Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site.
The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Firefox | Mozilla | * | 21.0 (excluding) |
Firefox | Mozilla | 17.0 (including) | 17.0.6 (excluding) |
Thunderbird | Mozilla | * | 17.0.6 (excluding) |
Thunderbird_esr | Mozilla | 17.0 (including) | 17.0.6 (excluding) |
Red Hat Enterprise Linux 5 | RedHat | thunderbird-0:17.0.6-1.el5_9 | * |
Red Hat Enterprise Linux 5 | RedHat | firefox-0:17.0.6-1.el5_9 | * |
Red Hat Enterprise Linux 5 | RedHat | xulrunner-0:17.0.6-1.el5_9 | * |
Red Hat Enterprise Linux 6 | RedHat | firefox-0:17.0.6-1.el6_4 | * |
Red Hat Enterprise Linux 6 | RedHat | xulrunner-0:17.0.6-2.el6_4 | * |
Red Hat Enterprise Linux 6 | RedHat | thunderbird-0:17.0.6-2.el6_4 | * |
Firefox | Ubuntu | devel | * |
Firefox | Ubuntu | lucid | * |
Firefox | Ubuntu | precise | * |
Firefox | Ubuntu | quantal | * |
Firefox | Ubuntu | raring | * |
Firefox | Ubuntu | upstream | * |
Seamonkey | Ubuntu | lucid | * |
Thunderbird | Ubuntu | devel | * |
Thunderbird | Ubuntu | lucid | * |
Thunderbird | Ubuntu | precise | * |
Thunderbird | Ubuntu | quantal | * |
Thunderbird | Ubuntu | raring | * |
Thunderbird | Ubuntu | upstream | * |
Xulrunner-1.9.2 | Ubuntu | lucid | * |