MuPDF Plugin for Firefox is prone to an overflow condition. The 'pdfmoz_onmouse()' function in apps/mozilla/moz_main.c contains a boundary error, resulting in a stack-based buffer overflow. With a specially crafted web site, a context-dependent attacker can potentially execute arbitrary code.
Classification
Location:
Local / Remote,
Context Dependent
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Solution:
Discontinued Product
Exploit:
Exploit Private
Disclosure:
Coordinated Disclosure
OSVDB:
Web Related
Solution
The vendor has discontinued this product and therefore has no patch or upgrade that mitigates this problem. It is recommended that an alternate software package be used in its place.