First published: Wed Oct 10 2012(Updated: )
Use-after-free vulnerability in the nsSMILAnimationController::DoSample function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox ESR | <10.0.8 | |
Mozilla Thunderbird ESR | <10.0.8 | |
Mozilla Firefox | <16.0 | |
Mozilla Thunderbird | <16.0 | |
Mozilla SeaMonkey | <2.13 | |
Ubuntu Linux | =10.04 | |
Ubuntu Linux | =11.04 | |
Ubuntu Linux | =11.10 | |
Ubuntu Linux | =12.04 | |
redhat enterprise Linux desktop | =5.0 | |
redhat enterprise Linux desktop | =6.0 | |
redhat enterprise Linux eus | =6.3 | |
redhat enterprise Linux server | =5.0 | |
redhat enterprise Linux server | =6.0 | |
redhat enterprise Linux workstation | =5.0 | |
redhat enterprise Linux workstation | =6.0 | |
Mozilla Firefox | <10.0.8 | |
Ubuntu | =10.04 | |
Ubuntu | =11.04 | |
Ubuntu | =11.10 | |
Ubuntu | =12.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4181 is a critical vulnerability that allows remote attackers to execute arbitrary code or cause a denial of service.
To fix CVE-2012-4181, update affected software such as Mozilla Firefox, Thunderbird, or SeaMonkey to their latest versions.
Affected versions include Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, and SeaMonkey before 2.13.
CVE-2012-4181 can be exploited through crafted web content that leads to remote code execution or crashes.
CVE-2012-4181 can affect applications running on various operating systems, including specific versions of Ubuntu and Red Hat.