Overview
Mozilla Firefox versions prior to 2.0.0.15 contain a vulnerability that may allow an attacker to execute code.
Description
Versions of Mozilla Firefox prior to 2.0.0.15 contain a buffer overflow vulnerability. Browsers such as SeaMonkey and Epiphany that use Mozilla's rendering engine may also be affected. Per Mozilla Foundation Security Advisory 2008-33: |
Impact
A remote, unauthenticated attacker may be able to execute arbitrary code or cause a vulnerable browser to crash. |
Solution
Upgrade Per Mozilla Foundation Security Advisory 2008-33 this issue is addressed in Firefox 2.0.0.15 and SeaMonkey 1.1.10. |
Vendor Information
CVSS Metrics
| Group | Score | Vector |
|---|---|---|
| Base | ||
| Temporal | ||
| Environmental |
References
Acknowledgements
Mozilla credits Security research firm Astabis for reporting this vulnerability.
This document was written by Ryan Giobbi.
Other Information
| CVE IDs: | CVE-2008-2811 |
| Severity Metric: | 7.17 |
| Date Public: | 2008-07-02 |
| Date First Published: | 2008-07-02 |
| Date Last Updated: | 2008-07-03 12:12 UTC |
| Document Revision: | 8 |