Lucene search

K
mozillaMozilla FoundationMFSA2010-81
HistoryDec 09, 2010 - 12:00 a.m.

Integer overflow vulnerability in NewIdArray — Mozilla

2010-12-0900:00:00
Mozilla Foundation
www.mozilla.org
22

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.423

Percentile

97.4%

Security researcher regenrecht reported via TippingPoint’s Zero Day Initiative that JavaScript arrays were vulnerable to an integer overflow vulnerability. The report demonstrated that an array could be constructed containing a very large number of items such that when memory was allocated to store the array items, the integer value used to calculate the buffer size would overflow resulting in too small a buffer being allocated. Subsequent use of the array object could then result in data being written past the end of the buffer and causing memory corruption.

Affected configurations

Vulners
Node
mozillafirefoxRange<3.5.16
OR
mozillafirefoxRange<3.6.13
OR
mozillaseamonkeyRange<2.0.11
VendorProductVersionCPE
mozillafirefox*cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
mozillaseamonkey*cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.423

Percentile

97.4%