FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2012-0452

This CVE name corresponds to:

Entered Topic
2012-02-11 mozilla -- use-after-free in nsXBLDocumentInfo::ReadPrototypeBindings

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2012-0452
Phase Assigned(20120109)

Description

Use-after-free vulnerability in Mozilla Firefox 10.x before 10.0.1, Thunderbird 10.x before 10.0.1, and SeaMonkey 2.7 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger failure of an nsXBLDocumentInfo::ReadPrototypeBindings function call, related to the cycle collector's access to a hash table containing a stale XBL binding.

References

Source Reference
CONFIRM http://www.mozilla.org/security/announce/2012/mfsa2012-10.html
CONFIRM https://bugzilla.mozilla.org/show_bug.cgi?id=724284
MANDRIVA MDVSA-2012:017
MANDRIVA MDVSA-2012:018
SUSE SUSE-SU-2012:0261
SUSE openSUSE-SU-2012:0258
UBUNTU USN-1360-1
BID 51975
OVAL oval:org.mitre.oval:def:15017
SECUNIA 49055