Mozilla Firefox IndexedDatabaseManager (CVE-2015-2728)
Mozilla Firefox IndexedDatabaseManager (CVE-2015-2728)
Release date:
Updated on:
Affected Systems:
Mozilla Firefox & lt; 39.0
Mozilla Thunderbird <38.1
Mozilla Firefox ESR <38.1
Description:
CVE (CAN) ID: CVE-2015-2728
Mozilla Firefox is an open-source web browser that uses the Gecko engine.
In versions earlier than Mozilla Firefox 39.0 and earlier than Firefox ESR 38.1, The IndexedDatabaseManager class regards an IDBDatabase field as a pointer in the implementation of IndexedDB, remote attackers can exploit this vulnerability to execute arbitrary code or cause DoS attacks.
<* Source: Paul Bandha
Link: https://www.mozilla.org/en-US/security/advisories/mfsa2015-61/
*>
Suggestion:
Vendor patch:
Mozilla
-------
Mozilla has released a Security Bulletin (mfsa2015-61) and patches for this:
Mfsa2015-61: Type confusion in Indexed Database Manager
Link: https://www.mozilla.org/en-US/security/advisories/mfsa2015-61/
This article permanently updates the link address: