|
|
|
![]() |
Vulnerability Note VU#714496Mozilla products allow execution of arbitrary JavaScriptOverviewMultiple Mozilla products allow running JavaScript to be recompiled while executing. This vulnerability may allow a remote attacker to execute arbitrary JavaScript bytecode.I. DescriptionAccording to Mozilla Foundation Security Advisory 2006-67:...it was possible to modify a Script object while it was executing, potentially leading to the execution of arbitrary JavaScript bytecode. Note that this issue affects Mozilla Firefox, Thunderbird, and SeaMonkey. For more information refer to Mozilla Foundation Security Advisory 2006-67. II. ImpactA remote, unauthenticated attacker may be able to execute arbitrary JavaScript bytecode.III. SolutionApply an updateAccording to the Mozilla Foundation Security Update 2006-67, this vulnerability is addressed in Firefox 1.5.0.8, Thunderbird 1.5.0.8, and SeaMonkey 1.0.6.
References
This vulnerability was reported in Mozilla Foundation Security Advisory 2006-67. Mozilla credits shutdown for providing information concerning this issue. This document was written by Chris Taschner.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||