PT-2005-4833 · Netscape+4 · Netscape+4

Publicado

2005-12-09

·

Atualizado

2018-10-19

·

CVE-2005-4134

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Mozilla Firefox version 1.5 Netscape versions 7.2 and 8.0.4 K-Meleon versions prior to 0.9.12
Description The issue allows remote attackers to cause a denial of service, resulting in CPU consumption and delayed application startup, via a web site with a large title. This title is recorded in history.dat but not processed efficiently during startup. It has been reported that Netscape 8.1 does not have this issue.
Recommendations For Mozilla Firefox version 1.5, consider restricting the size of titles that can be recorded in history.dat to prevent excessive CPU consumption. For Netscape versions 7.2 and 8.0.4, avoid using the affected versions until a fix is available. For K-Meleon versions prior to 0.9.12, update to version 0.9.12 or later to resolve the issue.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-4134
DSA-1044-1
DSA-1046-1
DSA-1051-1
HPSBUX02122
RHSA-2006:0200
RHSA-2006_0200

Produtos afetados

Hp-Ux
K-Meleon
Firefox
Netscape
Red Hat