CVE-2010-1212: Buffer Overflow
js/src/jstracer.cpp in the browser engine in Mozilla Firefox 3.6.x before 3.6.7 and Thunderbird 3.1.x before 3.1.1 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) propagation of deep aborts in the TraceRecorder::recordJSOPBINDNAME function, (2) depth handling in the TraceRecorder::recordJSOPGETELEM function, and (3) tracing of out-of-range arguments in the TraceRecorder::recordJSOPARGSUB function.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1212?
CVE-2010-1212 has a severity rating that can lead to denial of service and potential arbitrary code execution.
How do I fix CVE-2010-1212?
To address CVE-2010-1212, upgrade to Mozilla Firefox version 3.6.7 or later and Thunderbird version 3.1.1 or later.
What versions are affected by CVE-2010-1212?
CVE-2010-1212 affects Mozilla Firefox versions 3.6.1 to 3.6.6 and Thunderbird version 3.1.
What type of attack does CVE-2010-1212 enable?
CVE-2010-1212 enables remote attackers to crash the application or potentially execute arbitrary code through memory corruption.
Can CVE-2010-1212 affect users on the latest versions of Firefox and Thunderbird?
No, users on Mozilla Firefox 3.6.7 and later and Thunderbird 3.1.1 and later are not impacted by CVE-2010-1212.