The find_replen function in jsstr.c in the Javascript engine for Mozilla Suite 1.7.6, Firefox 1.0.1 and 1.0.2, and Netscape 7.2 allows remote attackers to read portions of heap memory in a Javascript string via the lambda replace method.
Software | From | Fixed in |
---|---|---|
netscape / navigator | 7.2 | 7.2.x |
mozilla / mozilla | 1.7.6 | 1.7.6.x |
mozilla / firefox | 1.0.1 | 1.0.1.x |
mozilla / firefox | 1.0.2 | 1.0.2.x |