Mozilla Firefox WOFF-Based Font Decoder Integer Overflow Remote Code Execution Vulnerability
BID:38298
Info
Mozilla Firefox WOFF-Based Font Decoder Integer Overflow Remote Code Execution Vulnerability
| Bugtraq ID: | 38298 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2010-1028 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 18 2010 12:00AM |
| Updated: | Aug 19 2013 07:17AM |
| Credit: | Evgeny Legerov of Intevydis |
| Vulnerable: |
Mozilla Firefox 3.6 |
| Not Vulnerable: |
Mozilla Firefox 3.6.2 |
Discussion
Mozilla Firefox WOFF-Based Font Decoder Integer Overflow Remote Code Execution Vulnerability
Mozilla Firefox is prone to a remote code-execution vulnerability due to an integer-overflow error in the WOFF decoder.
Successful exploits may allow an attacker to execute arbitrary code in the context of the user running the affected application. Failed exploit attempts will result in denial-of-service conditions.
The issue affects Mozilla Firefox 3.6.
Mozilla Firefox is prone to a remote code-execution vulnerability due to an integer-overflow error in the WOFF decoder.
Successful exploits may allow an attacker to execute arbitrary code in the context of the user running the affected application. Failed exploit attempts will result in denial-of-service conditions.
The issue affects Mozilla Firefox 3.6.
Exploit / POC
Mozilla Firefox WOFF-Based Font Decoder Integer Overflow Remote Code Execution Vulnerability
Working commercial exploits are available through VulnDisco and CORE IMPACT. These exploits are not otherwise publicly available or known to be circulating in the wild. Mozilla has also confirmed the existence of a private exploit for this issue.
The following exploit is available:
Working commercial exploits are available through VulnDisco and CORE IMPACT. These exploits are not otherwise publicly available or known to be circulating in the wild. Mozilla has also confirmed the existence of a private exploit for this issue.
The following exploit is available:
Solution / Fix
Mozilla Firefox WOFF-Based Font Decoder Integer Overflow Remote Code Execution Vulnerability
Solution:
The vendor released an advisory and Firefox 3.6.2 to address this issue. Please see the references for details.
Solution:
The vendor released an advisory and Firefox 3.6.2 to address this issue. Please see the references for details.
References
Mozilla Firefox WOFF-Based Font Decoder Integer Overflow Remote Code Execution Vulnerability
References:
References:
- Mozilla Acknowledges Critical Zero Day Flaw in Firefox (threatpost.com)
- Mozilla Homepage (Mozilla Foundation)
- New versions of Dbjit and Vulndisco ! (Intevydis)
- Update on Secunia Advisory SA38608 (Mozilla)
- MFSA 2010-08: WOFF heap corruption due to integer overflow (Mozilla Foundation)
- Vulnerability Note VU#964549 Mozilla WOFF decoder integer overflow (US-CERT)
- ZDI-10-064 Mozilla Firefox WOFF Font Format dirEntry Remote Code Execution Vulne (Zero Day Initiative)