|
|
|
Vulnerability Note VU#655892Mozilla JavaScript engine contains multiple integer overflowsOverviewThe Mozilla JavaScript engine contains multiple integer overflows. This vulnerability may allow a remote attacker to execute arbitrary code on a vulnerable system.I. DescriptionMozilla products that use the Mozilla JavaScript engine are vulnerable to integer overflows. Specifically, the JavaScript toSource() fails to properly handle malformed strings.For more information and a complete list of affected products refer to Mozilla Foundation Security Advisory 2006-50.
This vulnerability is addressed in Firefox 1.5.0.5, Thunderbird 1.5.0.5, and SeaMonkey 1.0.3 according to the Mozilla Foundation Security Update 2006-50.
References
This vulnerability was reported in Mozilla Foundation Security Advisory 2006-50. Mozilla credits Georgi Guninski with reporting this vulnerability. This document was written by Jeff Gennari.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||
|
||||||||||||||||||||||||||||||||||||