PT-2004-2545 · Mozilla · Firefox+2

Published

2004-10-26

·

Updated

2017-07-11

·

CVE-2004-1639

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 0.10 Mozilla version 5.0 Gecko version 20040913
Description The issue allows remote attackers to cause a denial of service, resulting in application crash or memory consumption, by sending a large binary file with a .html extension.
Recommendations For Mozilla Firefox versions prior to 0.10, update to a version later than 0.10 to resolve the issue. For Mozilla version 5.0, consider disabling the handling of large binary files with .html extensions as a temporary workaround until a patch is available. For Gecko version 20040913, restrict access to large binary files to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-1639

Affected Products

Gecko
Mozilla Firefox
Firefox