PT-2008-5371 · Mozilla+2 · Firefox+2

Published

2008-09-24

·

Updated

2024-12-12

·

CVE-2008-4063

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 3.0.2
Description The issue is related to multiple unspecified vulnerabilities in the layout engine of Mozilla Firefox. These vulnerabilities can be exploited by remote attackers to cause a denial of service, resulting in memory corruption and application crash, or possibly execute arbitrary code. The vulnerabilities are related to specific vectors, including the nsContentList::Item function when the this variable has a zero value, interaction of the indic IME extension with a Hindi language selection and the "g" character, and interaction of the nsFrameList::SortByContentOrder function with insufficient protection of inline frames.
Recommendations For versions prior to 3.0.2, update to version 3.0.2 or later to resolve the issue. As a temporary workaround, consider disabling the indic IME extension and avoiding the use of the "g" character with Hindi language selection until a patch is available. Restrict access to inline frames to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2008-4063
DSA-1669-1
OPENSUSE-SU-2014_1100-1
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:14572-1
RHSA-2008:0879
RHSA-2008_0879

Affected Products

Firefox
Red Hat
Suse