PT-2010-1980 · Mozilla · Firefox

Jesse Ruderman

·

Publicado

2010-03-25

·

Atualizado

2024-06-15

·

CVE-2010-0166

CVSS v2.0

5.1

Média

VetorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 3.6.2
Description The issue is related to the gfxTextRun::SanitizeGlyphRuns function in the browser engine, specifically when the Core Text API is used on Mac OS X. It does not properly handle certain deletions, which can be exploited by remote attackers using an HTML document containing invisible Unicode characters, such as U+FEFF, U+FFF9, U+FFFA, and U+FFFB. This can lead to a denial of service due to memory corruption and application crash, and potentially allow the execution of arbitrary code.
Recommendations For Mozilla Firefox versions prior to 3.6.2, update to version 3.6.2 or later to resolve the issue.

Exploit

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-0166
OPENSUSE-SU-2024:10071-1

Produtos afetados

Firefox