Mozilla Firefox, Mozilla Thunderbird, and Mozilla SeaMonkey contain a user-after-free error when handling child nodes. The issue is due to the 'AttributeChildRemoved()' method when removing child nodes from the 'nsDOMAttribute' node. This may allow a remote attacker to dereference already freed memory and potentially execute arbitrary code.
Classification
Location:
Remote / Network Access
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Solution:
Upgrade
Exploit:
Exploit Public,
Exploit Private
Disclosure:
Vendor Verified,
Coordinated Disclosure
OSVDB:
Web Related
Solution
Upgrade Firefox to version 10.0 or higher or 3.6.26 or higher, Thunderbird to version 10.0 or higher or 3.1.18 or higher, and SeaMonkey to version 2.7 or higher, as they have been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.