PT-2006-1367 · Mozilla+1 · Firefox+1
Igor Bukanov
·
Publicado
2006-02-02
·
Atualizado
2018-10-19
·
CVE-2006-0293
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Firefox version 1.5
Description
The issue is related to the function allocation code in Firefox, specifically the js NewFunction in jsfun.c, which allows attackers to cause a denial of service and possibly execute arbitrary code. This is achieved through user-defined methods that trigger garbage collection in a way that operates on freed objects.
Recommendations
For Firefox version 1.5, consider disabling the js NewFunction until a patch is available. Restrict the use of user-defined methods that could trigger garbage collection to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Firefox
Hp-Ux