Vulnerability Note VU#414240

Mozilla Mail vulnerable to buffer overflow via "writeGroup()" function in "nsVCardObj.cpp"

Original Release date: 17 Sep 2004 | Last revised: 17 Sep 2004

Overview

Mozilla Mail contains a vulnerability in the display routines for VCards. By sending an email message with a crafted VCard, a remote attacker may be able to execute arbitrary code on the victim's machine with the privileges of the current user.

Description

Mozilla Mail contains a stack overflow vulnerability in the display routines for VCards. By sending an email message with a crafted VCard, a remote attacker may be able to execute arbitrary code on the victim's machine with the privileges of the current user. This can be exploited in the preview mode as well.

Impact

A remote attacker may be able to execute arbitrary code on the victim's machine with the privileges of the current user.

Solution

This vulnerability is resolved in Firefox Preview Release, Mozilla 1.7.3, and Thunderbird 0.8.

Until a patch or upgrade can be performed, Mozilla recommends the following workaround; Disable in-line display of attachments, don't open VCard attachments.

Systems Affected (Learn More)

VendorStatusDate NotifiedDate Updated
MozillaNot Affected-17 Sep 2004
If you are a vendor and your product is affected, let us know.

CVSS Metrics (Learn More)

Group Score Vector
Base N/A N/A
Temporal N/A N/A
Environmental N/A N/A

References

Credit

Thanks to Georgi Guninski for reporting this vulnerability.

This document was written by Jason A Rafail.

Other Information

  • CVE IDs: Unknown
  • Date Public: 14 Sep 2004
  • Date First Published: 17 Sep 2004
  • Date Last Updated: 17 Sep 2004
  • Severity Metric: 32.40
  • Document Revision: 8

Feedback

If you have feedback, comments, or additional information about this vulnerability, please send us email.