PT-2005-2013 · Mozilla+2 · Suite+3

Brendan

+1

·

Published

2005-04-06

·

Updated

2018-05-03

·

CVE-2005-0989

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mozilla Suite version 1.7.6 Firefox versions 1.0.1 through 1.0.2 Netscape version 7.2
Description The issue allows remote attackers to read portions of heap memory in a Javascript string. This is achieved via the lambda replace method in the find replen function.
Recommendations For Mozilla Suite version 1.7.6, consider disabling the lambda replace method until a patch is available. For Firefox versions 1.0.1 through 1.0.2, restrict access to the find replen function in the Javascript engine to minimize the risk of exploitation. For Netscape version 7.2, avoid using the lambda replace method in the Javascript engine until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-0989
DSA-781-1
RHSA-2005:383
RHSA-2005:386
RHSA-2005:601
RHSA-2005_383
RHSA-2005_384
RHSA-2005_386
RHSA-2005_601

Affected Products

Firefox
Suite
Netscape
Red Hat