FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2009-2477

This CVE name corresponds to:

Entered Topic
2009-07-17 mozilla -- corrupt JIT state after deep return from native function

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2009-2477
Phase Assigned(20090715)

Description

js/src/jstracer.cpp in the Just-in-time (JIT) JavaScript compiler (aka TraceMonkey) in Mozilla Firefox 3.5 before 3.5.1 allows remote attackers to execute arbitrary code via certain use of the escape function that triggers access to uninitialized memory locations, as originally demonstrated by a document containing P and FONT elements.

References

Source Reference
MILW0RM 9137
MILW0RM 9181
MISC http://isc.sans.org/diary.html?storyid=6796
MISC http://www.h-online.com/security/First-Zero-Day-Exploit-for-Firefox-3-5--/news/113761
MISC http://voices.washingtonpost.com/securityfix/2009/07/stopgap_fix_for_critical_firef.html
CONFIRM http://blog.mozilla.com/security/2009/07/14/critical-javascript-vulnerability-in-firefox-35/
CONFIRM https://bugzilla.mozilla.org/show_bug.cgi?id=503286
CONFIRM http://www.mozilla.org/security/announce/2009/mfsa2009-41.html
FEDORA FEDORA-2009-7898
SUNALERT 266148
CERT-VN VU#443060
BID 35660
SECUNIA 35798
VUPEN ADV-2009-1868