Lucene search

K
mozillaMozilla FoundationMFSA2009-35
HistoryJul 21, 2009 - 12:00 a.m.

Crash and remote code execution during Flash player unloading — Mozilla

2009-07-2100:00:00
Mozilla Foundation
www.mozilla.org
11

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

0.329 Low

EPSS

Percentile

97.1%

Security researcher Attila Suszter reported that when a page contains a Flash object which presents a slow script dialog, and the page is navigated while the dialog is still visible to the user, the Flash plugin is unloaded resulting in a crash due to a call to the deleted object. This crash could potentially be used by an attacker to run arbitrary code on a victim’s computer.

Affected configurations

Vulners
Node
mozillafirefoxRange<3.0.12
OR
mozillafirefoxRange<3.5.1
CPENameOperatorVersion
firefoxlt3.0.12
firefoxlt3.5.1

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

0.329 Low

EPSS

Percentile

97.1%