Out-of-bounds read In esc
Description
Integer overflow in the XSLT node sorting implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allows remote attackers to execute arbitrary code via a large text value for a node.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
rpm rhel5 | 0:1.1.0-12.el5 | ||
rpm rhel5 | 0:2.0.0.24-6.el5 | ||
rpm rhel5 | 0:0.12-21.el5 | ||
rpm rhel5 | 0:3.6.4-8.el5 | ||
rpm rhel5 | 0:2.14.2-7.el5 | ||
rpm rhel5 | 0:2.16.7-7.el5 | ||
rpm rhel5 | 0:1.9.2.4-10.el5 | ||
rpm rhel5 | 0:2.16.0-26.el5 |
Aliases
1. 2. 3.
References
1. 2.