PT-2011-4236 · Mozilla+1 · Firefox+1

Mark Kaplan

·

Publicado

2011-09-28

·

Atualizado

2017-09-19

·

CVE-2011-2998

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions 3.6.x through 3.6.22
Description The issue is caused by an integer underflow in JavaScript code containing a large RegExp expression, which allows remote attackers to cause a denial of service or possibly execute arbitrary code.
Recommendations For Mozilla Firefox versions 3.6.x through 3.6.22, update to version 3.6.23 or later to resolve the issue.

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-2998
DSA-2312-1
DSA-2313-1
DSA-2317-1
RHSA-2011:1341
RHSA-2011:1342
RHSA-2011:1343
RHSA-2011:1344
RHSA-2011_1341
RHSA-2011_1342
RHSA-2011_1343
RHSA-2011_1344

Produtos afetados

Firefox
Red Hat