SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#808216

Mozilla contains heap overflow in UTF8 conversion of hostname portion of URLs

Overview

A vulnerability in the way Mozilla and its derived programs handle certain malformed URLs could allow a remote attacker to execute arbitrary code on a vulnerable system.

I. Description

A vulnerability exists in the way that some versions of the Mozilla and Firefox web browsers, and Thunderbird email client handle long URLs containing non-ASCII characters. The vulnerability results from a buffer overflow error in heap memory that occurs during UTF8 conversion of the hostname portion of the URL. This vulnerability could be exploited by a remote attacker by supplying a specially crafted URL in a web page or email message.

II. Impact

A remote attacker may be able to execute arbitrary code with the privileges of the user running an affected program.

III. Solution

Upgrade to a fixed version of the affected software

The Mozilla Project has released new versions of the affected software that include patches for this vulnerability. Please see the Systems Affected section of this document for more information.

Systems Affected

VendorStatusDate Updated
MozillaVulnerable17-Sep-2004

References


http://bugzilla.mozilla.org/show_bug.cgi?id=256316
http://secunia.com/advisories/12526/

Credit

Information about this issue was originally published by the Mozilla Project. The Mozilla Project, in turn, credits Gaël Delalleau and Mats Palmgren with independent discoveries of this issue.

This document was written by Chad R Dougherty.

Other Information

Date Public09/14/2004
Date First Published09/17/2004 02:08:43 PM
Date Last Updated09/17/2004
CERT Advisory 
CVE Name 
US-CERT Technical Alerts 
Metric28.59
Document Revision7

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2004 Carnegie Mellon University
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader