关键信息 Advisory: 2006-32 Title: Fixes for crashes with potential memory corruption (rv:1.8.0.4) Announced: June 1, 2006 Reporter: Mozilla Developers Impact: Critical Products: Firefox, SeaMonkey, Thunderbird Fixed in: Firefox 1.5.0.4, SeaMonkey 1.0.2, Thunderbird 1.5.0.4 Description Mozilla team members discovered several crashes during testing of the browser engine showing evidence of memory corruption that we presume is exploitable. Workaround Disable Javascript until you can upgrade to a fixed version. References Removing nested s from a select (Jesse Ruderman) - https://bugzilla.mozilla.org/show_bug.cgi?id=324918 Crashes during DOMNodeRemoved mutation event - https://bugzilla.mozilla.org/show_bug.cgi?id=325730 - https://bugzilla.mozilla.org/show_bug.cgi?id=329982 Content-implemented tree views can corrupt memory (Boris Zbarsky) - https://bugzilla.mozilla.org/show_bug.cgi?id=326501 Memory corruption involving BoxObjects (Boris Zbarsky, Neil Rashbrook, Georgi Guninski) - https://bugzilla.mozilla.org/show_bug.cgi?id=326931 - [更多链接...] XBL implementation doesn't root temporaries correctly (L. David Baron) - https://bugzilla.mozilla.org/show_bug.cgi?id=327712 crash with iframe removing itself (Georgi Guninski) - https://bugzilla.mozilla.org/show_bug.cgi?id=332971 potential integer overflow in jsstr tagify (Georgi Guninski) - https://bugzilla.mozilla.org/show_bug.cgi?id=335535