The find_replen function in jsstr.c in the Javascript engine for Mozilla Suite 1.7.6, Firefox 1.0.1 and 1.0.2, and Netscape 7.2 allows remote attackers to read portions of heap memory in a Javascript string via the lambda replace method.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Firefox | Mozilla | 1.0.1 (including) | 1.0.1 (including) |
Firefox | Mozilla | 1.0.2 (including) | 1.0.2 (including) |
Mozilla | Mozilla | 1.7.6 (including) | 1.7.6 (including) |
Navigator | Netscape | 7.2 (including) | 7.2 (including) |
Red Hat Enterprise Linux 2.1 | RedHat | galeon | * |
Red Hat Enterprise Linux 2.1 | RedHat | mozilla | * |
Red Hat Enterprise Linux 3 | RedHat | mozilla | * |
Red Hat Enterprise Linux 4 | RedHat | firefox-0:1.0.3-1.4.1 | * |
Red Hat Enterprise Linux 4 | RedHat | devhelp-0:0.9.2-2.4.4 | * |
Red Hat Enterprise Linux 4 | RedHat | thunderbird-0:1.0.6-1.4.1 | * |
Mozilla | Ubuntu | dapper | * |
Mozilla | Ubuntu | edgy | * |
Mozilla-thunderbird | Ubuntu | dapper | * |
Mozilla-thunderbird | Ubuntu | edgy | * |
Mozilla-thunderbird | Ubuntu | feisty | * |