Vulnerabilidad en motor JavaScript de Mozilla Firefox, Thunderbird y SeaMonkey (CVE-2009-0773)
Gravedad CVSS v2.0:
ALTA
Tipo:
CWE-399
Error en la gestión de recursos
Fecha de publicación:
05/03/2009
Última modificación:
09/04/2025
Descripción
El motor JavaScript de Mozilla Firefox anterior a v3.0.7, Thunderbird anterior a v2.0.0.21 y SeaMonkey v1.1.15, permite a atacantes remotos provocar una denegación de servicio (caída) y puede que ejecutar código de su elección a través de (1) una unión de un array que contiene "algunos elementos non-set" que hace que jsarray.cpp pase un argumento incorrecto a la función ResizeSlots lo que lanza una corrupción de memoria; (2) vectores relacionado con js_DecompileValueGenerator, jsopcode.cpp, __defineSetter__ y watch -ver- que lanzan un fallo de aserción o un fallo de segmentación y (3) vectores relacionados con gczeal, __defineSetter__ y watch -ver- que inducen a un cuelgue.
Impacto
Puntuación base 2.0
10.00
Gravedad 2.0
ALTA
Productos y versiones vulnerables
| CPE | Desde | Hasta |
|---|---|---|
| cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | 3.0.6 (incluyendo) | |
| cpe:2.3:a:mozilla:firefox:1.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:mozilla:firefox:1.0.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:mozilla:firefox:1.0.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:mozilla:firefox:1.0.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:mozilla:firefox:1.0.4:*:*:*:*:*:*:* | ||
| cpe:2.3:a:mozilla:firefox:1.0.5:*:*:*:*:*:*:* | ||
| cpe:2.3:a:mozilla:firefox:1.0.6:*:*:*:*:*:*:* | ||
| cpe:2.3:a:mozilla:firefox:1.0.7:*:*:*:*:*:*:* | ||
| cpe:2.3:a:mozilla:firefox:1.0.8:*:*:*:*:*:*:* | ||
| cpe:2.3:a:mozilla:firefox:1.5:*:*:*:*:*:*:* | ||
| cpe:2.3:a:mozilla:firefox:1.5.0.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:mozilla:firefox:1.5.0.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:mozilla:firefox:1.5.0.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:mozilla:firefox:1.5.0.4:*:*:*:*:*:*:* |
Para consultar la lista completa de nombres de CPE con productos y versiones, ver esta página
Referencias a soluciones, herramientas e información
- http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00002.html
- http://secunia.com/advisories/34140
- http://secunia.com/advisories/34145
- http://secunia.com/advisories/34272
- http://secunia.com/advisories/34383
- http://secunia.com/advisories/34462
- http://secunia.com/advisories/34464
- http://secunia.com/advisories/34527
- http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.405420
- http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.433952
- http://support.avaya.com/elmodocs2/security/ASA-2009-069.htm
- http://support.avaya.com/japple/css/japple?temp_documentID=366362&temp_productID=154235&temp_releaseID=361845&temp_bucketID=126655&PAGE=Document
- http://www.debian.org/security/2009/dsa-1751
- http://www.debian.org/security/2009/dsa-1830
- http://www.mandriva.com/security/advisories?name=MDVSA-2009%3A075
- http://www.mandriva.com/security/advisories?name=MDVSA-2009%3A083
- http://www.mozilla.org/security/announce/2009/mfsa2009-07.html
- http://www.redhat.com/support/errata/RHSA-2009-0315.html
- http://www.securityfocus.com/bid/33990
- http://www.securitytracker.com/id?1021795=
- http://www.vupen.com/english/advisories/2009/0632
- https://bugzilla.mozilla.org/show_bug.cgi?id=457521
- https://bugzilla.mozilla.org/show_bug.cgi?id=467499
- https://bugzilla.mozilla.org/show_bug.cgi?id=472787
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10491
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5856
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5980
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6141
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6708
- https://www.redhat.com/archives/fedora-package-announce/2009-March/msg01077.html
- http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00002.html
- http://secunia.com/advisories/34140
- http://secunia.com/advisories/34145
- http://secunia.com/advisories/34272
- http://secunia.com/advisories/34383
- http://secunia.com/advisories/34462
- http://secunia.com/advisories/34464
- http://secunia.com/advisories/34527
- http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.405420
- http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.433952
- http://support.avaya.com/elmodocs2/security/ASA-2009-069.htm
- http://support.avaya.com/japple/css/japple?temp_documentID=366362&temp_productID=154235&temp_releaseID=361845&temp_bucketID=126655&PAGE=Document
- http://www.debian.org/security/2009/dsa-1751
- http://www.debian.org/security/2009/dsa-1830
- http://www.mandriva.com/security/advisories?name=MDVSA-2009%3A075
- http://www.mandriva.com/security/advisories?name=MDVSA-2009%3A083
- http://www.mozilla.org/security/announce/2009/mfsa2009-07.html
- http://www.redhat.com/support/errata/RHSA-2009-0315.html
- http://www.securityfocus.com/bid/33990
- http://www.securitytracker.com/id?1021795=
- http://www.vupen.com/english/advisories/2009/0632
- https://bugzilla.mozilla.org/show_bug.cgi?id=457521
- https://bugzilla.mozilla.org/show_bug.cgi?id=467499
- https://bugzilla.mozilla.org/show_bug.cgi?id=472787
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10491
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5856
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5980
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6141
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6708
- https://www.redhat.com/archives/fedora-package-announce/2009-March/msg01077.html



