Input validation error - CVE-2011-0077

 

Input validation error - CVE-2011-0077

Published: May 7, 2011 / Updated: August 4, 2020


Vulnerability identifier: #VU33969
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2011-0077
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0072, CVE-2011-0074, CVE-2011-0075, and CVE-2011-0078.


Affected software

xulrunner (Alpine package)

How to mitigate CVE-2011-0077

Install update from vendor's website.

xulrunner (Alpine package) - update to 2.0.1-r0

External References

Related Security Bulletins