|
|
| |
Credit:
The original article can be found at: http://www.securityfocus.com/bid/45348
The information has been provided by Igor Bukanov
|
| |
Vulnerable Systems:
* Mozilla Firefox 3.5.17
* Mozilla Firefox 3.5.14
* Mozilla Firefox 3.5.13
* Mozilla Firefox 3.5.10
* Mozilla Firefox 3.5.10
* Mozilla Firefox 3.5.9
* Mozilla Firefox 3.5.9
* Mozilla Firefox 3.5.8
* Mozilla Firefox 3.5.7
* Mozilla Firefox 3.5.6
* Mozilla Firefox 3.5.5
* Mozilla Firefox 3.5.4
* Mozilla Firefox 3.5.3
* Mozilla Firefox 3.5.2
* Mozilla Firefox 3.5.1
* Mozilla Firefox 3.5
* Mozilla Firefox 3.5.15
* Mozilla Firefox 3.5.12
* Mozilla Firefox 3.5.11
Non-Vulnerable Systems:
* Mozilla Thunderbird 3.1.7
* Mozilla Thunderbird 3.0.11
* Mozilla SeaMonkey 2.0.11
* Mozilla Firefox 3.6.13
* Mozilla Firefox 3.5.16
An attacker can exploit this issue by enticing an unsuspecting user into viewing a page containing malicious content. A successful exploit will result in the execution of arbitrary code in the context of the user running the affected application.
Vendor Status:
Mozilla as issued an update for this vulnerablity
Patch Availability:
http://www.mozilla.org/en-US/products/download.html?product=firefox-12.0&os=win&lang=en-US
CVE Information:
CVE-2010-3777
Disclosure Timeline:
Initial Release Dec 21 2011
|
|
|