Description: A vulnerability has been reported in Mozilla Firefox, which can be exploited by malicious people to compromise a vulnerable system.
The vulnerability is caused due to an error in the handling of reference counters for CSS objects. This can be exploited to execute arbitrary code via an overly large number of references to a common CSS object
The vulnerability is reported in versions prior to Firefox 3.0.1 and 2.0.0.16, Thunderbird 2.0.0.16, and SeaMonkey 1.1.11.
Provided and/or discovered by: Reported via the Zero Day Initiative.
Changelog: 2008-06-20: Added CVE reference.
2008-07-16: Updated advisory based on new information from Mozilla. Added Thunderbird and SeaMonkey in list of affected software.
2008-07-17: Firefox version 3.0.1 released.
2008-07-18: Added reporter link to the "Original Advisory" section.
2008-07-24: Updated "Solution" section due to the availability of the fixed Thunderbird version.
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.