PT-2010-1151 · Mozilla+2 · Thunderbird+4

Published

2010-10-19

·

Updated

2024-12-12

·

CVE-2010-3179

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 3.5.14 Mozilla Firefox versions 3.6.x prior to 3.6.11 Thunderbird versions prior to 3.0.9 Thunderbird versions 3.1.x prior to 3.1.5 SeaMonkey versions prior to 2.0.9
Description The issue is caused by a stack-based buffer overflow in the text-rendering functionality, allowing remote attackers to execute arbitrary code or cause a denial of service via a long argument to the document.write method. This can result in memory corruption and application crash.
Recommendations For Mozilla Firefox versions prior to 3.5.14, update to version 3.5.14 or later. For Mozilla Firefox versions 3.6.x prior to 3.6.11, update to version 3.6.11 or later. For Thunderbird versions prior to 3.0.9, update to version 3.0.9 or later. For Thunderbird versions 3.1.x prior to 3.1.5, update to version 3.1.5 or later. For SeaMonkey versions prior to 2.0.9, update to version 2.0.9 or later. As a temporary workaround, consider restricting the use of the document.write method until a patch is available.

Exploit

Fix

DoS

RCE

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-02230
CVE-2010-3179
DSA-2124-1
OPENSUSE-SU-2014_1100-1
OPENSUSE-SU-2024:10071-1
OPENSUSE-SU-2024:10230-1
OPENSUSE-SU-2024:14572-1
RHSA-2010:0782
RHSA-2010:0861
RHSA-2010:0896
RHSA-2010_0782
RHSA-2010_0861
RHSA-2010_0896

Affected Products

Firefox
Red Hat
Seamonkey
Suse
Thunderbird