PT-2009-6652 · Mozilla+1 · Thunderbird+6

Olli Pettay

+1

·

Published

1970-01-01

·

Updated

2018-10-30

·

CVE-2009-2462

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 3.0.12 Thunderbird (affected versions not specified) libmozjs1d-dbg (affected versions not specified) libmozjs1d (affected versions not specified) libmozjs-dev (affected versions not specified) libmozillainterfaces-java (affected versions not specified)
Description The issue allows remote attackers to cause a denial of service or possibly execute arbitrary code via various vectors related to the browser engine, including the frame chain, synchronous events, and other components. Exploitation of the vulnerabilities may lead to disruption of confidentiality, integrity, and availability of protected information. The vulnerabilities can be exploited remotely.
Recommendations For Mozilla Firefox versions prior to 3.0.12, update to version 3.0.12 or later. For Thunderbird, libmozjs1d-dbg, libmozjs1d, libmozjs-dev, and libmozillainterfaces-java, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-01736
BDU:2015-01737
BDU:2015-01738
BDU:2015-01739
CVE-2009-2462
DSA-1840-1
RHSA-2009:1162
RHSA-2009:1163
RHSA-2009_1162
RHSA-2009_1163
RHSA-2010:0153
RHSA-2010:0154
RHSA-2010_0153
RHSA-2010_0154

Affected Products

Firefox
Red Hat
Thunderbird
Libmozillainterfaces-Java
Libmozjs-Dev
Libmozjs1D
Libmozjs1D-Dbg