Release date:
Updated on:
Affected Systems:
Mozilla Firefox 3.6.x
Mozilla SeaMonkey 2.x
Unaffected system:
Mozilla Firefox 7
Mozilla SeaMonkey 2.4
Description:
--------------------------------------------------------------------------------
Bugtraq id: 49813
Cve id: CVE-2011-3002
Firefox is a very popular open-source WEB browser. SeaMonkey is an open-source Web browser, mail and newsgroup client, IRC session client, and HTML editor.
Firefox and SeaMonkey are implemented with security vulnerabilities. Remote attackers can execute arbitrary code in affected applications or cause DoS attacks.
In the ANGLE library used in WebGL, the value returned by GrowAtomTable () has no verification error, resulting in buffer overflow caused by specially crafted requests.
<* Source: Michael Jordan
Link: http://www.mozilla.org/security/announce/2011/mfsa2011-40.html
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Mozilla
-------
Mozilla has released a Security Bulletin (mfsa2011-41) and patches for this:
Mfsa2011-41: Potentially exploitable WebGL crashes
Link: http://www.mozilla.org/security/announce/2011/mfsa2011-41.html