First published: Mon Apr 02 2007(Updated: )
The Javascript engine in Mozilla 1.7 and earlier on Sun Solaris 8, 9, and 10 might allow remote attackers to execute arbitrary code via vectors involving garbage collection that causes deletion of a temporary object that is still being used. NOTE: this issue might be related to CVE-2006-3805.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Solaris SPARC | =10.0-hw2 | |
Sun SunOS | =5.8 | |
Sun SunOS | =5.9 | |
Mozilla Mozilla | <=1.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-1794 is classified as a critical vulnerability due to the potential for remote code execution.
To mitigate CVE-2007-1794, update to a version of Mozilla later than 1.7 that does not include the vulnerability.
CVE-2007-1794 affects Mozilla versions up to and including 1.7 on Sun Solaris systems.
Yes, CVE-2007-1794 can be exploited remotely by attackers.
CVE-2007-1794 is a vulnerability involving memory management and garbage collection flaws in the Javascript engine.