PT-2010-4267 · Mozilla+2 · Firefox+4

Reed

·

Publicado

2010-07-20

·

Atualizado

2024-12-12

·

CVE-2010-2753

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions 3.5.x through 3.5.10 Mozilla Firefox versions 3.6.x through 3.6.6 Thunderbird versions 3.0.x through 3.0.5 Thunderbird versions 3.1.x through 3.1.0 SeaMonkey version 2.0.5 and earlier
Description The issue allows remote attackers to execute arbitrary code via a large selection attribute in a XUL tree element, which triggers a use-after-free. This occurs due to an integer overflow in the affected software.
Recommendations For Mozilla Firefox versions 3.5.x through 3.5.10, update to version 3.5.11 or later. For Mozilla Firefox versions 3.6.x through 3.6.6, update to version 3.6.7 or later. For Thunderbird versions 3.0.x through 3.0.5, update to version 3.0.6 or later. For Thunderbird versions 3.1.x through 3.1.0, update to version 3.1.1 or later. For SeaMonkey version 2.0.5 and earlier, update to version 2.0.6 or later.

Exploit

Correção

RCE

Integer Overflow

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-2753
DSA-2075-1
OPENSUSE-SU-2014_1100-1
OPENSUSE-SU-2024:10071-1
OPENSUSE-SU-2024:10230-1
OPENSUSE-SU-2024:14572-1
RHSA-2010:0544
RHSA-2010:0545
RHSA-2010:0546
RHSA-2010:0547
RHSA-2010_0544
RHSA-2010_0545
RHSA-2010_0546
RHSA-2010_0547
ZDI-10-131

Produtos afetados

Firefox
Red Hat
Seamonkey
Suse
Thunderbird