|
|
| |
| The vulnerability is caused due to an array indexing error while allocating space for floating point numbers. This can be exploited to trigger a memory corruption when a specially crafted floating point number is processed. Successful exploitation allows execution of arbitrary code. |
| |
Credit:
The information has been provided by Alin Rad Pop.
The original article can be found at: http://secunia.com/secunia_research/2009-35/
|
| |
Vulnerable Systems:
* Mozilla Firefox version 3.0.14 and prior
* Mozilla Firefox version 3.5.3 and prior
Immune Systems:
* * Mozilla Firefox version 3.0.15
* Mozilla Firefox version 3.5.4
CVE Information:
CVE-2009-1563
Disclosure Timeline:
14/09/2009 - Vendor notified.
14/09/2009 - Vendor response.
28/10/2009 - Public disclosure.
|
|
|