RULE(RULE ID:313007)

Rule General Information
Release Date: 2016-10-20
Rule Name: WEB-CLIENT Mozilla Firefox XSL Transformation Memory Corruption Vulnerability -2 (CVE-2009-1169)
Severity:
CVE ID:
Rule Protection Details
Description: The txMozillaXSLTProcessor::TransformToDoc function in Mozilla Firefox before 3.0.8 and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XML file with a crafted XSLT transform.
Impact: An attacker can execute arbitrary code in the context of the vulnerable system. Failed exploit may cause denial-of-service attack.
Affected OS: Windows, Solaris, Other Unix, FreeBSD, Linux
Reference: SecurityFocusBID:34235
SecurityTrackerID:1021939
Solutions
Upgrade to version 2.0 8 to solve the problem.