Уязвимость выполнения произвольного кода и DoS атаки через некорректную обработку функции nsSVGPathElement::GetPathLengthScale в Mozilla Firefox, Thunderbird и SeaMonkey
Описание
Функция nsSVGPathElement::GetPathLengthScale в Mozilla Firefox, Thunderbird и SeaMonkey позволяет злоумышленникам выполнить произвольный код или вызвать DoS атаку через выход за пределы допустимых границ чтения данных с использованием неуказанных векторов.
Затронутые версии ПО
- Mozilla Firefox версии до 18.0
- Mozilla Firefox ESR версии 10.x до 10.0.12 и 17.x до 17.0.1
- Mozilla Thunderbird версии до 17.0.2
- Mozilla Thunderbird ESR версии 10.x до 10.0.12 и 17.x до 17.0.1
- SeaMonkey версии до 2.15
Тип уязвимости
- Выполнение произвольного кода
- DoS атака через некорректное чтение данных
Ссылки
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- Vendor Advisory
- Third Party AdvisoryVDB Entry
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Issue TrackingPatchVendor Advisory
- Third Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- Vendor Advisory
Уязвимые конфигурации
Одно из
Одно из
Одно из
Одно из
EPSS
10 Critical
CVSS2
Дефекты
Связанные уязвимости
The nsSVGPathElement::GetPathLengthScale function in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.1, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.1, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via unspecified vectors.
The nsSVGPathElement::GetPathLengthScale function in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.1, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.1, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via unspecified vectors.
The nsSVGPathElement::GetPathLengthScale function in Mozilla Firefox b ...
The nsSVGPathElement::GetPathLengthScale function in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.1, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.1, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via unspecified vectors.
EPSS
10 Critical
CVSS2