Use-after-free vulnerability in the imgContainer::InternalAddFrameHelper function in src/imgContainer.cpp in libpr0n in Mozilla Firefox 3.6 before 3.6.2 allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via a multipart/x-mixed-replace animation in which the frames have different bits-per-pixel (bpp) values.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade www-client/seamonkey-bin.Upgrade www-client/firefox-bin.Upgrade net-libs/xulrunner.Upgrade dev-libs/nss.Upgrade www-client/seamonkey.Upgrade www-client/firefox.Upgrade www-client/icecat.Upgrade www-client/mozilla-firefox.Upgrade mail-client/thunderbird.Upgrade www-client/mozilla-firefox-bin.Upgrade net-libs/xulrunner-bin.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade mail-client/mozilla-thunderbird.Upgrade mail-client/thunderbird-bin. | Oct 30, 2017 | Mar 25, 2010 |
| Mfsa2010 09 | — | Upgrade to Mozilla Firefox version 3.6.2 | Jun 14, 2012 | Mar 25, 2010 |
| Suse | — | Upgrade MozillaFirefox-translations-commonUpgrade MozillaFirefox-translationsUpgrade mozilla-xulrunner192-develUpgrade mozilla-xulrunner192-x86Upgrade mozilla-xulrunner192-translationsUpgrade mozilla-xulrunner192-32bitUpgrade MozillaFirefox-develUpgrade mozilla-xulrunner192-translations-32bitUpgrade mozilla-xulrunner192Upgrade MozillaFirefoxUpgrade mozilla-xulrunner192-gnomeUpgrade mozilla-xulrunner192-gnome-32bitUpgrade MozillaFirefox-translations-other | Aug 9, 2024 | Jun 28, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub