Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Mozilla Firefox / Thunderbird / Seamonkey multiple security vulnerabilities

  ZDI-11-103: Mozilla Firefox JSON.stringify Dangling Pointer Remote Code Execution Vulnerability

  Mozilla Foundation Security Advisory 2011-10

  Mozilla Foundation Security Advisory 2011-09

  Mozilla Foundation Security Advisory 2011-08

From:MOZILLA
Date:03.03.2011
Subject:Mozilla Foundation Security Advisory 2011-03

Mozilla Foundation Security Advisory 2011-03

Title: Use-after-free error in JSON.stringify
Impact: Critical
Announced: March 1, 2011
Reporter: regenrecht
Products: Firefox, SeaMonkey

Fixed in: Firefox 3.6.14
 Firefox 3.5.17
 SeaMonkey 2.0.12
Description

Security researcher regenrecht reported via TippingPoint's Zero Day Initiative that a method used by JSON.stringify contained a use-after-free error in which a currently in-use pointer was freed and subsequently dereferenced. This could lead to arbitrary code execution if an attacker was able to store malicious code in the freed section of memory.

Mozilla developer Igor Bukanov also independently discovered and reported this issue two weeks after the initial report was received.
References

   * JSON.stringify dangling pointer bugs
   * CVE-2011-0055

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru