Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

HTTP:STC:MOZILLA:JIT-ESCAPE-MC

Severity

High

Recommended

No

Recommended Action

Drop

Category

HTTP

Keywords

Mozilla Firefox JIT escape Function Memory Corruption

Release Date

2011/08/02

Update Number

1966

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

HTTP: Mozilla Firefox JIT escape Function Memory Corruption


This signature detects attempts to exploit a known vulnerability against Mozilla Firefox Browser Engine. Attackers can leverage this vulnerability to execute arbitrary code on the victim.

Extended Description

Mozilla Firefox is prone to a remote code-execution vulnerability. Successful exploits may allow an attacker to execute arbitrary code in the context of the user running the affected application. Failed attempts will likely result in denial-of-service conditions. The issue affects Firefox 3.5; other versions may also be vulnerable. NOTE: Remote code execution was confirmed in Firefox 3.5 running on Microsoft Windows XP SP2. A crash was observed in Firefox 3.5 on Windows XP SP3. UPDATE (July 15, 2009): Remote code execution is also possible in Firefox 3.5 running on Apple Mac OS X.

Affected Products

  • Mozilla Firefox 3.5.0
  • Mozilla XULRunner 1.9
  • Mozilla XULRunner 1.9.1
  • Mozilla XULRunner 1.9.1.1
  • Red Hat Fedora 11
  • Sun OpenSolaris Build Snv 119
  • Sun OpenSolaris Build Snv 120
  • Sun OpenSolaris Build Snv 121

References

  • BugTraq: 35660
  • CVE: CVE-2009-2477

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out