vendor:
Firefox
by:
Matteo Memelli
7.5
CVSS
HIGH
Integer Overflow
Integer Overflow
CWE
Product Name: Firefox
Affected Version From: 3.6.16
Affected Version To: 3.6.17
Patch Exists: YES
Related CWE: CVE-2011-2371
CPE: a:mozilla:firefox
Metasploit:
https://www.rapid7.com/db/vulnerabilities/suse-cve-2011-2371/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2011-2371/, https://www.rapid7.com/db/vulnerabilities/mozilla-thunderbird-cve-2011-2371/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2011-0887/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2011-0888/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2011-0885/, https://www.rapid7.com/db/vulnerabilities/mfsa2011-22-cve-2011-2371/, https://www.rapid7.com/db/vulnerabilities/mozilla-seamonkey-cve-2011-2371/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2011-2371/
Platforms Tested: Windows 7 Ultimate
2011
Mozilla Firefox Array.reduceRight() Integer Overflow Exploit
The Mozilla Firefox browser is vulnerable to an integer overflow exploit in the Array.reduceRight() function. This vulnerability allows an attacker to bypass DEP (Data Execution Prevention) and ASLR (Address Space Layout Randomization) protections using a Java MSVCR71 sayonara rop chain. The exploit has been tested on Windows 7 Ultimate with Firefox versions 3.6.16 and 3.6.17.
Mitigation:
Upgrade to a patched version of Mozilla Firefox. Apply the latest security updates.