CVE-2012-3970
published 2012-08-29CVE-2012-3970: Use-after-free vulnerability in the nsTArray_base::Length function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0…
PriorityP342critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
5.19%
91.5th percentile
Use-after-free vulnerability in the nsTArray_base::Length function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving movement of a requiredFeatures attribute from one SVG document to another.
Affected
275 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 14.0 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird regressions
vendor_ubuntu·2012-09-28·CVSS 4.3
[MEDIUM] Thunderbird regressions
Title: Thunderbird regressions
Summary: USN-1551-1 introduced regressions in Thunderbird.
USN-1551-1 fixed vulnerabilities in Thunderbird. The new package caused a
regression in the message editor and certain performance regressions as
well. This update fixes the problems.
Original advisory details:
Gary Kwong, Christian Holler, Jesse Ruderman, Steve Fink, Bob Clary, Andrew
Sutherland, Jason Smith, John Schoenick, Vladimir Vukicevic and Daniel
Holbert discovered memory safety issues affecting Thunderbird. If the user
were tricked into opening a specially crafted E-Mail, an attacker could
exploit these to cause a denial of service via application crash, or
potentially execute code with the privileges of the user invoking
Thunderbird. (CVE-2012-1970, CVE-2012-1971)
Abhishek Arya discove
Ubuntu
Firefox regression
vendor_ubuntu·2012-09-11·CVSS 4.3
[MEDIUM] Firefox regression
Title: Firefox regression
Summary: USN-1548-1 introduced a regression in Firefox.
USN-1548-1 fixed vulnerabilities in Firefox. The new package caused a
regression in Private Browsing which could leak sites visited to the
browser cache. This update fixes the problem.
Original advisory details:
Gary Kwong, Christian Holler, Jesse Ruderman, Steve Fink, Bob Clary, Andrew
Sutherland, Jason Smith, John Schoenick, Vladimir Vukicevic and Daniel
Holbert discovered memory safety issues affecting Firefox. If the user were
tricked into opening a specially crafted page, an attacker could exploit
these to cause a denial of service via application crash, or potentially
execute code with the privileges of the user invoking Firefox.
(CVE-2012-1970, CVE-2012-1971)
Abhishek Arya discovered multiple use-
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2012-08-30·CVSS 4.3
CVE-2012-1970 [MEDIUM] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Multiple security issues were fixed in Thunderbird.
Gary Kwong, Christian Holler, Jesse Ruderman, Steve Fink, Bob Clary, Andrew
Sutherland, Jason Smith, John Schoenick, Vladimir Vukicevic and Daniel
Holbert discovered memory safety issues affecting Thunderbird. If the user
were tricked into opening a specially crafted E-Mail, an attacker could
exploit these to cause a denial of service via application crash, or
potentially execute code with the privileges of the user invoking
Thunderbird. (CVE-2012-1970, CVE-2012-1971)
Abhishek Arya discovered multiple use-after-free vulnerabilities. If the
user were tricked into opening a specially crafted E-Mail, an attacker
could exploit these to cause a denial of service via application crash, or
potential
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2012-08-29·CVSS 4.3
CVE-2012-1970 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Multiple security issues were fixed in Firefox.
Gary Kwong, Christian Holler, Jesse Ruderman, Steve Fink, Bob Clary, Andrew
Sutherland, Jason Smith, John Schoenick, Vladimir Vukicevic and Daniel
Holbert discovered memory safety issues affecting Firefox. If the user were
tricked into opening a specially crafted page, an attacker could exploit
these to cause a denial of service via application crash, or potentially
execute code with the privileges of the user invoking Firefox.
(CVE-2012-1970, CVE-2012-1971)
Abhishek Arya discovered multiple use-after-free vulnerabilities. If the
user were tricked into opening a specially crafted page, an attacker could
exploit these to cause a denial of service via application crash, or
potentially execute code with
Red Hat
Mozilla: SVG buffer overflow and use-after-free issues (MFSA 2012-63)
vendor_redhat·2012-08-28·CVSS 10.0
CVE-2012-3970 [CRITICAL] CWE-119 Mozilla: SVG buffer overflow and use-after-free issues (MFSA 2012-63)
Mozilla: SVG buffer overflow and use-after-free issues (MFSA 2012-63)
Use-after-free vulnerability in the nsTArray_base::Length function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving movement of a requiredFeatures attribute from one SVG document to another.
