CVE-2011-2378 Information

Description

The appendChild function in Mozilla Firefox before 3.6.20 Thunderbird 3.x before 3.1.12 SeaMonkey 2.x and possibly other products does not properly handle DOM objects which allows remote attackers to execute arbitrary code via unspecified vectors that lead to dereferencing of a \dangling pointer.\

Reference

http://lists.opensuse.org/opensuse-security-announce/2011-08/msg00023.html http://lists.opensuse.org/opensuse-security-announce/2011-08/msg00027.html http://www.debian.org/security/2011/dsa-2295 http://www.debian.org/security/2011/dsa-2296 http://www.debian.org/security/2011/dsa-2297 http://www.mandriva.com/security/advisories?name=MDVSA-2011:127 http://www.mozilla.org/security/announce/2011/mfsa2011-30.html http://www.redhat.com/support/errata/RHSA-2011-1164.html http://www.redhat.com/support/errata/RHSA-2011-1166.html https://bugzilla.mozilla.org/show_bug.cgi?id=648065 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A14163

Share on: