CVE-2007-1092

Impact:
Critical
Public Date:
2007-02-23

The MITRE CVE dictionary describes this issue as:

Mozilla Firefox 1.5.0.9 and 2.0.0.1, and SeaMonkey before 1.0.8 allow remote attackers to execute arbitrary code via JavaScript onUnload handlers that modify the structure of a document, wich triggers memory corruption due to the lack of a finalize hook on DOM window objects.

Find out more about CVE-2007-1092 from the MITRE CVE dictionary dictionary and NIST NVD.

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux version 4 (thunderbird) RHSA-2007:0078 2007-03-02
Red Hat Enterprise Linux version 4 (firefox) RHSA-2007:0079 2007-02-23
Red Hat Enterprise Linux version 2.1 (seamonkey) RHSA-2007:0077 2007-02-24
Red Hat Enterprise Linux version 3 (seamonkey) RHSA-2007:0077 2007-02-24
Red Hat Enterprise Linux version 4 RHSA-2007:0077 2007-02-24

Affected Packages State

Platform Package State
Red Hat Enterprise Linux version 4 devhelp 0.10-0.7.el4 Fixed
Red Hat Enterprise Linux version 4 seamonkey 1.0.8-0.2.el4 Fixed