51 строка
2.2 KiB
Markdown
51 строка
2.2 KiB
Markdown
---
|
|
announced: December 16, 2008
|
|
fixed_in:
|
|
- Firefox 3.0.5
|
|
- Firefox 2.0.0.19
|
|
- Thunderbird 2.0.0.19
|
|
- SeaMonkey 1.1.14
|
|
impact: Critical
|
|
reporter: Mozilla developers
|
|
title: Crashes with evidence of memory corruption (rv:1.9.0.5/1.8.1.19)
|
|
---
|
|
|
|
<h3>Description</h3>
|
|
|
|
<p>Mozilla developers identified and fixed several stability bugs in the browser
|
|
engine used in Firefox and other Mozilla-based products. Some of these crashes
|
|
showed evidence of memory corruption under certain circumstances and we presume
|
|
that with enough effort at least some of these could be exploited to run
|
|
arbitrary code.</p>
|
|
|
|
<p class="note">Thunderbird shares the browser engine with Firefox and could be
|
|
vulnerable if JavaScript were to be enabled in mail. This is not the default
|
|
setting and we strongly discourage users from running JavaScript in
|
|
mail. Without further investigation we cannot rule out the possibility that for
|
|
some of these an attacker might be able to prepare memory for exploitation
|
|
through some means other than JavaScript such as large images.</p>
|
|
|
|
<h3>Workaround</h3>
|
|
|
|
<p>Disable JavaScript until a version containing these fixes can be installed.</p>
|
|
|
|
|
|
<h3>References</h3>
|
|
|
|
<p>Daniel Veditz, and Jesse Ruderman reported crashes in the layout engine which affected both Firefox 2 and Firefox 3. David Baron reported a crash in the layout engine which only affected Firefox 2 as well as a crash in the layout engine which only affected Firefox 3.</p>
|
|
<ul>
|
|
<li><a href="https://bugzilla.mozilla.org/buglist.cgi?bug_id=460803,464998">Layout engine crashes - Firefox 2 and 3</a></li>
|
|
<li><a class="ex-ref" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5500">CVE-2008-5500</a></li>
|
|
<li><a href="https://bugzilla.mozilla.org/buglist.cgi?bug_id=395623">Layout engine crash - Firefox 3 only</a></li>
|
|
<li><a class="ex-ref" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5501">CVE-2008-5501</a></li>
|
|
</ul>
|
|
|
|
<p>Gary Kwong reported a crash in the JavaScript engine which affected Firefox 3 only.</p>
|
|
<ul>
|
|
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=458679">JavaScript engine crash - Firefox 3 only</a></li>
|
|
<li><a class="ex-ref" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5502">CVE-2008-5502</a></li>
|
|
</ul>
|
|
|
|
|
|
|