PT-2011-1347 · Palm · Webos

Townsend Ladd Harris

·

Published

2011-09-13

·

Updated

2018-10-10

·

CVE-2009-5098

CVSS v2.0

5.4

Medium

VectorAV:N/AC:H/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Palm Pre WebOS versions 1.1 and earlier
Description The issue allows remote attackers to cause a denial of service, resulting in a crash, by exploiting a weakness in the LunaSysMgr process. This occurs when a web page containing a long string following a refresh tag is accessed, triggering a floating point exception. The estimated number of potentially affected devices worldwide is not specified.
Recommendations For Palm Pre WebOS versions 1.1 and earlier, consider avoiding the use of web pages with long strings following refresh tags until a fix is available. As a temporary workaround, users may want to view web pages in landscape mode to potentially mitigate the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-5098

Affected Products

Webos