Skip to main content
x

Mozilla Firefox နှင့် Thunderbird တွင် Use-After-Free Memory-Corruption Vulnerability ရှိ

Mozilla Firefox နှင့် Thunderbird တွင် Use-After-Free Memory-Corruption Vulnerability ရှိကြောင်းကို Security Focus မှ (၅.၈.၂ဝ၁၄) ရက်နေ့တွင် ကြေညာခဲ့သည်။ ၄င်း Vulnerability မှတဆင့် Attacker များသည် Context ထဲတွင် Arbitrary Code ထည့်၍ Exploit ပြုလုပ်နိုင်ပါသည်။ ထို E×ploit သည် Denial-of-Service(DoS) ဖြစ်နိုင်သည့် အခြေအနေထိ ရောက်ရှိနိုင်ပါသည်။ Firefox 31, Thunderbird 31, Firefox ESR 24.7, Thunderbird 24.7 တို့တွင် Vulnerabilityမျာ:ကိုဖြေရှင်းပြီး ဖြစ်ပါသည်။ အသေးစိတ်ကို အောက်ပါ Link များတွင်ကြည့်ရှုနိုင်ပါသည်။

http://www.securityfocus.com/bid/68816/discuss

http://cwe.mitre.org/data/definitions/416.html

Use-After-Free Memory-Corruption Vulnerability is a referencing memory after it has been freed can cause a program to crash.

The following code illustrates a use after free error:

Example Language: C

char* ptr = (char*)malloc (SIZE);

if (err) {

abrt = 1;

free(ptr);} ...

if (abrt) {

logError("operation aborted before commit", ptr); }

When an error occurs, the pointer is immediately freed. However, this pointer is later incorrectly used in the logError function.

၄-၈-၂၀၁၄