Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 228495 - www-client/mozilla-firefox(-bin) unspecified vulnerability (CVE-2008-2785)
Summary: www-client/mozilla-firefox(-bin) unspecified vulnerability (CVE-2008-2785)
Status: RESOLVED DUPLICATE of bug 231975
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard: ?? [upstream]
Keywords:
Depends on:
Blocks:
 
Reported: 2008-06-20 11:03 UTC by Matthias Geerdsen (RETIRED)
Modified: 2008-07-16 18:57 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Matthias Geerdsen (RETIRED) gentoo-dev 2008-06-20 11:03:12 UTC
CVE-2008-2785 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2785):
  Unspecified vulnerability in Firefox 3.0 and 2.0.x has unknown impact and
  remote attack vectors, aka ZDI-CAN-349.
Comment 1 Matthias Geerdsen (RETIRED) gentoo-dev 2008-06-20 12:14:45 UTC
nothing to see here (et), move along

No information available at the moment, so this bug is just to keep track of the issue


http://dvlabs.tippingpoint.com/blog/2008/06/18/vulnerability-in-mozilla-firefox-30

There is also CVE-2008-2786, which could be related.
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2786
Comment 2 Robert Buchholz (RETIRED) gentoo-dev 2008-07-16 18:57:35 UTC
Mozilla writes:
An anonymous researcher, via TippingPoint's Zero Day Initiative program, reported a vulnerability in Mozilla's internal CSSValue array data structure. The vulnerability was caused by an insufficiently sized variable being used as a reference counter for CSS objects. By creating a very large number of references to a common CSS object, this counter could be overflowed which could cause a crash when the browser attempts to free the CSS object while still in use. An attacker could use this crash to run arbitrary code on the victim's computer.

Fixed in 2.0.0.16, handling this in the other bug.

*** This bug has been marked as a duplicate of bug 231975 ***