Mozilla Firefox DOM Insertion Remote Code Execution Vulnerability
Last Update Date:
28 Jan 2011
Release Date:
28 Oct 2010
5713
Views
RISK: Medium Risk
A vulnerability has been identified in Mozilla Firefox, Thunderbird and SeaMonkey, which could be exploited by malicious web sites to execute arbitrary code. This issue is caused by a memory corruption error when handling "document.write()" methods and DOM insertion, which could allow remote attackers to compromise a vulnerable system.
This vulnerability is exploited in the wild by the Belmoo malware.
Impact
- Remote Code Execution
System / Technologies affected
- Mozilla Firefox version 3.6.11 and prior
- Mozilla Firefox version 3.5.14 and prior
- Mozilla Thunderbird version 3.1.5 and prior
- Mozilla Thunderbird version 3.0.9 and prior
- Mozilla SeaMonkey version 2.0.9 and prior
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Upgrade to Mozilla Firefox version 3.6.12 or 3.5.15 :
http://www.mozilla.com/firefox/ - Upgrade to Mozilla Thunderbird version 3.1.6 or 3.0.10 :
http://www.mozilla.com/thunderbird/ - Upgrade to Mozilla SeaMonkey version 2.0.10 :
http://www.mozilla.com/seamonkey/
Vulnerability Identifier
Source
Related Link
Share with