Skip to main content

Mozilla Firefox Remote Code Execution Vulnerability

Last Update Date: 23 Apr 2015 Release Date: 22 Apr 2015 3731 Views

RISK: High Risk

TYPE: Clients - Browsers

TYPE: Browsers

A vulnerability was identified in Mozilla Firefox. A remote user can cause arbitrary code to be executed on the target user's system.

A remote user can create specially crafted HTML that, when loaded by the target user, will trigger a race condition when a plugin fails to initialize, which may lead to a memory corruption error in AsyncPaintWaitEvent::AsyncPaintWaitEvent() and arbitrary code execution on the target system.


Impact

  • Remote Code Execution

System / Technologies affected

  • Versions prior to 37.0.2

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • The vendor has issued a fix (37.0.2).

Vulnerability Identifier


Source


Related Link