities were added in Firefox 3.5 so prior releases of Firefox were not affected.
References

Georgi Guninski reported a crash in liboggz.

   * liboggz bugs
   * CVE-2009-3377

Lucas Adamski, Matthew Gregan, David Keeler, and Dan Kaminsky reported crashes in libvorbis.

   * libvorbis bugs
   * CVE-2009-3379

Juan Becerra reported a crash in liboggplay.

   * https://bugzilla.mozilla.org/show_bug.cgi?id=500311
   * CVE-2009-3378

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server