Mozilla Multiple URI Processing Heap Based Buffer Overflow Vulnerabilities
BID:11170
Info
Mozilla Multiple URI Processing Heap Based Buffer Overflow Vulnerabilities
| Bugtraq ID: | 11170 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2004-0902 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 14 2004 12:00AM |
| Updated: | Jul 12 2009 07:06AM |
| Credit: | Discovery of this issue is credited to Georgi Guninski <[email protected]>. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 8 SuSE Linux Enterprise Server 9 SuSE Linux Desktop 1.0 SuSE Linux 8.1 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 S.u.S.E. Linux Personal 8.2 Redhat Linux 9.0 i386 Redhat Linux 7.3 i686 Redhat Linux 7.3 i386 Redhat Linux 7.3 Redhat Fedora Core1 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux WS 2.1 IA64 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux ES 2.1 IA64 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux AS 3 Redhat Enterprise Linux AS 2.1 IA64 Redhat Enterprise Linux AS 2.1 Redhat Desktop 3.0 Redhat Advanced Workstation for the Itanium Processor 2.1 IA64 Redhat Advanced Workstation for the Itanium Processor 2.1 Mozilla Thunderbird 0.7.3 Mozilla Thunderbird 0.7.2 Mozilla Thunderbird 0.7.1 Mozilla Thunderbird 0.7 Mozilla Browser 1.7.2 Mozilla Browser 1.7.1 Mozilla Browser 1.7 |
| Not Vulnerable: |
Mozilla Thunderbird 0.8 Mozilla Browser 1.7.3 |
Discussion
Mozilla Multiple URI Processing Heap Based Buffer Overflow Vulnerabilities
Mozilla is reportedly affected by multiple heap based buffer overflow vulnerabilities when processing URIs in emails. These issues are due to a failure of the affected application to validate user-supplied string lengths before copying them into finite process buffers.
An attacker might leverage these issues to have arbitrary code executed in the context of the user running the vulnerable application.
Mozilla is reportedly affected by multiple heap based buffer overflow vulnerabilities when processing URIs in emails. These issues are due to a failure of the affected application to validate user-supplied string lengths before copying them into finite process buffers.
An attacker might leverage these issues to have arbitrary code executed in the context of the user running the vulnerable application.
Exploit / POC
Mozilla Multiple URI Processing Heap Based Buffer Overflow Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Mozilla Multiple URI Processing Heap Based Buffer Overflow Vulnerabilities
Solution:
This issue has been addressed in Mozilla 1.7.3 and Thunderbird 0.8.
Conectiva has released an advisory (CLA-2004:877) to address various issues including this issue in Mozilla. This advisory contains updated Mozilla packages (1.7.3) for Conectiva Linux 9 and 10. Please see the referenced advisory for more information.
Gentoo has released an advisory (GLSA 200409-26) to address various issues in Mozilla Browsers. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their systems.
emerge sync
emerge -pv your-version
emerge your-version
RedHat Linux has released advisory RHSA-2004:486-18 along with fixes to address this, and other issues for RedHat Enterprise Linux operating systems. Please see the referenced advisory for further information on obtaining fixes.
HP has released an advisory (SSRT4826) dealing with this issue for their Tru64 UNIX platform. Please see the referenced advisory for more information.
SuSE Linux has released advisory SUSE-SA:2004:036 along with fixes dealing with this issue. Please see the referenced advisory for more information.
MandrakeSoft has issued patches. Users are advised to see the attached advisory for more detail.
The Fedora Legacy project has released advisory FLSA-2004:2089 along with fixes to address multiple issues in RedHat Fedora Core 1, and RedHat Linux 7.3 and 9.0. Please see the referenced advisory for further information.
Mozilla Thunderbird 0.7
Mozilla Thunderbird 0.7.1
Mozilla Thunderbird 0.7.2
Mozilla Thunderbird 0.7.3
Mozilla Browser 1.7
Mozilla Browser 1.7.1
Mozilla Browser 1.7.2
Solution:
This issue has been addressed in Mozilla 1.7.3 and Thunderbird 0.8.
Conectiva has released an advisory (CLA-2004:877) to address various issues including this issue in Mozilla. This advisory contains updated Mozilla packages (1.7.3) for Conectiva Linux 9 and 10. Please see the referenced advisory for more information.
Gentoo has released an advisory (GLSA 200409-26) to address various issues in Mozilla Browsers. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their systems.
emerge sync
emerge -pv your-version
emerge your-version
RedHat Linux has released advisory RHSA-2004:486-18 along with fixes to address this, and other issues for RedHat Enterprise Linux operating systems. Please see the referenced advisory for further information on obtaining fixes.
HP has released an advisory (SSRT4826) dealing with this issue for their Tru64 UNIX platform. Please see the referenced advisory for more information.
SuSE Linux has released advisory SUSE-SA:2004:036 along with fixes dealing with this issue. Please see the referenced advisory for more information.
MandrakeSoft has issued patches. Users are advised to see the attached advisory for more detail.
The Fedora Legacy project has released advisory FLSA-2004:2089 along with fixes to address multiple issues in RedHat Fedora Core 1, and RedHat Linux 7.3 and 9.0. Please see the referenced advisory for further information.
Mozilla Thunderbird 0.7
-
Mozilla Thunderbird 0.8
http://www.mozilla.org/products/thunderbird/releases/
Mozilla Thunderbird 0.7.1
-
Mozilla Thunderbird 0.8
http://www.mozilla.org/products/thunderbird/releases/
Mozilla Thunderbird 0.7.2
-
Mozilla Thunderbird 0.8
http://www.mozilla.org/products/thunderbird/releases/
Mozilla Thunderbird 0.7.3
-
Mozilla Thunderbird 0.8
http://www.mozilla.org/products/thunderbird/releases/
Mozilla Browser 1.7
-
Mozilla Mozilla 1.7.3
http://www.mozilla.org/products/thunderbird/releases/
Mozilla Browser 1.7.1
-
Mozilla Mozilla 1.7.3
http://www.mozilla.org/products/thunderbird/releases/
Mozilla Browser 1.7.2
-
Mozilla Mozilla 1.7.3
http://www.mozilla.org/products/thunderbird/releases/
References
Mozilla Multiple URI Processing Heap Based Buffer Overflow Vulnerabilities
References:
References:
- Bugzilla Bug 258005 - heap overflows triggerd by "send page (Mozilla)
- Cisco NX-OS Download Page (Cisco)
- Mozilla Homepage (Mozilla Foundation)
- RHSA-2004:486-18 - Updated mozilla packages fix security issues (RedHat)
- VU#327560 - Mozilla "send page" feature contains a buffer overflow vulnerability (US-CERT)