Vulnerability Note VU#751636
Mozilla Layout Engine memory corruption vulnerabilities
OverviewThe Mozilla layout engine contains multiple vulnerabilities that may lead to memory corruption. These vulnerabilities may allow an attacker to execute code or cause a denial-of-service condition.
I. DescriptionThe Mozilla Layout Engine contains an multiple vulnerabilities that may result in memory corruption. The impacts of these vulnerabilities vary. According to Mozilla Foundation Security Advisory 2007-12:
Some of these crashes that showed evidence of memory corruption under certain circumstances and we presume that with enough effort at least some of these could be exploited to run arbitrary code.
Information about the individual bug reports addressed in this update can be found in Mozilla Foundation Security Advisory 2007-12.
II. ImpactPotential consequences include remote execution of arbitrary code and denial of service.
III. SolutionUpgrade
These vulnerabilities are addressed in Firefox 2.0.0.4, Firefox 1.5.0.12, Thunderbird 2.0.0.4, Thunderbird 1.5.0.12, SeaMonkey 1.0.9, SeaMonkey 1.1.2.
Systems Affected
| Vendor | Status | Date Notified | Date Updated |
| Mozilla | Vulnerable | 31-May-2007 |
References
http://www.mozilla.org/security/announce/2007/mfsa2007-12.html
https://bugzilla.mozilla.org/show_bug.cgi?id=377216
https://bugzilla.mozilla.org/show_bug.cgi?id=370360
https://bugzilla.mozilla.org/show_bug.cgi?id=372285
https://bugzilla.mozilla.org/show_bug.cgi?id=306902
https://bugzilla.mozilla.org/show_bug.cgi?id=348492
https://bugzilla.mozilla.org/show_bug.cgi?id=369150
https://bugzilla.mozilla.org/show_bug.cgi?id=369249
https://bugzilla.mozilla.org/show_bug.cgi?id=372237
https://bugzilla.mozilla.org/show_bug.cgi?id=372376
https://bugzilla.mozilla.org/show_bug.cgi?id=376223
https://bugzilla.mozilla.org/show_bug.cgi?id=336574
https://bugzilla.mozilla.org/show_bug.cgi?id=336744
https://bugzilla.mozilla.org/show_bug.cgi?id=336994
https://bugzilla.mozilla.org/show_bug.cgi?id=362708
https://bugzilla.mozilla.org/show_bug.cgi?id=369542
https://bugzilla.mozilla.org/show_bug.cgi?id=371124
https://bugzilla.mozilla.org/show_bug.cgi?id=378273
https://bugzilla.mozilla.org/show_bug.cgi?id=378325
https://bugzilla.mozilla.org/show_bug.cgi?id=374584
https://bugzilla.mozilla.org/show_bug.cgi?id=375196
Credit
These vulnerabilities were reported in Mozilla Foundation Security Advisory 2007-12. Mozilla credits Boris Zbarsky, Eli Friedman, Georgi Guninski, Jesse Ruderman, Martijn Wargers and Olli Pettay with reporting these issues.
This document was written by Jeff Gennari.
Other Information
| Date Public: | 2007-05-31 |
| Date First Published: | 2007-05-31 |
| Date Last Updated: | 2007-06-20 |
| CERT Advisory: | |
| CVE-ID(s): | CVE-2007-2867 |
| NVD-ID(s): | CVE-2007-2867 |
| US-CERT Technical Alerts: | |
| Metric: | 8.19 |
| Document Revision: | 29 |
If you have feedback, comments, or additional information about this vulnerability, please send us
email.
|