Inappropriate coding practices In firefox
Description
The AnimationThread function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 uses an incorrect argument to the sscanf function, which might allow remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact via unknown vectors.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
rpm rhel7 | 0:38.3.0-2.el7_1 | ||
rpm rhel5 | 0:38.3.0-2.el5_11 | ||
rpm rhel6 | 0:38.3.0-2.el6_7 | ||
rpm rhel5 | 0:38.3.0-1.el5_11 | ||
rpm rhel6 | 0:38.3.0-1.el6_7 | ||
rpm rhel7 | 0:38.3.0-1.el7_1 |
Aliases
1. 2. 3.