PT-2005-1335 · Mozilla+1 · Thunderbird+3

Daniel De Wildt

+1

·

Published

2005-02-28

·

Updated

2017-10-11

·

CVE-2005-0255

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Mozilla versions 1.7.3 Firefox version 1.0 Thunderbird versions prior to 1.0.2
Description The issue is related to string handling functions, such as the nsTSubstring CharT::Replace function, which do not properly check the return values of other functions that resize the string. This allows remote attackers to cause a denial of service and possibly execute arbitrary code by forcing an out-of-memory state that causes a reallocation to fail and return a pointer to a fixed address, leading to heap corruption.
Recommendations For Mozilla version 1.7.3, update to a version that includes the fix for this issue. For Firefox version 1.0, update to a version that includes the fix for this issue. For Thunderbird versions prior to 1.0.2, update to version 1.0.2 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-0255
RHSA-2005:176
RHSA-2005:337
RHSA-2005_176
RHSA-2005_277
RHSA-2005_337

Affected Products

Firefox
Mozilla Firefox
Red Hat
Thunderbird