PT-2010-1980 · Mozilla · Firefox

Jesse Ruderman

·

Published

2010-03-25

·

Updated

2024-06-15

·

CVE-2010-0166

CVSS v2.0

5.1

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 3.6.2
Description The issue is related to the gfxTextRun::SanitizeGlyphRuns function in the browser engine, specifically when the Core Text API is used on Mac OS X. It does not properly handle certain deletions, which can be exploited by remote attackers using an HTML document containing invisible Unicode characters, such as U+FEFF, U+FFF9, U+FFFA, and U+FFFB. This can lead to a denial of service due to memory corruption and application crash, and potentially allow the execution of arbitrary code.
Recommendations For Mozilla Firefox versions prior to 3.6.2, update to version 3.6.2 or later to resolve the issue.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-0166
OPENSUSE-SU-2024:10071-1

Affected Products

Firefox