CVE-2011-3650: Buffer Overflow
Mozilla Firefox before 3.6.24 and 4.x through 7.0 and Thunderbird before 3.1.6 and 5.0 through 7.0 do not properly handle JavaScript files that contain many functions, which allows user-assisted remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a crafted file that is accessed by debugging APIs, as demonstrated by Firebug.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3650?
CVE-2011-3650 is considered a moderate severity vulnerability that can lead to denial of service and application crash.
How do I fix CVE-2011-3650?
To fix CVE-2011-3650, upgrade Mozilla Firefox to version 3.6.24 or later, and Thunderbird to version 3.1.6 or later.
What are the affected versions by CVE-2011-3650?
CVE-2011-3650 affects Mozilla Firefox versions prior to 3.6.24 and 4.x through 7.0, as well as Thunderbird versions before 3.1.6 and 5.0 through 7.0.
What type of attack does CVE-2011-3650 allow?
CVE-2011-3650 allows user-assisted remote attackers to cause a denial of service through memory corruption.
Is there a workaround for CVE-2011-3650 if I cannot update immediately?
There is no workaround for CVE-2011-3650; users are advised to update their software to the latest versions as soon as possible.