Skip to main content

Mozilla Firefox DOM Insertion Remote Code Execution Vulnerability

Last Update Date: 28 Jan 2011 Release Date: 28 Oct 2010 4769 Views

RISK: Medium Risk

A vulnerability has been identified in Mozilla Firefox, Thunderbird and SeaMonkey, which could be exploited by malicious web sites to execute arbitrary code. This issue is caused by a memory corruption error when handling "document.write()" methods and DOM insertion, which could allow remote attackers to compromise a vulnerable system.

This vulnerability is exploited in the wild by the Belmoo malware.


Impact

  • Remote Code Execution

System / Technologies affected

  • Mozilla Firefox version 3.6.11 and prior
  • Mozilla Firefox version 3.5.14 and prior
  • Mozilla Thunderbird version 3.1.5 and prior
  • Mozilla Thunderbird version 3.0.9 and prior
  • Mozilla SeaMonkey version 2.0.9 and prior

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link