Уязвимость use-after-free в Mozilla Firefox, Thunderbird и SeaMonkey, приводящая к выполнения произвольного кода в браузерах через SVG анимацию
Описание
Уязвимость типа "use-after-free" обнаружена в функции ConvertBetweenTimeContainer
компонента nsSMILTimeValueSpec
. Эта уязвимость позволяет злоумышленникам выполнить произвольный код через SVG анимацию.
Затронутые версии ПО
- Mozilla Firefox до версий 3.6.28 и 4.x через 10.0
- Firefox ESR 10.x до версии 10.0.3
- Thunderbird до версии 3.1.20 и 5.0 через 10.0
- Thunderbird ESR 10.x до версии 10.0.3
- SeaMonkey до версии 2.8
Тип уязвимости
Удалённое выполнение кода
Ссылки
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party AdvisoryVendor Advisory
Уязвимые конфигурации
Одно из
Одно из
Одно из
EPSS
9.3 Critical
CVSS2
Дефекты
Связанные уязвимости
Use-after-free vulnerability in the nsSMILTimeValueSpec::ConvertBetweenTimeContainer function in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 might allow remote attackers to execute arbitrary code via an SVG animation.
Use-after-free vulnerability in the nsSMILTimeValueSpec::ConvertBetweenTimeContainer function in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 might allow remote attackers to execute arbitrary code via an SVG animation.
Use-after-free vulnerability in the nsSMILTimeValueSpec::ConvertBetwee ...
Use-after-free vulnerability in the nsSMILTimeValueSpec::ConvertBetweenTimeContainer function in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 might allow remote attackers to execute arbitrary code via an SVG animation.
EPSS
9.3 Critical
CVSS2