PT-2006-1367 · Mozilla+1 · Firefox+1
Igor Bukanov
·
Published
2006-02-02
·
Updated
2018-10-19
·
CVE-2006-0293
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Firefox version 1.5
Description
The issue is related to the function allocation code in Firefox, specifically the js NewFunction in jsfun.c, which allows attackers to cause a denial of service and possibly execute arbitrary code. This is achieved through user-defined methods that trigger garbage collection in a way that operates on freed objects.
Recommendations
For Firefox version 1.5, consider disabling the js NewFunction until a patch is available. Restrict the use of user-defined methods that could trigger garbage collection to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Firefox
Hp-Ux