Mozilla Foundation Security Advisory 2011-06
Use-after-free error using Web Workers
- Announced
- March 1, 2011
- Reporter
- Daniel Kozlowski
- Impact
- Critical
- Products
- Firefox, SeaMonkey
- Fixed in
-
- Firefox 3.5.17
- Firefox 3.6.14
- SeaMonkey 2.0.12
Description
Daniel Kozlowski reported that a
JavaScript Worker
could be used to keep a reference to an
object that could be freed during garbage collection. Subsequent
calls through this deleted reference could cause attacker-controlled
memory to be executed on a victim's computer.