Bug 630061 (CVE-2010-3166)

Summary: CVE-2010-3166 Mozilla Heap buffer overflow in nsTextFrameUtils::TransformText (MFSA 2010-53)
Product: [Other] Security Response Reporter: Josh Bressers <bressers>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: urgent Docs Contact:
Priority: urgent    
Version: unspecifiedCC: gecko-bugs-nobody, security-response-team, vdanen
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard: public=20100907,reported=20100901,source=mozilla,impact=critical,cvss2=6.8/AV:N/AC:M/Au:N/C:P/I:P/A:P,rhel-4.8.z/firefox=affected,rhel-5.5.z/firefox=affected,rhel-6.0/firefox=affected,cwe=CWE-122[auto]
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2013-04-12 14:21:24 EDT Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Description Josh Bressers 2010-09-03 11:50:19 EDT
Security researcher wushi of team509 reported a heap buffer overflow in
code routines responsible for transforming text runs. A page could be
constructed with a bidirectional text run which upon reflow could result in
an incorrect length being calculated for the run of text. When this value
is subsequently used to allocate memory for the text too small a buffer may
be created potentially resulting in a buffer overflow and the execution of
attacker controlled memory.
Comment 1 Vincent Danen 2010-09-07 19:21:18 EDT
This is now public:

Comment 2 errata-xmlrpc 2010-09-07 20:33:59 EDT
This issue has been addressed in following products:

  Red Hat Enterprise Linux 4
  Red Hat Enterprise Linux 5

Via RHSA-2010:0681 https://rhn.redhat.com/errata/RHSA-2010-0681.html