Mozilla Foundation Security Advisory 2015-16
Use-after-free in IndexedDB
- Announced
- February 24, 2015
- Reporter
- Paul Bandha
- Impact
- Critical
- Products
- Firefox, Firefox ESR, Firefox OS, SeaMonkey, Thunderbird
- Fixed in
-
- Firefox 36
- Firefox ESR 31.5
- Firefox OS 2.2
- SeaMonkey 2.33
- Thunderbird 31.5
Description
Security researcher Paul Bandha used the used the Address
Sanitizer tool to discover a use-after-free vulnerability when running specific
web content with IndexedDB
to create an index. This leads to a
potentially exploitable crash.
In general this flaw cannot be exploited through email in the Thunderbird product because scripting is disabled, but is potentially a risk in browser or browser-like contexts.