Mozilla Firefox and SeaMonkey CVE-2011-3002 Remote Buffer Overflow Vulnerability
BID:49813
Info
Mozilla Firefox and SeaMonkey CVE-2011-3002 Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 49813 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2011-3002 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 27 2011 12:00AM |
| Updated: | Apr 13 2015 09:39PM |
| Credit: | Michael Jordon |
| Vulnerable: |
Ubuntu Ubuntu Linux 11.04 powerpc Ubuntu Ubuntu Linux 11.04 i386 Ubuntu Ubuntu Linux 11.04 ARM Ubuntu Ubuntu Linux 11.04 amd64 S.u.S.E. openSUSE 11.4 S.u.S.E. openSUSE 11.3 Mozilla SeaMonkey 2.3 Mozilla SeaMonkey 2.2 Mozilla Firefox 3.6.13 Mozilla Firefox 3.6.10 Mozilla Firefox 3.6.9 Mozilla Firefox 3.6.8 Mozilla Firefox 3.6.6 Mozilla Firefox 3.6.4 Mozilla Firefox 3.6.3 Mozilla Firefox 3.6.2 Mozilla Firefox 6 Mozilla Firefox 5.0 Mozilla Firefox 4.0.1 Mozilla Firefox 4.0 Beta1 Mozilla Firefox 4.0 Mozilla Firefox 3.6.7 Mozilla Firefox 3.6.6 Mozilla Firefox 3.6.20 Mozilla Firefox 3.6.19 Mozilla Firefox 3.6.18 Mozilla Firefox 3.6.17 Mozilla Firefox 3.6.16 Mozilla Firefox 3.6.15 Mozilla Firefox 3.6.14 Mozilla Firefox 3.6.12 Mozilla Firefox 3.6.11 Mozilla Firefox 3.6 Mandriva Linux Mandrake 2011 x86_64 Mandriva Linux Mandrake 2011 |
| Not Vulnerable: |
Mozilla SeaMonkey 2.4 Mozilla Firefox 7 |
Discussion
Mozilla Firefox and SeaMonkey CVE-2011-3002 Remote Buffer Overflow Vulnerability
Mozilla Firefox and SeaMonkey are prone to a buffer-overflow vulnerability.
An attacker can exploit this issue to execute arbitrary code in the context of the user running an affected application. Failed attempts could lead to a denial-of-service condition.
This issue is fixed in:
Firefox 7
SeaMonkey 2.4
NOTE: This issue was previously covered in BID 49800 (Mozilla Firefox/Thunderbird/SeaMonkey MFSA 2011-36 through -45 Multiple Vulnerabilities) but has been given its own record for better documentation.
Mozilla Firefox and SeaMonkey are prone to a buffer-overflow vulnerability.
An attacker can exploit this issue to execute arbitrary code in the context of the user running an affected application. Failed attempts could lead to a denial-of-service condition.
This issue is fixed in:
Firefox 7
SeaMonkey 2.4
NOTE: This issue was previously covered in BID 49800 (Mozilla Firefox/Thunderbird/SeaMonkey MFSA 2011-36 through -45 Multiple Vulnerabilities) but has been given its own record for better documentation.