CVE-2008-2785: Critical severity thunderbird vulnerability
Mozilla Firefox before 2.0.0.16 and 3.x before 3.0.1, Thunderbird before 2.0.0.16, and SeaMonkey before 1.1.11 use an incorrect integer data type as a CSS object reference counter in the CSSValue array (aka nsCSSValue:Array) data structure, which allows remote attackers to execute arbitrary code via a large number of references to a common CSS object, leading to a counter overflow and a free of in-use memory, aka ZDI-CAN-349.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2008-2785?
CVE-2008-2785 is classified as a critical vulnerability that can allow remote attackers to execute arbitrary code.
How do I fix CVE-2008-2785?
To fix CVE-2008-2785, update affected Mozilla Firefox, Thunderbird, or SeaMonkey versions to a release that is 2.0.0.16, 3.0.1, or higher.
Which versions of Mozilla software are affected by CVE-2008-2785?
CVE-2008-2785 affects Mozilla Firefox versions prior to 2.0.0.16, Thunderbird versions before 2.0.0.16, and SeaMonkey versions before 1.1.11.
Can CVE-2008-2785 be exploited without user interaction?
Yes, CVE-2008-2785 can be exploited remotely without requiring user interaction.
What impacts can CVE-2008-2785 have on affected systems?
CVE-2008-2785 can lead to complete system compromise, allowing attackers to install malicious software and take control of the affected system.