CVE-2012-4187
CVE-2012-4187
Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 do not properly manage a certain insPos variable, which allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption and assertion failure) via unspecified vectors.
Productos afectados
n/a · n/a¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00010.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1351.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=787493http://secunia.com/advisories/50856http://secunia.com/advisories/50892http://secunia.com/advisories/50904http://secunia.com/advisories/50935http://secunia.com/advisories/50936http://secunia.com/advisories/50984http://secunia.com/advisories/55318https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16425http://www.mandriva.com/security/advisories?name=MDVSA-2012:163