Mozilla Multiple Products Remote Code Execution Vulnerability
JavaScript가 활성화된 경우 Mozilla Firefox 3.5.x~3.5.14 및 3.6.x~3.6.11, Thunderbird 3.1.6 이전의 3.1.6 및 3.0.10 이전의 3.0.x, SeaMonkey 2.0.10 이전의 2.x는 원격 공격자가 nsCSSFrameConstructor::ContentAppended, appendChild 메서드, 잘못된 인덱스 추적 및 다중 프레임 생성과 관련된 벡터를 통해 임의 코드를 실행할 수 있게 하며, 이는 메모리 손상을 유발한다. 2010년 10월 Belmoo 악성코드에 의해 실제로 악용되었다.
JavaScript가 활성화된 경우 Mozilla Firefox 3.5.x~3.5.14 및 3.6.x~3.6.11, Thunderbird 3.1.6 이전의 3.1.6 및 3.0.10 이전의 3.0.x, SeaMonkey 2.0.10 이전의 2.x는 원격 공격자가 nsCSSFrameConstructor::ContentAppended, appendChild 메서드, 잘못된 인덱스 추적 및 다중 프레임 생성과 관련된 벡터를 통해 임의 코드를 실행할 수 있게 하며, 이는 메모리 손상을 유발한다. 2010년 10월 Belmoo 악성코드에 의해 실제로 악용되었다.
한국어 설명은 영문 원문을 기준으로 제공됩니다. 제품명·버전·보안 식별자는 아래 원문과 함께 확인할 수 있습니다.
영문 원문 보기
Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled, allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption, as exploited in the wild in October 2010 by the Belmoo malware.
영향 제품·버전
제품 Mozilla Multiple Products
영향 버전 Mozilla Multiple Products 3.5, 3.5.1, 3.5.2, 3.5.3, 3.5.4, 3.5.5, 3.5.6, 3.5.7, 3.5.8, 3.5.9, 3.5.10, 3.5.11, 3.5.12, 3.5.13, 3.5.14, 3.6, 3.6.2, 3.6.3, 3.6.4
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
조치 기한: 2025.10.27
해당사항 확인방법
Mozilla Multiple Products의 현재 전체 버전이 공식 영향 범위(Mozilla Multiple Products 3.5, 3.5.1, 3.5.2, 3.5.3, 3.5.4, 3.5.5, 3.5.6, 3.5.7, 3.5.8, 3.5.9, 3.5.10, 3.5.11, 3.5.12, 3.5.13, 3.5.14, 3.6, 3.6.2, 3.6.3, 3.6.4)에 포함되는지 확인합니다. OS를 선택하면 해당 OS의 제품·패키지·KB·APAR 확인 명령만 표시됩니다.
조치방안
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
조치 후 확인사항
패치 후 같은 명령으로 전체 버전을 다시 확인해 수정 버전은 공급사 공식자료 확인 필요 기준을 충족하는지 확인합니다. 이어서 메모리 손상 관련 오류·공격 흔적이 새로 발생하지 않는지 확인합니다.