Crashes with evidence of memory corruption (184.108.40.206)
As part of the Firefox 220.127.116.11 release we fixed several crash bugs to
improve the stability of the product, with a particular focus on finding
crashes caused by DHTML. Some of these crashes showed evidence of memory
corruption that we presume could be exploited to run arbitrary code with
Note: Thunderbird shares the browser engine with Firefox and could be
the mail portion of SeaMonkey.
Also fixed in Firefox/Thunderbird 1.0.8, Mozilla Suite 1.7.13
Muck with the boxobject's internal frame pointer.
This issue also affects FC4
So was this ever fixed in FC5? FC4? With Seamonkey, maybe?
Ah. I see that this was indeed fixed on 2006-05-03, for both FC4 and FC5
(but not mentioned in the advisories.) The update to Mozilla-1.7.13 fixed
this issue along with the others mentioned.
This bug was fixed for FC4 in Fedora Update FEDORA-2006-488
This bug was fixed for FC5 in Fedora Update FEDORA-2006-487
Going ahead and closing this ERRATA.