FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2008-5013

This CVE name corresponds to:

Entered Topic
2008-11-13 mozilla -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2008-5013
Phase Assigned(20081110)

Description

Mozilla Firefox 2.x before 2.0.0.18 and SeaMonkey 1.x before 1.1.13 do not properly check when the Flash module has been dynamically unloaded properly, which allows remote attackers to execute arbitrary code via a crafted SWF file that "dynamically unloads itself from an outside JavaScript function," which triggers an access of an expired memory address.

References

Source Reference
MISC https://bugzilla.mozilla.org/show_bug.cgi?id=433610
CONFIRM http://www.mozilla.org/security/announce/2008/mfsa2008-49.html
DEBIAN DSA-1669
DEBIAN DSA-1671
DEBIAN DSA-1697
MANDRIVA MDVSA-2008:228
REDHAT RHSA-2008:0977
SUNALERT 256408
SUSE SUSE-SA:2008:055
CERT TA08-319A
BID 32281
SECTRACK 1021181
SECUNIA 34501
VUPEN ADV-2008-3146
SECUNIA 32845
SECUNIA 32693
SECUNIA 32694
SECUNIA 32714
SECUNIA 33433
VUPEN ADV-2009-0977