Back

HIGH

Firefox 3 crashes in the JavaScript engine

Published Mar 5, 2009

Description

The JavaScript engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a splice of an array that contains "some non-set elements," which causes jsarray.cpp to pass an incorrect argument to the ResizeSlots function, which triggers memory corruption; (2) vectors related to js_DecompileValueGenerator, jsopcode.cpp, __defineSetter__, and watch, which triggers an assertion failure or a segmentation fault; and (3) vectors related to gczeal, __defineSetter__, and watch, which triggers a hang.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (34)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 5, 2009
Updated Aug 7, 2024
Reserved Mar 3, 2009
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Critical
Public date Mar 4, 2009