|
|
|
![]() |
Vulnerability Note VU#239124Mozilla fails to properly handle simultaneous XPCOM eventsOverviewMozilla products are vulnerable to memory corruption via simultaneous XPCOM events. This may allow a remote attacker to execute arbitrary code on a vulnerable system.I. DescriptionXPCOMXPCOM is a cross-platform component object model similar to Microsoft COM or CORBA. XPCOM provides the following features to software developers:
XPCOM events that occur simultaneously can trigger the use of a deleted timer object, which can cause memory corruption. II. ImpactA remote, unauthenticated attacker may be able to execute arbitrary code on a vulnerable system. The attacker could also cause the vulnerable application to crash.III. SolutionApply an updateThis vulnerability is addressed in Firefox 1.5.0.5, Thunderbird 1.5.0.5, and SeaMonkey 1.0.3 according to the Mozilla Foundation Security Update 2006-46.
References
This vulnerability was reported by the Mozilla Foundation, who in turn credit Secunia Research. This document was written by Will Dormann.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||||||||