82676 : Mozilla Multiple Product Use-after-free nsFrameList::FirstChild Function Absolutely Positioned Element Column Container Size Manipulation Remote Code Execution
Printer |
http://osvdb.org/82676 |
Email This
| Edit Vulnerability
Views This Week
Views All Time
Added to OSVDB
Last Modified
Modified (since 2008)
Percent Complete
9
499
12 months ago
4 months ago
2 times
100%
Timeline
Disclosure Date
2012-06-05
Description
Multiple Mozilla products contain a use-after-free flaw in the nsFrameList::FirstChild function. The issue is triggered when a remote attacker manipulates the size of a container within an absolutely position element inside of a column. This may allow a remote attacker cause a denial of service or to potentially execute arbitrary code.
Classification
Location:
Remote / Network Access
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Solution:
Upgrade
Exploit:
Exploit Unknown
Disclosure:
Vendor Verified,
Coordinated Disclosure
OSVDB:
Web Related
Solution
Upgrade Firefox or Thunderbird to version 13 or 10.0.5 for ESR, and SeaMonkey to version 2.10 or higher, as they have been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.