The nsDisplayList::HitTest function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 mishandles rendering display transformation, which allows remote attackers to execute arbitrary code via a crafted web site that leverages type confusion.
The product does not correctly convert an object, resource, or structure from one type to a different type.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Firefox | Mozilla | * | 47.0.1 (including) |
Firefox | Mozilla | 45.1.0 (including) | 45.1.0 (including) |
Firefox | Mozilla | 45.1.1 (including) | 45.1.1 (including) |
Firefox | Mozilla | 45.2.0 (including) | 45.2.0 (including) |
Firefox | Mozilla | 45.3.0 (including) | 45.3.0 (including) |
Red Hat Enterprise Linux 5 | RedHat | firefox-0:45.3.0-1.el5_11 | * |
Red Hat Enterprise Linux 6 | RedHat | firefox-0:45.3.0-1.el6_8 | * |
Red Hat Enterprise Linux 7 | RedHat | firefox-0:45.3.0-1.el7_2 | * |
Firefox | Ubuntu | precise | * |
Firefox | Ubuntu | trusty | * |
Firefox | Ubuntu | upstream | * |
Firefox | Ubuntu | xenial | * |