|
|
|
Vulnerability Note VU#141528Mozilla products fail to properly handle JavaScript regular expressionsOverviewMozilla products fail to properly handle certain JavaScript regular expressions. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary code or cause a denial-of-service condition.I. DescriptionAccording to Mozilla Foundation Security Advisory 2006-57:...a regular expression that ends with a backslash inside an unterminated character set (e.g. "[\\") will cause the regular epression engine to read beyond the end of the buffer, possibly leading to a crash. Note that this issue affects Mozilla Firefox, Thunderbird, and SeaMonkey. II. ImpactA remote, unauthenticated attacker may be able to execute arbitrary code or cause a denial-of-service condition.III. SolutionUpgradeThis issue is addressed by Firefox 1.5.0.7, Thunderbird 1.5.0.7, and SeaMonkey 1.0.5.
References
This issue was reported in Mozilla Foundation Security Advisory 2006-57. Mozilla credits Priit Laes, CanadianGuy, Girts Folkmanis, and Catalin Patulea for reporting this issue. This document was written by Chris Taschner.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
||||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||