Mozilla Firefox/Thunderbird/SeaMonkey 'nsHTMLSelectElement' Remote Code Execution Vulnerability
BID:54080
Info
Mozilla Firefox/Thunderbird/SeaMonkey 'nsHTMLSelectElement' Remote Code Execution Vulnerability
| Bugtraq ID: | 54080 |
| Class: | Design Error |
| CVE: |
CVE-2011-3671 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 18 2012 12:00AM |
| Updated: | Mar 19 2015 09:33AM |
| Credit: | regenrecht via TippingPoint's Zero Day Initiative |
| Vulnerable: |
Mozilla Thunderbird 8.0 Mozilla Thunderbird 7.0.1 Mozilla Thunderbird 7.0 Mozilla Thunderbird 6.0.2 Mozilla Thunderbird 6.0.1 Mozilla Thunderbird 6.0 Mozilla Thunderbird 6 Mozilla Thunderbird 6 Mozilla Thunderbird 5.0 Mozilla Thunderbird 5 Mozilla SeaMonkey 2.0.11 Mozilla SeaMonkey 2.0.9 Mozilla SeaMonkey 2.0.8 Mozilla SeaMonkey 2.0.5 Mozilla SeaMonkey 2.0.4 Mozilla SeaMonkey 2.0.3 Mozilla SeaMonkey 2.0.2 Mozilla SeaMonkey 2.0.1 Mozilla SeaMonkey 2.5 Mozilla SeaMonkey 2.4 Mozilla SeaMonkey 2.3 Mozilla SeaMonkey 2.2 Mozilla SeaMonkey 2.1b2 Mozilla SeaMonkey 2.10 Mozilla SeaMonkey 2.1 Alpha3 Mozilla SeaMonkey 2.1 Alpha2 Mozilla SeaMonkey 2.1 Alpha1 Mozilla SeaMonkey 2.1 Mozilla SeaMonkey 2.0.9 Mozilla SeaMonkey 2.0.7 Mozilla SeaMonkey 2.0.6 Mozilla SeaMonkey 2.0.5 Mozilla SeaMonkey 2.0.4 Mozilla SeaMonkey 2.0.14 Mozilla SeaMonkey 2.0.13 Mozilla SeaMonkey 2.0.12 Mozilla SeaMonkey 2.0.10 Mozilla SeaMonkey 2.0 Rc2 Mozilla SeaMonkey 2.0 Rc1 Mozilla SeaMonkey 2.0 Beta 2 Mozilla SeaMonkey 2.0 Beta 1 Mozilla SeaMonkey 2.0 Alpha 3 Mozilla SeaMonkey 2.0 Alpha 2 Mozilla SeaMonkey 2.0 Alpha 1 Mozilla SeaMonkey 2.0 Mozilla Firefox 8.0.1 Mozilla Firefox 8.0 Mozilla Firefox 7.0.1 Mozilla Firefox 7.0 Mozilla Firefox 7 Mozilla Firefox 6.0.2 Mozilla Firefox 6.0.1 Mozilla Firefox 6.0 Mozilla Firefox 6 Mozilla Firefox 5.0.1 Mozilla Firefox 5.0 Mozilla Firefox 4.0.1 Mozilla Firefox 4.0 Beta9 Mozilla Firefox 4.0 Beta8 Mozilla Firefox 4.0 Beta7 Mozilla Firefox 4.0 Beta6 Mozilla Firefox 4.0 Beta5 Mozilla Firefox 4.0 Beta4 Mozilla Firefox 4.0 Beta3 Mozilla Firefox 4.0 Beta12 Mozilla Firefox 4.0 Beta11 Mozilla Firefox 4.0 Beta10 Mozilla Firefox 4.0 Beta1 Mozilla Firefox 4.0 |
| Not Vulnerable: |
Mozilla Thunderbird 9.0 Mozilla SeaMonkey 2.6 Mozilla Firefox 9.0 |
Discussion
Mozilla Firefox/Thunderbird/SeaMonkey 'nsHTMLSelectElement' Remote Code Execution Vulnerability
Mozilla Firefox, Thunderbird, and SeaMonkey are prone to a remote code-execution vulnerability due to a use-after-free condition.
An attacker can exploit this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts will likely result in denial-of-service conditions.
This issue is fixed in:
Firefox 9.0
Thunderbird 9.0
SeaMonkey 2.6
Mozilla Firefox, Thunderbird, and SeaMonkey are prone to a remote code-execution vulnerability due to a use-after-free condition.
An attacker can exploit this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts will likely result in denial-of-service conditions.
This issue is fixed in:
Firefox 9.0
Thunderbird 9.0
SeaMonkey 2.6
Exploit / POC
Mozilla Firefox/Thunderbird/SeaMonkey 'nsHTMLSelectElement' Remote Code Execution Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Mozilla Firefox/Thunderbird/SeaMonkey 'nsHTMLSelectElement' Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Mozilla Firefox/Thunderbird/SeaMonkey 'nsHTMLSelectElement' Remote Code Execution Vulnerability
References:
References:
- Cisco NX-OS Download Page (Cisco)
- SeaMonkey Homepage (Mozilla)
- Cisco NX-OS Software TACACS+ Command Authorization Vulnerability (Cisco)
- Mozilla Foundation Security Advisory 2012-41 (Mozilla)
- ZDI-12-128: Mozilla Firefox nsHTMLSelectElement Remote Code Execution Vulnerabil (TippingPoint Zero Day Initiative)