Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-2998

Опубликовано: 28 сент. 2011
Источник: redhat
CVSS2: 6.8

Описание

Integer underflow in Mozilla Firefox 3.6.x before 3.6.23 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via JavaScript code containing a large RegExp expression.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux Extended Update Support 5.7firefoxAffected
Red Hat Enterprise Linux Extended Update Support 5.7thunderbirdAffected
Red Hat Enterprise Linux Extended Update Support 6.1firefoxAffected
Red Hat Enterprise Linux Extended Update Support 6.1thunderbirdAffected
Red Hat Enterprise Linux 4firefoxFixedRHSA-2011:134128.09.2011
Red Hat Enterprise Linux 4thunderbirdFixedRHSA-2011:134328.09.2011
Red Hat Enterprise Linux 4seamonkeyFixedRHSA-2011:134428.09.2011
Red Hat Enterprise Linux 5firefoxFixedRHSA-2011:134128.09.2011
Red Hat Enterprise Linux 5xulrunnerFixedRHSA-2011:134128.09.2011
Red Hat Enterprise Linux 5thunderbirdFixedRHSA-2011:134328.09.2011

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=741924Mozilla: Integer underflow when using JavaScript RegExp (MFSA 2011-37)

6.8 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 13 лет назад

Integer underflow in Mozilla Firefox 3.6.x before 3.6.23 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via JavaScript code containing a large RegExp expression.

nvd
больше 13 лет назад

Integer underflow in Mozilla Firefox 3.6.x before 3.6.23 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via JavaScript code containing a large RegExp expression.

debian
больше 13 лет назад

Integer underflow in Mozilla Firefox 3.6.x before 3.6.23 allows remote ...

github
около 3 лет назад

Integer underflow in Mozilla Firefox 3.6.x before 3.6.23 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via JavaScript code containing a large RegExp expression.

oracle-oval
больше 13 лет назад

ELSA-2011-1342: thunderbird security update (CRITICAL)

6.8 Medium

CVSS2