Multiple Mozilla products contain a flaw related to the texImage2D() function in WebGL. The issue is triggered when an unspecified error occurs when using JSVAL_TO_OBJECT, which may allow a remote attacker to execute arbitrary code.
Classification
Location:
Remote / Network Access,
Context Dependent
Attack Type:
Input Manipulation
Impact:
Loss of Integrity,
Loss of Availability
Solution:
Upgrade
Exploit:
Exploit Private
Disclosure:
Vendor Verified,
Coordinated Disclosure
OSVDB:
Web Related
Solution
Upgrade Firefox and Thunderbird to version 12.0 or higher (10.0.4 for ESR) and SeaMonkey to version 2.9 or higher, as they have been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.