PT-2011-4561 · Mozilla+2 · Firefox+4

Published

2011-11-08

·

Updated

2024-12-12

·

CVE-2011-3650

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions 4.x through 7.0 Mozilla Firefox version 3.6.24 and earlier Thunderbird versions 5.0 through 7.0 Thunderbird version 3.1.6 and earlier
Description The issue arises from improper handling of certain JavaScript files containing numerous functions. This allows remote attackers, assisted by a local user, to cause a denial of service through memory corruption and application crash. It is also possible for attackers to have an unspecified impact via a crafted file accessed by debugging APIs, as demonstrated by Firebug.
Recommendations For Mozilla Firefox versions 4.x through 7.0, update to a version later than 7.0 to resolve the issue. For Mozilla Firefox version 3.6.24 and earlier, update to version 3.6.24 or later to mitigate the risk. For Thunderbird versions 5.0 through 7.0, update to a version later than 7.0 to resolve the issue. For Thunderbird version 3.1.6 and earlier, update to version 3.1.6 or later to mitigate the risk. As a temporary workaround, consider disabling the debugging APIs until a patch is available. Restrict access to the debugging APIs to minimize the risk of exploitation.

Exploit

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-3650
DSA-2341-1
DSA-2342-1
DSA-2345-1
OPENSUSE-SU-2014_1100-1
OPENSUSE-SU-2024:10071-1
OPENSUSE-SU-2024:10230-1
OPENSUSE-SU-2024:14572-1
RHSA-2011:1437
RHSA-2011:1439
RHSA-2011_1437
RHSA-2011_1439

Affected Products

Firebug
Firefox
Red Hat
Suse
Thunderbird