Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Mozilla Firefox / Thunderbird / SeaMonkey multiple security vulnerabilities

  New writeup by Amit Klein (Trusteer): "Cross-domain information leakage in Firefox 3.6.4-3.6.8, Firefox 3.5.10-3.5.11 and Firefox 4.0 Beta1"

  ZDI-10-176: Mozilla Firefox normalizeDocument Remote Code Execution Vulnerability

  ZDI-10-171: Mozilla Firefox nsTreeContentView Dangling Pointer Remote Code Execution Vulnerability

  ZDI-10-172: Mozilla Firefox tree Object Removal Remote Code Execution Vulnerability

From:MOZILLA
Date:10.09.2010
Subject:Mozilla Foundation Security Advisory 2010-55

Mozilla Foundation Security Advisory 2010-55

Title: XUL tree removal crash and remote code execution
Impact: Low (Critical in Gecko 1.9.1 and earlier)
Announced: September 7, 2010
Reporter: regenrecht
Products: Firefox, Thunderbird, SeaMonkey

Fixed in: Firefox 3.6.9
 Firefox 3.5.12
 Thunderbird 3.1.3
 Thunderbird 3.0.7
 SeaMonkey 2.0.7
Description

Security researcher regenrecht reported via TippingPoint's Zero Day Initiative that XUL <tree> objects could be manipulated such that the setting of certain properties on the object would trigger the removal of the tree from the DOM and cause certain sections of deleted memory to be accessed. In products based on Gecko version 1.9.2 (Firefox 3.6, Thunderbird 3.1) and newer this memory has been overwritten by a value that will cause an unexploitable crash. In products based on Gecko version 1.9.1 (Firefox 3.5, Thunderbird 3.0, and SeaMonkey 2.0) and older an attacker could potentially use this vulnerability to crash a victim's browser and run arbitrary code on their computer.
References

   * https://bugzilla.mozilla.org/show_bug.cgi?id=576075
   * CVE-2010-3168

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru