PT-2005-2013 · Mozilla+2 · Suite+3
Brendan
+1
·
Publicado
2005-04-06
·
Atualizado
2018-05-03
·
CVE-2005-0989
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Mozilla Suite version 1.7.6
Firefox versions 1.0.1 through 1.0.2
Netscape version 7.2
Description
The issue allows remote attackers to read portions of heap memory in a Javascript string. This is achieved via the lambda replace method in the
find replen function.Recommendations
For Mozilla Suite version 1.7.6, consider disabling the lambda replace method until a patch is available.
For Firefox versions 1.0.1 through 1.0.2, restrict access to the
find replen function in the Javascript engine to minimize the risk of exploitation.
For Netscape version 7.2, avoid using the lambda replace method in the Javascript engine until the issue is resolved.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Firefox
Suite
Netscape
Red Hat