|
|
|
Vulnerability Note VU#414240Mozilla Mail vulnerable to buffer overflow via "writeGroup()" function in "nsVCardObj.cpp"OverviewMozilla Mail contains a vulnerability in the display routines for VCards. By sending an email message with a crafted VCard, a remote attacker may be able to execute arbitrary code on the victim's machine with the privileges of the current user.I. DescriptionMozilla Mail contains a stack overflow vulnerability in the display routines for VCards. By sending an email message with a crafted VCard, a remote attacker may be able to execute arbitrary code on the victim's machine with the privileges of the current user. This can be exploited in the preview mode as well.II. ImpactA remote attacker may be able to execute arbitrary code on the victim's machine with the privileges of the current user.III. SolutionThis vulnerability is resolved in Firefox Preview Release, Mozilla 1.7.3, and Thunderbird 0.8.Until a patch or upgrade can be performed, Mozilla recommends the following workaround; Disable in-line display of attachments, don't open VCard attachments.
References
Thanks to Georgi Guninski for reporting this vulnerability. This document was written by Jason A Rafail.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||
|
||||||||||||||||||||||||||||||||||||