PT-2009-6652 · Mozilla+1 · Thunderbird+6

Olli Pettay

+1

·

Publicado

1970-01-01

·

Atualizado

2018-10-30

·

CVE-2009-2462

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 3.0.12 Thunderbird (affected versions not specified) libmozjs1d-dbg (affected versions not specified) libmozjs1d (affected versions not specified) libmozjs-dev (affected versions not specified) libmozillainterfaces-java (affected versions not specified)
Description The issue allows remote attackers to cause a denial of service or possibly execute arbitrary code via various vectors related to the browser engine, including the frame chain, synchronous events, and other components. Exploitation of the vulnerabilities may lead to disruption of confidentiality, integrity, and availability of protected information. The vulnerabilities can be exploited remotely.
Recommendations For Mozilla Firefox versions prior to 3.0.12, update to version 3.0.12 or later. For Thunderbird, libmozjs1d-dbg, libmozjs1d, libmozjs-dev, and libmozillainterfaces-java, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-01736
BDU:2015-01737
BDU:2015-01738
BDU:2015-01739
CVE-2009-2462
DSA-1840-1
RHSA-2009:1162
RHSA-2009:1163
RHSA-2009_1162
RHSA-2009_1163
RHSA-2010:0153
RHSA-2010:0154
RHSA-2010_0153
RHSA-2010_0154

Produtos afetados

Firefox
Red Hat
Thunderbird
Libmozillainterfaces-Java
Libmozjs-Dev
Libmozjs1D
Libmozjs1D-Dbg