PT-2011-4236 · Mozilla+1 · Firefox+1

Mark Kaplan

·

Published

2011-09-28

·

Updated

2017-09-19

·

CVE-2011-2998

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions 3.6.x through 3.6.22
Description The issue is caused by an integer underflow in JavaScript code containing a large RegExp expression, which allows remote attackers to cause a denial of service or possibly execute arbitrary code.
Recommendations For Mozilla Firefox versions 3.6.x through 3.6.22, update to version 3.6.23 or later to resolve the issue.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-2998
DSA-2312-1
DSA-2313-1
DSA-2317-1
RHSA-2011:1341
RHSA-2011:1342
RHSA-2011:1343
RHSA-2011:1344
RHSA-2011_1341
RHSA-2011_1342
RHSA-2011_1343
RHSA-2011_1344

Affected Products

Firefox
Red Hat