Release date:
Updated on:
Affected Systems:
Mozilla Firefox 3.6.x
Mozilla Thunderbird 3.x
Mozilla SeaMonkey 2.x
Unaffected system:
Mozilla Firefox 6
Mozilla Firefox 3.6.23
Mozilla Thunderbird 6
Mozilla SeaMonkey 2.3
Description:
--------------------------------------------------------------------------------
Bugtraq id: 49847
Firefox is a very popular open-source WEB browser. Thunderbird is a mail client that supports IMAP, POP protocol, and HTML format. SeaMonkey is an open-source Web browser, mail and newsgroup client, IRC session client, and HTML editor.
Mozilla Firefox/SeaMonkey has a security vulnerability. Remote attackers can exploit this vulnerability to execute arbitrary code with the current user permission, which may cause DOS.
In the ANGLE library used by WebGL, the returned value of GrowAtomTable () is not checked.
<* Source: Ben Hawkes
Link: http://www.mozilla.org/security/announce/2011/mfsa2011-38.html
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Mozilla
-------
Mozilla has released a Security Bulletin (mfsa2011-41) and patches for this:
Mfsa2011-41: Potentially exploitable WebGL crashes
Link: http://www.mozilla.org/security/announce/2011/mfsa2011-41.html