PT-2005-4833 · Netscape+4 · Netscape+4

Published

2005-12-09

·

Updated

2018-10-19

·

CVE-2005-4134

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Mozilla Firefox version 1.5 Netscape versions 7.2 and 8.0.4 K-Meleon versions prior to 0.9.12
Description The issue allows remote attackers to cause a denial of service, resulting in CPU consumption and delayed application startup, via a web site with a large title. This title is recorded in history.dat but not processed efficiently during startup. It has been reported that Netscape 8.1 does not have this issue.
Recommendations For Mozilla Firefox version 1.5, consider restricting the size of titles that can be recorded in history.dat to prevent excessive CPU consumption. For Netscape versions 7.2 and 8.0.4, avoid using the affected versions until a fix is available. For K-Meleon versions prior to 0.9.12, update to version 0.9.12 or later to resolve the issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-4134
DSA-1044-1
DSA-1046-1
DSA-1051-1
HPSBUX02122
RHSA-2006:0200
RHSA-2006_0200

Affected Products

Hp-Ux
K-Meleon
Firefox
Netscape
Red Hat