|
Brought to you by:
Suppliers of:
|
|
|
| |
| The vulnerability is caused due to a race condition when accessing the private data of an NPObject JS wrapper class object if navigating away from a web page while loading a Java applet. This can be exploited via a specially crafted web page to use already freed memory. Successful exploitation may allow execution of arbitrary code. |
| |
Credit:
The information has been provided by Jakob Balle and Carsten Eiram.
The original article can be found at: http://secunia.com/secunia_research/2009-19/
|
| |
Vulnerable Systems:
* Firefox 3.0.7, 3.0.8, and 3.0.9 for Windows with JRE 6 Update 13
Immune Systems:
* Firefox version 3.0.11
CVE Information:
CVE-2009-1837
Disclosure Timeline:
26/03/2009 - Vendor notified.
01/04/2009 - Vendor notified (2nd attempt).
01/04/2009 - Vendor response.
12/06/2009 - Public disclosure.
|
|
|
|
|