PT-2015-1143 · Mozilla+2 · Firefox+2

Robert Kaiser

·

Publicado

2015-04-20

·

Atualizado

2024-12-12

·

CVE-2015-2706

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 37.0.2
Description The issue is related to a race condition in the AsyncPaintWaitEvent::AsyncPaintWaitEvent function. This allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via a crafted plugin that does not properly complete initialization.
Recommendations For versions prior to 37.0.2, update to version 37.0.2 or later to resolve the issue. As a temporary workaround, consider disabling the use of plugins that do not properly complete initialization until a patch is available. Restrict access to potentially vulnerable plugins to minimize the risk of exploitation.

Exploit

Correção

RCE

DoS

Race Condition

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2015-1406
ALT-PU-2015-1464
BDU:2015-10028
CVE-2015-2706
MGASA-2015-0342
OPENSUSE-SU-2024:10071-1
OPENSUSE-SU-2024:14572-1
USN-2571-1

Produtos afetados

Alt Linux
Firefox
Ubuntu