Overview
Mozilla Firefox versions prior to 2.0.0.15 contain a vulnerability that may allow an attacker to execute code.
Description
Versions of Mozilla Firefox prior to 2.0.0.15 contain a buffer overflow vulnerability. Browsers such as SeaMonkey and Epiphany that use Mozilla's rendering engine may also be affected. Per Mozilla Foundation Security Advisory 2008-33: |
Impact
A remote, unauthenticated attacker may be able to execute arbitrary code or cause a vulnerable browser to crash. |
Solution
Upgrade Per Mozilla Foundation Security Advisory 2008-33 this issue is addressed in Firefox 2.0.0.15 and SeaMonkey 1.1.10. |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
Mozilla credits Security research firm Astabis for reporting this vulnerability.
This document was written by Ryan Giobbi.
Other Information
CVE IDs: | CVE-2008-2811 |
Severity Metric: | 7.17 |
Date Public: | 2008-07-02 |
Date First Published: | 2008-07-02 |
Date Last Updated: | 2008-07-03 12:12 UTC |
Document Revision: | 8 |