PT-2005-1335 · Mozilla+1 · Thunderbird+3

Daniel De Wildt

+1

·

Publicado

2005-02-28

·

Atualizado

2017-10-11

·

CVE-2005-0255

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Mozilla versions 1.7.3 Firefox version 1.0 Thunderbird versions prior to 1.0.2
Description The issue is related to string handling functions, such as the nsTSubstring CharT::Replace function, which do not properly check the return values of other functions that resize the string. This allows remote attackers to cause a denial of service and possibly execute arbitrary code by forcing an out-of-memory state that causes a reallocation to fail and return a pointer to a fixed address, leading to heap corruption.
Recommendations For Mozilla version 1.7.3, update to a version that includes the fix for this issue. For Firefox version 1.0, update to a version that includes the fix for this issue. For Thunderbird versions prior to 1.0.2, update to version 1.0.2 or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-0255
RHSA-2005:176
RHSA-2005:337
RHSA-2005_176
RHSA-2005_277
RHSA-2005_337

Produtos afetados

Firefox
Mozilla Firefox
Red Hat
Thunderbird