CVE-2011-2371
60Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 76%
from disclosure to weapon104 days
Published on NVDJun 30
1st PoC+104d
metasploitJun 21
exploitation probability
76%top 1% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
What the vendors declare (VEX)
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Red HatVEX document ↗
Affected
1 product (2 components)
Red Hat Enterprise Linux 6
none_available: Affected
Fixed
9 products (250 components)
Red Hat Enterprise Linux AS version 4 · Red Hat Enterprise Linux ES version 4 · Red Hat Enterprise Linux WS version 4 · Red Hat Enterprise Linux (v. 5.6.z server) · Red Hat Enterprise Linux Server (v. 6) · and others 4
Integer overflow in the Array.reduceRight method in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allows remote attackers to execute arbitrary code via vectors involving a long JavaScript Array object.
Affected products
n/a · n/apublic PoCs found — 3✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/17974exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/17976exploitdbwww.exploit-db.com/exploits/18531unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00001.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=664009http://secunia.com/advisories/45002http://securityreason.com/securityalert/8472https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13987http://support.avaya.com/css/P8/documents/100144854http://support.avaya.com/css/P8/documents/100145333http://www.debian.org/security/2011/dsa-2268http://www.debian.org/security/2011/dsa-2269http://www.debian.org/security/2011/dsa-2273http://www.mandriva.com/security/advisories?name=MDVSA-2011:111http://www.mozilla.org/security/announce/2011/mfsa2011-22.html