Skip to main content

Mozilla Products Multiple Vulnerabilities

Last Update Date: 28 Jan 2011 Release Date: 21 Oct 2010 4700 Views

RISK: Medium Risk

Multiple vulnerabilities have been identified in Mozilla Firefox, Thunderbird and SeaMonkey, which could be exploited by attackers to manipulate or disclose certain data, bypass security restrictions or compromise a vulnerable system.

1. Due to memory corruption errors in the browser engine when parsing malformed data, which could be exploited by attackers to crash a vulnerable browser or execute arbitrary code.

2. Due to buffer overflow and memory corruption errors when processing overly long data passed to "document.write()", which could be exploited by remote attackers to compromise a vulnerable system.

3. Due to a use-after-free error in "nsBarProp" when accessing the "locationbar" property of a "window" object after it had been closed, which could be exploited by remote attackers to compromise a vulnerable system.

4. Due to a dangling pointer in "LookupGetterOrSetter" when "window.__lookupGetter__" is called without arguments, which could be exploited by remote attackers to compromise a vulnerable system.

5. Due to an input validation error in the Gopher parser when processing certain text, which could allow cross site scripting attacks.

6. Due to an error when handling modal call, which could allow attackers to bypass same-origin policy and conduct cross-dmain scripting attacks.

7. Due to an error when handling SSL certificates, which could allow spoofing attacks via MitM attacks.

8. Due to errors when loading libraries on Windows and Linux, which could allow attackers or malicious users to load malicious librairies.

9. Due to the SSL implementation permitting servers to use Diffie-Hellman Ephemeral mode (DHE) with insecure keys, which could be exploited to guess the keys.


Impact

  • Remote Code Execution
  • Security Restriction Bypass
  • Information Disclosure

System / Technologies affected

  • Mozilla Firefox versions prior to 3.6.11
  • Mozilla Firefox versions prior to 3.5.14
  • Mozilla Thunderbird versions prior to 3.1.5
  • Mozilla Thunderbird versions prior to 3.0.9
  • Mozilla SeaMonkey versions prior to 2.0.9

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link