Mozilla Firefox နှင့် Thunderbird တွင် Use-After-Free Memory-Corruption Vulnerability ရှိ
Mozilla Firefox နှင့် Thunderbird တွင် Use-After-Free Memory-Corruption Vulnerability ရှိကြောင်းကို Security Focus မှ (၅.၈.၂ဝ၁၄) ရက်နေ့တွင် ကြေညာခဲ့သည်။ ၄င်း Vulnerability မှတဆင့် Attacker များသည် Context ထဲတွင် Arbitrary Code ထည့်၍ Exploit ပြုလုပ်နိုင်ပါသည်။ ထို E×ploit သည် Denial-of-Service(DoS) ဖြစ်နိုင်သည့် အခြေအနေထိ ရောက်ရှိနိုင်ပါသည်။ Firefox 31, Thunderbird 31, Firefox ESR 24.7, Thunderbird 24.7 တို့တွင် Vulnerabilityမျာ:ကိုဖြေရှင်းပြီး ဖြစ်ပါသည်။ အသေးစိတ်ကို အောက်ပါ Link များတွင်ကြည့်ရှုနိုင်ပါသည်။
http://www.securityfocus.com/bid/68816/discuss
http://cwe.mitre.org/data/definitions/416.html
Use-After-Free Memory-Corruption Vulnerability is a referencing memory after it has been freed can cause a program to crash.
The following code illustrates a use after free error:
Example Language: C
char* ptr = (char*)malloc (SIZE);
if (err) {
abrt = 1;
free(ptr);} ...
if (abrt) {
logError("operation aborted before commit", ptr); }
When an error occurs, the pointer is immediately freed. However, this pointer is later incorrectly used in the logError function.
၄-၈-၂၀၁၄
