Security testing
Scanit offers penetration tests, vulnerability assessments and web application audits.
Learn ethical hacking.
Scanit offers 5-day training on ethical hacking.

Mozilla crashes with evidence of memory corruption (rv:1.8.1.5) (CVE-2007-3734)

Description

Several bugs that lead to memory corruption were discovered in Mozilla layout and JavaScript engine. The bugs allow a specially crafted web page to crash the browser or execute arbitrary code.

This is an arbitrary code execution vulnerability. It means that it can be used to place a backdoor, a virus or spyware on the vulnerable computer.

Recommendations

If you are running Mozilla Firefox 2 upgrade to version 2.0.0.5 or later. If you are running Mozilla Firefox 1.0 or 1.5 upgrade to 2.0 branch. Firefox 1.0 and 1.5 are no longer supported by Mozilla Foundation.

If you are running Mozilla SeaMonkey upgrade to version 1.1.3 or later.

If you are using some other Mozilla-based browser, try upgrading to the latest available version or consult your vendor.

References