Affected Versions:
Mozilla Firefox 3.6.xMozilla Firefox 3.5.xMozilla Thunderbird 3.1.xMozilla Thunderbird 3.0.xMozilla SeaMonkey < 2.0.9
Vulnerability description:
Firefox is a very popular open-source WEB browser. The js3250.dll library of Firefox has a security vulnerability. When creating and deleting a JavaObject,
The LookupGetterorSetter () function is not filtered,
This may cause a hover pointer to be transferred to the JS_ValueToId () function.
Remote attackers can exploit this vulnerability to execute arbitrary code as a SYSTEM user.
<* Reference
Http://marc.info /? L = full-disclosure & m = 128752219931203 & q = p3
Http://www.mozilla.org/security/announce/2010/mfsa2010-67.html
Https://www.redhat.com/support/errata/RHSA-2010-0782.html
*>Vendor patch:
Mozilla
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.mozilla.org/
RedHat
------
For this reason, RedHat has released a Security Bulletin (RHSA-2010: 0782-01) and patch:
The RHSA-2010: 0782-01: Critical: firefox security update
Link: https://www.redhat.com/support/errata/RHSA-2010-0782.html