Server side template injection In nspr
Description
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.14 and 3.5.x before 3.5.3, Thunderbird before 2.0.0.24, and SeaMonkey before 1.1.19 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the BinHex decoder in netwerk/streamconv/converters/nsBinHexDecoder.cpp, and unknown vectors.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
rpm rhel5 | 0:3.0.14-1.el5_4 | ||
rpm rhel5 | 0:4.7.5-1.el5_4 | ||
rpm rhel5 | 0:1.9.0.14-1.el5_4 | ||
rpm rhel5 | 0:2.0.0.24-2.el5_4 |
Aliases
1. 2. 3.