Mozilla Firefox, Thunderbird and SeaMonkey contain a use-after-free vulnerability related to the 'nsBarProp' function. This may allow a remote attacker to execute arbitrary code by accessing a closed window's locationbar property.
Classification
Location:
Remote / Network Access
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Solution:
Upgrade
Exploit:
Exploit Unknown
Disclosure:
Vendor Verified
OSVDB:
Web Related
Solution
Upgrade Firefox to version 3.6.11 or 3.5.14 or higher, Thunderbird to 3.1.5 or 3.0.9 or higher and SeaMonkey to 2.0.9 or higher, as they have been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.