|
|
|
|
| |
Credit:
The information has been provided by ZDI.
The original article can be found at: http://www.zerodayinitiative.com/advisories/ZDI-06-009.html
|
| |
Vulnerable Systems:
* Firefox versions 1.0 - 1.0.7
* Thunderbird versions 1.5 - 1.5.0.1
* Thunderbird versions 1.0 - 1.0.7
* SeaMonkey version 1.0
* Mozilla Suite versions 1.7 - 1.7.12
The specific flaw exists within nsHTMLContentSink.cpp, during the parsing of HTML tags as they appear in a specific order. The flaw results in a memory corruption that leads to an attacker controlled function pointer dereference from the stack and eventually execution of arbitrary code.
Vendor Response:
Mozilla has issued an update to correct this vulnerability. Further details are available at:
http://www.mozilla.org/security/announce/2006/mfsa2006-18.html
CVE Information:
CVE-2006-0749
Disclosure Timeline:
2005.12.13 - Vulnerability reported to vendor
2005.12.13 - Digital Vaccine released to TippingPoint customers
2006.04.14 - Coordinated public release of advisory
|
|
|
|
|