---------------------------------------------------------------------- Want a new job? http://secunia.com/secunia_security_specialist/ http://secunia.com/hardcore_disassembler_and_reverse_engineer/ International Partner Manager - Project Sales in the IT-Security Industry: http://corporate.secunia.com/about_secunia/64/ ---------------------------------------------------------------------- TITLE: Mozilla Firefox 3 on Mac OS X GIF File Handling Code Execution SECUNIA ADVISORY ID: SA31132 VERIFY ADVISORY: http://secunia.com/advisories/31132/ CRITICAL: Highly critical IMPACT: System access WHERE: >From remote OPERATING SYSTEM: Apple Macintosh OS X http://secunia.com/product/96/ SOFTWARE: Mozilla Firefox 3.x http://secunia.com/product/19089/ DESCRIPTION: A vulnerability has been reported in Firefox 3 on Mac OS X, which potentially can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to an error in the Mozilla graphics code on Mac OS X. This can be exploited to free an uninitialised pointer via a specially crafted GIF file. Successful exploitation may allow execution of arbitrary code. SOLUTION: Update to version 3.0.1. http://www.mozilla.com/en-US/firefox/ PROVIDED AND/OR DISCOVERED BY: The vendor credits Drew Yao of Apple Product Security. ORIGINAL ADVISORY: MFSA 2008-36: http://www.mozilla.org/security/announce/2008/mfsa2008-36.html ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help everybody keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------