Description: Sun has acknowledged some vulnerabilities in Mozilla 1.7 for Sun Solaris, which can potentially be exploited by malicious people to compromise a vulnerable system.
1) A memory corruption error may potentially be exploited to execute arbitrary code.
For more information see vulnerability #11 in: SA19873
2) An error within the handling of Script objects can potentially be exploited to execute arbitrary JavaScript bytecode.
For more information see vulnerability #2 in: SA22722
The vulnerabilities are reported in Mozilla 1.7 for Sun Solaris 8, 9, and 10 for both the x86 and SPARC platforms. Mozilla 1.4 may also be affected.
Changelog: 2007-07-25: Updated "Description" section with additional vulnerability. Added link to "Original advisory" and "Other References" section. Added CVE reference.
2007-08-24: Updated "Solution" section.
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.