Lucene search

K
mozillaMozilla FoundationMFSA2009-54
HistoryOct 27, 2009 - 12:00 a.m.

Crash with recursive web-worker calls — Mozilla

2009-10-2700:00:00
Mozilla Foundation
www.mozilla.org
8

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

0.501 Medium

EPSS

Percentile

97.5%

Security researcher Orlando Berrera of Sec Theory reported that recursive creation of JavaScript web-workers can be used to create a set of objects whose memory could be freed prior to their use. These conditions often result in a crash which could potentially be used by an attacker to run arbitrary code on a victim’s computer.

Affected configurations

Vulners
Node
mozillafirefoxRange<3.5.4
CPENameOperatorVersion
firefoxlt3.5.4

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

0.501 Medium

EPSS

Percentile

97.5%