Free and open-source vulnerability scanner
Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.
Install NowAvailable for macOS, Windows, and Linux
Mozilla Firefox Multiple Memory Corruption Vulnerabilities Aug-09 (Windows)
Information
Severity
Severity
Family
Family
CVSSv2 Base
CVSSv2 Base
CVSSv2 Vector
CVSSv2 Vector
Solution Type
Solution Type
Created
Created
Modified
Modified
Summary
This host is installed with Mozilla Firefox and is prone to multiple Memory Corruption vulnerabilities.
Insight
Insight
Multiple memory corruption are due to: - Error in 'js_watch_set()' function in js/src/jsdbgapi.cpp in the JavaScript engine which can be exploited via a crafted '.js' file. - Error in 'libvorbis()' which is used in the application can be exploited via a crafted '.ogg' file. - Error in 'TraceRecorder::snapshot()' function in js/src/jstracer.cpp and other unspecified vectors. - Error in 'window.open()' which fails to sanitise the invalid character in the crafted URL. This allows remote attackers to spoof the address bar, and possibly conduct phishing attacks, via a crafted web page that calls window.open with an invalid character in the URL, makes document.write calls to the resulting object, and then calls the stop method during the loading of the error page.
Affected Software
Affected Software
Firefox version before 3.0.13 or 3.5 before 3.5.2 on Windows.
Solution
Solution
Upgrade to Firefox version 3.0.13/3.5.2.