Lucene search

K
mozillaMozilla FoundationMFSA2012-86
HistoryOct 09, 2012 - 12:00 a.m.

Heap memory corruption issues found using Address Sanitizer — Mozilla

2012-10-0900:00:00
Mozilla Foundation
www.mozilla.org
19

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

0.713 High

EPSS

Percentile

98.1%

Security researcher Atte Kettunen from OUSPG reported several heap memory corruption issues found using the Address Sanitizer tool. These issues are potentially exploitable, allowing for remote code execution.

Affected configurations

Vulners
Node
mozillafirefoxRange<16
OR
mozillafirefox_esrRange<10.0.8
OR
mozillaseamonkeyRange<2.13
OR
mozillathunderbirdRange<16
OR
mozillathunderbird_esrRange<10.0.8

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

0.713 High

EPSS

Percentile

98.1%