PT-2009-1316 · Tencent · Foxmail

Published

2009-01-05

·

Updated

2017-08-08

·

CVE-2008-5839

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Foxmail version 6.5
Description A buffer overflow issue allows remote attackers to execute arbitrary code via a long mailto URI in the HREF attribute of an A element.
Recommendations For Foxmail version 6.5, consider avoiding the use of long mailto URIs in the HREF attribute of an A element until a patch is available. As a temporary workaround, restrict the handling of mailto URIs to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-5839

Affected Products

Foxmail