GHSA
GHSA-9g4c-vw2f-x5wq: Use-after-free vulnerability in the nsTArray_base::Length function in Mozilla Firefox before 15
ghsa_unreviewed·2022-05-17
CVE-2012-3970 [HIGH] GHSA-9g4c-vw2f-x5wq: Use-after-free vulnerability in the nsTArray_base::Length function in Mozilla Firefox before 15
Use-after-free vulnerability in the nsTArray_base::Length function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving movement of a requiredFeatures attribute from one SVG document to another.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-3969 CVE-2012-3970 Mozilla: SVG buffer overflow and use-after-free issues (MFSA 2012-63)
bugzilla·2012-08-27·CVSS 9.3
CVE-2012-3969 [CRITICAL] CVE-2012-3969 CVE-2012-3970 Mozilla: SVG buffer overflow and use-after-free issues (MFSA 2012-63)
CVE-2012-3969 CVE-2012-3970 Mozilla: SVG buffer overflow and use-after-free issues (MFSA 2012-63)
Security researcher Arthur Gerkis used the Address Sanitizer tool to find two issues involving Scalable Vector Graphics (SVG) files. The first issue is a buffer overflow in Gecko's SVG filter code when the sum of two values is too large to be stored as a signed 32-bit integer, causing the function to write past the end of an array. The second issue is a use-after-free when an element with a "requiredFeatures" attribute is moved between documents. In that situation, the internal representation of the "requiredFeatures" value could be freed prematurely. Both issues are potentially exploitable.
Reference:
http://www.mozilla.org/security/announce/2012/mfsa2012-63.html
Acknowledgements:
Red Hat
Bugzilla
CVE-2011-3970 libxslt: Out-of-bounds read when parsing certain patterns
bugzilla·2012-02-09·CVSS 4.3
CVE-2011-3970 [MEDIUM] CVE-2011-3970 libxslt: Out-of-bounds read when parsing certain patterns
CVE-2011-3970 libxslt: Out-of-bounds read when parsing certain patterns
Common Vulnerabilities and Exposures assigned an identifier CVE-2011-3970 to
the following vulnerability:
Name: CVE-2011-3970
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3970
Assigned: 20111001
Reference: CONFIRM:http://code.google.com/p/chromium/issues/detail?id=110277
Reference: CONFIRM:http://googlechromereleases.blogspot.com/2012/02/stable-channel-update.html
libxslt, as used in Google Chrome before 17.0.963.46, allows remote
attackers to cause a denial of service (out-of-bounds read) via
unspecified vectors.
Upstream patch:
http://git.gnome.org/browse/libxslt/commit/?id=fe5a4fa33eb85bce3253ed3742b1ea6c4b59b41b
Discussion:
Created libxslt tracking bugs for this issue
Affects: fedora-all [bug
http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00028.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00014.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1210.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1211.htmlhttp://www.mozilla.org/security/announce/2012/mfsa2012-63.htmlhttp://www.securityfocus.com/bid/55278http://www.ubuntu.com/usn/USN-1548-1http://www.ubuntu.com/usn/USN-1548-2http://www.xerox.com/download/security/security-bulletin/16287-4d6b7b0c81f7b/cert_XRX13-003_v1.0.pdfhttps://bugzilla.mozilla.org/show_bug.cgi?id=760996https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16876http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00028.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00014.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1210.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1211.htmlhttp://www.mozilla.org/security/announce/2012/mfsa2012-63.htmlhttp://www.securityfocus.com/bid/55278http://www.ubuntu.com/usn/USN-1548-1http://www.ubuntu.com/usn/USN-1548-2http://www.xerox.com/download/security/security-bulletin/16287-4d6b7b0c81f7b/cert_XRX13-003_v1.0.pdfhttps://bugzilla.mozilla.org/show_bug.cgi?id=760996https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16876
2012-08-29
Published