XML.Nested.Tags.Handling.Race.Condition

NameXML.Nested.Tags.Handling.Race.Condition.Memory.Corruption
Alias/esMozilla.Firefox.Javascript.Handler.Memory.Corruption
Last Updated DateNov 13, 2008
Release DateSep 17, 2006
SeverityHigh
ImpactSystem Compromise: Remote attackers can gain control of vulnerable systems.
Denial of Service.
DescriptionThis indicates an attack attempt against a memory-corruption vulnerability in Mozilla Firefox, Thunderbird, and SeaMonkey.

This vulnerability is caused by the application's failure to properly free structures. A remote attacker may exploit this to execute arbitrary code or cause a denial-of-service condition.
Affected ProductsMozilla Firefox version 1.5.0.7 and prior
Mozilla Thunderbird version 1.5.0.7 and prior
Mozilla SeaMonkey version 1.0.5 and prior
Recommended ActionsUpgrade the software to the latest version:
http://www.mozilla.org/products/
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2006-4253
Reference/shttp://www.securityfocus.com/bid/19488 (BugTraq)
http://www.vupen.com/english/advisories/2006/3617
Reference: VID-13192