Overview
Mozilla Firefox's javascript engine contains a vulnerability that may allow an attacker to execute code.
Description
Mozilla Firefox version 3.5 contains a vulnerability in the TraceMonkey components of Firefox's JavaScript engine. Per Mozilla Bug Bug 503286: |
Impact
A remote, unauthenticated attacker may be able to execute arbitrary code or cause Firefox to crash. |
Solution
Firefox 3.5.1 has been released to address this issue. See Mozilla Foundation Security Advisory 2009-41 for more information. Until updates can be applied, the below workarounds may mitigate this issue. |
Disable TraceMonkey |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 0 | AV:--/AC:--/Au:--/C:--/I:--/A:-- |
Temporal | 0 | E:Not Defined (ND)/RL:Not Defined (ND)/RC:Not Defined (ND) |
Environmental | 0 | CDP:Not Defined (ND)/TD:Not Defined (ND)/CR:Not Defined (ND)/IR:Not Defined (ND)/AR:Not Defined (ND) |
References
- http://www.mozilla.org/security/announce/2009/mfsa2009-41.html
- http://blog.mozilla.com/security/2009/07/14/critical-javascript-vulnerability-in-firefox-35/
- https://bugzilla.mozilla.org/show_bug.cgi?id=503286
- http://milw0rm.com/exploits/9137
- http://kb.mozillazine.org/Firefox_:_FAQs_:_About:config_Entries
- http://voices.washingtonpost.com/securityfix/2009/07/stopgap_fix_for_critical_firef.html?wprss=securityfix
Acknowledgements
Information from zbyte, Mozilla, and other sources was used in this report.
This document was written by Ryan Giobbi.
Other Information
CVE IDs: | None |
Severity Metric: | 40.50 |
Date Public: | 2009-07-09 |
Date First Published: | 2009-07-14 |
Date Last Updated: | 2009-07-17 12:05 UTC |
Document Revision: | 22 |