int(4113)

Vulnerability Bulletins


Ejecución de código arbitrario en Mozilla Firefox sobre Mac OS X

Vulnerability classification

Property Value
Confidence level Oficial
Impact Obtener acceso
Dificulty Experto
Required attacker level Acceso remoto sin cuenta a un servicio estandar

System information

Property Value
Affected manufacturer GNU/Linux
Affected software Mozilla Firefox 3.x < 3.0.1 (solo Mac OS X)

Description

Se ha descubierto una vulnerabilidad en Mozilla Firefox 3.x de Mac OS X. La vulnerabilidad reside en un error al procesar ciertos datos GIF.

Un atacante remoto podría ejecutar código arbitrario mediante una imagen GIF especialmente diseñada.

Solution



Actualización de software

Mozilla
Firefox 3.0.1
http://www.mozilla.org/products/firefox/

Sun (256408)
Solaris 10 / SPARC / patch 125539-06
Solaris 10 / x86 / patch 125540-06
OpenSolaris / builds snv_95 o posterior
http://sunsolve.sun.com/pub-cgi/show.pl?target=patchpage

Standar resources

Property Value
CVE CVE-2008-2934
BID 30266

Other resources

Mozilla Foundation Security Advisory (2008-36)
http://www.mozilla.org/security/announce/2008/mfsa2008-36.html

Sun Alert Notification (256408)
http://sunsolve.sun.com/search/document.do?assetkey=1-66-256408-1

Version history

Version Comments Date
1.0 Aviso emitido 2008-07-18
1.1 Aviso emitido por Sun (256408) 2009-04-13