Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:24308
HistoryJul 24, 2010 - 12:00 a.m.

Mozilla Foundation Security Advisory 2010-35

2010-07-2400:00:00
vulners.com
20

Mozilla Foundation Security Advisory 2010-35

Title: DOM attribute cloning remote code execution vulnerability
Impact: Critical
Announced: July 20, 2010
Reporter: regenrecht (via TippingPoint's Zero Day Initiative)
Products: Firefox, SeaMonkey

Fixed in: Firefox 3.6.7
Firefox 3.5.11
SeaMonkey 2.0.6
Description

Security researcher regenrecht reported via TippingPoint's Zero Day Initiative an error in the DOM attribute cloning routine where under certain circumstances an event attribute node can be deleted while another object still contains a reference to it. This reference could subsequently be accessed, potentially causing the execution of attacker controlled memory.
References

* https://bugzilla.mozilla.org/show_bug.cgi?id=572986
* CVE-2010-1208