CVE-2004-0903
Summary
| CVE | CVE-2004-0903 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-01-27 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Stack-based buffer overflow in the writeGroup function in nsVCardObj.cpp for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to execute arbitrary code via malformed VCard attachments that are not properly handled when previewing a message. |
Risk And Classification
Primary CVSS: v2.0 10 from [email protected]
AV:N/AC:L/Au:N/C:C/I:C/A:C
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Conectiva | Linux | 10.0 | All | All | All |
| Operating System | Conectiva | Linux | 9.0 | All | All | All |
| Application | Mozilla | Mozilla | 1.7 | All | All | All |
| Application | Mozilla | Mozilla | 1.7.1 | All | All | All |
| Application | Mozilla | Mozilla | 1.7.2 | All | All | All |
| Application | Mozilla | Thunderbird | 0.7 | All | All | All |
| Application | Mozilla | Thunderbird | 0.7.1 | All | All | All |
| Application | Mozilla | Thunderbird | 0.7.2 | All | All | All |
| Application | Mozilla | Thunderbird | 0.7.3 | All | All | All |
| Operating System | Redhat | Enterprise Linux | 2.1 | All | advanced_server | All |
| Operating System | Redhat | Enterprise Linux | 2.1 | All | advanced_server_ia64 | All |
| Operating System | Redhat | Enterprise Linux | 2.1 | All | enterprise_server | All |
| Operating System | Redhat | Enterprise Linux | 2.1 | All | enterprise_server_ia64 | All |
| Operating System | Redhat | Enterprise Linux | 2.1 | All | workstation | All |
| Operating System | Redhat | Enterprise Linux | 2.1 | All | workstation_ia64 | All |
| Operating System | Redhat | Enterprise Linux | 3.0 | All | advanced_server | All |
| Operating System | Redhat | Enterprise Linux | 3.0 | All | enterprise_server | All |
| Operating System | Redhat | Enterprise Linux | 3.0 | All | workstation_server | All |
| Operating System | Redhat | Enterprise Linux Desktop | 3.0 | All | All | All |
| Operating System | Redhat | Fedora Core | core_1.0 | All | All | All |
| Operating System | Redhat | Linux | 7.3 | All | All | All |
| Operating System | Redhat | Linux | 7.3 | All | i386 | All |
| Operating System | Redhat | Linux | 7.3 | All | i686 | All |
| Operating System | Redhat | Linux | 9.0 | All | i386 | All |
| Operating System | Redhat | Linux Advanced Workstation | 2.1 | All | ia64 | All |
| Operating System | Redhat | Linux Advanced Workstation | 2.1 | All | itanium_processor | All |
| Operating System | Suse | Suse Linux | 1.0 | All | desktop | All |
| Operating System | Suse | Suse Linux | 8 | All | enterprise_server | All |
| Operating System | Suse | Suse Linux | 8.1 | All | All | All |
| Operating System | Suse | Suse Linux | 8.2 | All | All | All |
| Operating System | Suse | Suse Linux | 9.0 | All | All | All |
| Operating System | Suse | Suse Linux | 9.0 | All | enterprise_server | All |
| Operating System | Suse | Suse Linux | 9.0 | All | x86_64 | All |
| Operating System | Suse | Suse Linux | 9.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 257314 – stack based buffer overflow with vcards when previewing email message | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | Vendor Advisory |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| '[security bulletin]SSRT4826 rev.0 Mozilla Application Suite for HP Tru64 UNIX Multiple Potential Sec' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Security Announcement | af854a3a-2127-422b-91ae-364da2661108 | www.novell.com | |
| Mozilla Security Advisory | af854a3a-2127-422b-91ae-364da2661108 | www.mozilla.org | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| US-CERT Technical Cyber Security Alert TA04-261A -- Multiple vulnerabilities in Mozilla products | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | US Government Resource |
| Gentoo Linux Documentation -- Mozilla, Firefox, Thunderbird, Epiphany: New releases fix vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| '[FLSA-2004:2089] Updated mozilla packages fix security vulnerabilities' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| US-CERT Vulnerability Note VU#414240 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | Third Party Advisory, US Government Resource |
| Mozilla Browser Vcard Handling Remote Buffer Overflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.