Apr 23 2008

Profile Image of MuZumbu
MuZumbu

Highly critical Vulnerability in Mozilla Firefox Javascript Garbage

Posted at 11:14 am under Secunia

Secunia Advisory: SA29787
Release Date: 2008-04-17
Last Update: 2008-04-21
Critical:
Highly critical
Impact: DoS
System access
Where: From remote
Solution Status: Vendor Patch
Software: Mozilla Firefox 2.0.x
CVE reference: CVE-2008-1380 (Secunia mirror)
Description:
A vulnerability has been reported in Mozilla Firefox, which can potentially be exploited by malicious people to compromise a user’s system.

The vulnerability is caused due to an error in the Javascript Garbage Collector and can be exploited to cause a memory corruption via specially crafted Javascript code.

Successful exploitation may allow execution of arbitrary code.

The vulnerability is reported in version 2.0.0.13. Prior versions may also be affected.

Do you have this product installed on your home computer? Scan using the free Personal Software Inspector. Check if a vulnerable version is installed on computers in your corporate network, using the Network Software Inspector.

Solution:
Update to version 2.0.0.14.
http://www.mozilla.com/en-US/firefox/

Provided and/or discovered by:
Reported by the vendor.

No responses yet

Trackback URI | Comments RSS

Leave a Reply

You must be logged in to post a comment.

"