Concurrency vulnerability in Mozilla Firefox 1.5.0.6 and earlier allows remote...
Vulnerability Description
Concurrency vulnerability in Mozilla Firefox 1.5.0.6 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via multiple Javascript timed events that load a deeply nested XML file, followed by redirecting the browser to another page, which leads to a concurrency failure that causes structures to be freed incorrectly, as demonstrated by (1) ffoxdie and (2) ffoxdie3. NOTE: it has been reported that Netscape 8.1 and K-Meleon 1.0.1 are also affected by ffoxdie. Mozilla confirmed to CVE that ffoxdie and ffoxdie3 trigger the same underlying vulnerability. NOTE: it was later reported that Firefox 2.0 RC2 and 1.5.0.7 are also affected.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-4253
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.securityfocus.com/archive/1/448956/100/100/threaded
- http://www.securityfocus.com/archive/1/443500/100/100/threaded
- http://securitytracker.com/id?1016847
- http://secunia.com/advisories/22391
- http://www.vupen.com/english/advisories/2006/3748
- http://www.redhat.com/support/errata/RHSA-2006-0676.html
- http://www.mozilla.org/security/announce/2006/mfsa2006-59.html
- http://lcamtuf.coredump.cx/ffoxdie.html
- http://secunia.com/advisories/22055
- http://secunia.com/advisories/22195
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9528
- http://www.ubuntu.com/usn/usn-352-1
- http://secunia.com/advisories/21513
- http://secunia.com/advisories/21950
- http://www.ubuntu.com/usn/usn-351-1
- http://secunia.com/advisories/22025
- http://secunia.com/advisories/22056
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:168
- http://www.securityfocus.com/archive/1/443020/100/100/threaded
- http://secunia.com/advisories/22210
- http://secunia.com/advisories/24711
- http://security.gentoo.org/glsa/glsa-200610-04.xml
- http://support.avaya.com/elmodocs2/security/ASA-2006-224.htm
- http://www.pianetapc.it/view.php?id=770
- http://www.vupen.com/english/advisories/2008/0083
- http://www.securityfocus.com/archive/1/443528/100/0/threaded
- ftp://patches.sgi.com/support/free/security/advisories/20060901-01-P.asc
- http://secunia.com/advisories/21939
- http://securitytracker.com/id?1016848
- http://www.vupen.com/english/advisories/2006/3617
- http://secunia.com/advisories/21915
- http://www.vupen.com/english/advisories/2007/1198
- http://www.securityfocus.com/archive/1/447837/100/200/threaded
- http://www.redhat.com/support/errata/RHSA-2006-0677.html
- http://security.gentoo.org/glsa/glsa-200609-19.xml
- http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00771742
- http://www.securityfocus.com/archive/1/448984/100/100/threaded
- http://secunia.com/advisories/22274
- http://www.redhat.com/support/errata/RHSA-2006-0675.html
- http://secunia.com/advisories/21940
- http://secunia.com/advisories/22001
- http://www.securityfocus.com/archive/1/446140/100/0/threaded
- http://www.ubuntu.com/usn/usn-350-1
- http://secunia.com/advisories/21906
- http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00771742
- http://www.securityfocus.com/archive/1/449245/100/100/threaded
- http://security.gentoo.org/glsa/glsa-200610-01.xml
- http://secunia.com/advisories/22074
- http://secunia.com/advisories/22066
- http://secunia.com/advisories/22088
- http://www.securityfocus.com/archive/1/443306/100/100/threaded
- http://secunia.com/advisories/21949
- http://www.novell.com/linux/security/advisories/2006_54_mozilla.html
- https://bugzilla.mozilla.org/show_bug.cgi?id=348514
- http://www.securityfocus.com/bid/19534
- https://issues.rpath.com/browse/RPL-640
- http://www.securityfocus.com/archive/1/447840/100/200/threaded
- http://lcamtuf.coredump.cx/ffoxdie3.html
- http://www.securityfocus.com/archive/1/449726/100/0/threaded
- http://secunia.com/advisories/22036
- http://securitytracker.com/id?1016846
- http://www.ubuntu.com/usn/usn-354-1
- http://www.securityfocus.com/bid/19488
- http://www.securityfocus.com/archive/1/449487/100/0/threaded
- http://secunia.com/advisories/22422
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:169
- http://www.securiteam.com/securitynews/5VP0M0AJFW.html
- http://secunia.com/advisories/21916
More from k-meleon project
View All →Affected Vendor
k-meleon project
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.