Lucene search

K
zdiOrlando Barrera II, SecTheoryZDI-10-046
HistoryApr 02, 2010 - 12:00 a.m.

Mozilla Firefox Web Worker Array Remote Code Execution Vulnerability

2010-04-0200:00:00
Orlando Barrera II, SecTheory
www.zerodayinitiative.com
31

EPSS

0.367

Percentile

97.2%

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Mozilla Firefox. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The specific flaw exists within the implementation of web worker threads. Due to mishandling the array data type while processing posted messages, a web worker thread can be made to corrupt heap memory. An attacker can exploit this vulnerability to execute arbitrary code under the context of the user running the browser.