SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#751636

Mozilla Layout Engine memory corruption vulnerabilities

Overview

The Mozilla layout engine contains multiple vulnerabilities that may lead to memory corruption. These vulnerabilities may allow an attacker to execute code or cause a denial-of-service condition.

I. Description

The Mozilla Layout Engine contains an multiple vulnerabilities that may result in memory corruption. The impacts of these vulnerabilities vary. According to Mozilla Foundation Security Advisory 2007-12:

    Some of these crashes that showed evidence of memory corruption under certain circumstances and we presume that with enough effort at least some of these could be exploited to run arbitrary code.

Information about the individual bug reports addressed in this update can be found in Mozilla Foundation Security Advisory 2007-12.

II. Impact

Potential consequences include remote execution of arbitrary code and denial of service.

III. Solution

Upgrade

These vulnerabilities are addressed in Firefox 2.0.0.4, Firefox 1.5.0.12, Thunderbird 2.0.0.4, Thunderbird 1.5.0.12, SeaMonkey 1.0.9, SeaMonkey 1.1.2.

Systems Affected

VendorStatusDate Updated
MozillaVulnerable31-May-2007

References


http://www.mozilla.org/security/announce/2007/mfsa2007-12.html
https://bugzilla.mozilla.org/show_bug.cgi?id=377216
https://bugzilla.mozilla.org/show_bug.cgi?id=370360
https://bugzilla.mozilla.org/show_bug.cgi?id=372285
https://bugzilla.mozilla.org/show_bug.cgi?id=306902
https://bugzilla.mozilla.org/show_bug.cgi?id=348492
https://bugzilla.mozilla.org/show_bug.cgi?id=369150
https://bugzilla.mozilla.org/show_bug.cgi?id=369249
https://bugzilla.mozilla.org/show_bug.cgi?id=372237
https://bugzilla.mozilla.org/show_bug.cgi?id=372376
https://bugzilla.mozilla.org/show_bug.cgi?id=376223
https://bugzilla.mozilla.org/show_bug.cgi?id=336574
https://bugzilla.mozilla.org/show_bug.cgi?id=336744
https://bugzilla.mozilla.org/show_bug.cgi?id=336994
https://bugzilla.mozilla.org/show_bug.cgi?id=362708
https://bugzilla.mozilla.org/show_bug.cgi?id=369542
https://bugzilla.mozilla.org/show_bug.cgi?id=371124
https://bugzilla.mozilla.org/show_bug.cgi?id=378273
https://bugzilla.mozilla.org/show_bug.cgi?id=378325
https://bugzilla.mozilla.org/show_bug.cgi?id=374584
https://bugzilla.mozilla.org/show_bug.cgi?id=375196

Credit

These vulnerabilities were reported in Mozilla Foundation Security Advisory 2007-12. Mozilla credits Boris Zbarsky, Eli Friedman, Georgi Guninski, Jesse Ruderman, Martijn Wargers and Olli Pettay with reporting these issues.

This document was written by Jeff Gennari.

Other Information

Date Public05/31/2007
Date First Published05/31/2007 09:34:37 AM
Date Last Updated06/20/2007
CERT Advisory 
CVE NameCVE-2007-2867
US-CERT Technical Alerts 
Metric8.19
Document Revision29

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2007 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader