PT-2007-4172 · Mozilla+1 · Firefox+3
Brendan Eich
+4
·
Published
2007-05-31
·
Updated
2018-10-16
·
CVE-2007-2868
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Mozilla Firefox versions 1.5.x through 1.5.0.11
Mozilla Firefox versions 2.x through 2.0.0.3
Mozilla Thunderbird versions 1.5.x through 1.5.0.11
Mozilla Thunderbird versions 2.x through 2.0.0.3
SeaMonkey version 1.0.9
SeaMonkey version 1.1.2
Description
The issue allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors that trigger memory corruption in the JavaScript engine.
Recommendations
For Mozilla Firefox versions 1.5.x through 1.5.0.11, update to version 1.5.0.12 or later.
For Mozilla Firefox versions 2.x through 2.0.0.3, update to version 2.0.0.4 or later.
For Mozilla Thunderbird versions 1.5.x through 1.5.0.11, update to version 1.5.0.12 or later.
For Mozilla Thunderbird versions 2.x through 2.0.0.3, update to version 2.0.0.4 or later.
For SeaMonkey version 1.0.9 and 1.1.2, update to a version that is not affected by this issue.
Fix
DoS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Firefox
Thunderbird
Red Hat
Seamonkey