blogs.sun.comConfirmation
http://blogs.sun.com/security/entry/multiple_vulnerabilities_in_mozilla_firefox CVE-2010-3179
Mozilla Firefox SeaMonkey 3.6.10 / Thunderbird 3.1.4 - 'document.write' Memory Corruption
Record summary
CVE-2010-3179 has a selected CVSS score of 9.3; EIP currently links 1 catalogued exploit.
Description
Stack-based buffer overflow in the text-rendering functionality in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a long argument to the document.write method.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBMozilla Firefox SeaMonkey 3.6.10 / Thunderbird 3.1.4 - 'document.write' Memory CorruptionExploitDB exploitby Alexander MillerNot analyzed1 file
References
Showing 12 of 18FEDORA-2010-16897Vendor advisory
http://lists.fedoraproject.org/pipermail/package-announce/2010-October/050077.html FEDORA-2010-16885Vendor advisory
http://lists.fedoraproject.org/pipermail/package-announce/2010-October/050154.html 42867Third-party advisory
http://secunia.com/advisories/42867 support.avaya.comConfirmation
http://support.avaya.com/css/P8/documents/100120156 DSA-2124Vendor advisory
http://www.debian.org/security/2010/dsa-2124 MDVSA-2010:210Vendor advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2010:210 MDVSA-2010:211Vendor advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2010:211 mozilla.orgConfirmation
http://www.mozilla.org/security/announce/2010/mfsa2010-65.html RHSA-2010:0782Vendor advisory
http://www.redhat.com/support/errata/RHSA-2010-0782.html RHSA-2010:0861Vendor advisory
http://www.redhat.com/support/errata/RHSA-2010-0861.html RHSA-2010:0896Vendor advisory
http://www.redhat.com/support/errata/RHSA-2010-0896.html