First published: Wed Oct 10 2012(Updated: )
Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly perform a cast of an unspecified variable during use of the instanceof operator on a JavaScript object, which allows remote attackers to execute arbitrary code or cause a denial of service (assertion failure) via a crafted web site.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <16.0 | |
Mozilla SeaMonkey | <2.13 | |
Thunderbird | <16.0 | |
Ubuntu | =10.04 | |
Ubuntu | =11.04 | |
Ubuntu | =11.10 | |
Ubuntu | =12.04 | |
SUSE Linux Enterprise Desktop | =10-sp4 | |
SUSE Linux Enterprise Desktop | =11-sp2 | |
SUSE Linux Enterprise Server | =10-sp4 | |
SUSE Linux Enterprise Server | =11-sp2 | |
SUSE Linux Enterprise Server | =11-sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-3989 has a severity rating that indicates it allows remote attackers to execute arbitrary code or cause a denial of service.
To fix CVE-2012-3989, update to the latest versions of Mozilla Firefox, Thunderbird, or SeaMonkey beyond the vulnerable versions specified.
CVE-2012-3989 affects Mozilla Firefox versions prior to 16.0, Thunderbird versions prior to 16.0, and SeaMonkey versions prior to 2.13.
Yes, Ubuntu Linux versions 10.04, 11.04, 11.10, and 12.04 are affected by CVE-2012-3989.
CVE-2012-3989 can be exploited to execute arbitrary code or trigger a denial of service condition.