You are here: Security Center > Mozilla Foundation Security Advisories > MFSA 2013-66

Mozilla Foundation Security Advisory 2013-66

Title: Buffer overflow in Mozilla Maintenance Service and Mozilla Updater
Impact: High
Announced: August 6, 2013
Reporter: Seb Patane
Products: Firefox, Thunderbird, Seamonkey

Fixed in: Firefox 23.0
  Firefox ESR 17.0.8
  Thunderbird 17.0.8
  Thunderbird ESR 17.0.8
  Seamonkey 2.20

Description

Security researcher Seb Patane reported stack buffer overflows in both the Maintenance Service and the Mozilla Updater when unexpectedly long paths were encountered. A local attacker could pass these as command-line arguments to the Maintenance Service to crash either program and potentially lead to arbitrary code being run with the Administrator privileges used by the Maintenance Service and inherited by the Updater.

References