PT-2005-3194 · Mozilla+2 · Mozilla Firefox+3
John Dalbec
·
Publicado
2005-07-13
·
Atualizado
2017-10-11
·
CVE-2005-2265
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions:
Firefox versions prior to 1.0.5
Mozilla versions prior to 1.7.9
Netscape versions 7.2 and 8.0.2
Description:
The issue allows remote attackers to cause a denial of service, resulting in an access violation and crash, and possibly execute arbitrary code. This is achieved by calling
InstallVersion.compareTo with an object instead of a string.Recommendations:
For Firefox versions prior to 1.0.5, update to version 1.0.5 or later.
For Mozilla versions prior to 1.7.9, update to version 1.7.9 or later.
For Netscape versions 7.2 and 8.0.2, consider disabling the
InstallVersion.compareTo function as a temporary workaround until a patch is available.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Firefox
Mozilla Firefox
Netscape
Red Hat