PT-2010-1151 · Mozilla+2 · Thunderbird+4

Publicado

2010-10-19

·

Atualizado

2024-12-12

·

CVE-2010-3179

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 3.5.14 Mozilla Firefox versions 3.6.x prior to 3.6.11 Thunderbird versions prior to 3.0.9 Thunderbird versions 3.1.x prior to 3.1.5 SeaMonkey versions prior to 2.0.9
Description The issue is caused by a stack-based buffer overflow in the text-rendering functionality, allowing remote attackers to execute arbitrary code or cause a denial of service via a long argument to the document.write method. This can result in memory corruption and application crash.
Recommendations For Mozilla Firefox versions prior to 3.5.14, update to version 3.5.14 or later. For Mozilla Firefox versions 3.6.x prior to 3.6.11, update to version 3.6.11 or later. For Thunderbird versions prior to 3.0.9, update to version 3.0.9 or later. For Thunderbird versions 3.1.x prior to 3.1.5, update to version 3.1.5 or later. For SeaMonkey versions prior to 2.0.9, update to version 2.0.9 or later. As a temporary workaround, consider restricting the use of the document.write method until a patch is available.

Exploit

Correção

DoS

RCE

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-02230
CVE-2010-3179
DSA-2124-1
OPENSUSE-SU-2014_1100-1
OPENSUSE-SU-2024:10071-1
OPENSUSE-SU-2024:10230-1
OPENSUSE-SU-2024:14572-1
RHSA-2010:0782
RHSA-2010:0861
RHSA-2010:0896
RHSA-2010_0782
RHSA-2010_0861
RHSA-2010_0896

Produtos afetados

Firefox
Red Hat
Seamonkey
Suse
Thunderbird