Mozilla Browser Vcard Handling Remote Buffer Overflow Vulnerability
BID:11174
Info
Mozilla Browser Vcard Handling Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 11174 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2004-0903 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 14 2004 12:00AM |
| Updated: | Aug 05 2010 07:46PM |
| Credit: | Discovery is credited to Georgi Guninski <[email protected]>. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 8 SuSE Linux Desktop 1.0 SuSE Linux 8.1 SuSE Linux 9.1 SuSE Linux 9 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 S.u.S.E. Linux Personal 8.2 Redhat Linux 9.0 i386 Redhat Linux 7.3 i686 Redhat Linux 7.3 i386 Redhat Linux 7.3 Redhat Fedora Core1 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux WS 2.1 IA64 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux ES 2.1 IA64 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux AS 3 Redhat Enterprise Linux AS 2.1 IA64 Redhat Enterprise Linux AS 2.1 Redhat Desktop 3.0 Redhat Advanced Workstation for the Itanium Processor 2.1 IA64 Redhat Advanced Workstation for the Itanium Processor 2.1 Netscape Navigator 7.2 Netscape Navigator 7.1 Netscape Navigator 7.0.2 Netscape Navigator 7.0 Mozilla Thunderbird 0.7.3 Mozilla Thunderbird 0.7.2 Mozilla Thunderbird 0.7.1 Mozilla Thunderbird 0.7 Mozilla Thunderbird 0.6 Mozilla Browser 1.7.3 Mozilla Browser 1.7.2 Mozilla Browser 1.7.1 Mozilla Browser 1.7 rc3 Mozilla Browser 1.7 |
| Not Vulnerable: |
Mozilla Thunderbird 0.8 Mozilla Browser 1.7.3 |
Discussion
Mozilla Browser Vcard Handling Remote Buffer Overflow Vulnerability
Mozilla Browser is reported prone to a remote buffer overflow vulnerability when processing malicious vcard files. This issue presents itself due to insufficient boundary checks performed by the application and may allow a remote attacker to gain unauthorized access to a vulnerable computer.
It is reported that the issue originates in the 'nsVCardObj.cpp' file and may allow an attacker to overflow a finite buffer by creating a malformed vcard (vcf) file and sending the file to a vulnerable user in email. Reportedly, this issue occurs when the mail is previewed in the browser.
These vulnerabilities were researched on Mozilla 1.7, however, other versions may be affected as well. Thunderbird 0.7 was tested as well.
Mozilla Browser is reported prone to a remote buffer overflow vulnerability when processing malicious vcard files. This issue presents itself due to insufficient boundary checks performed by the application and may allow a remote attacker to gain unauthorized access to a vulnerable computer.
It is reported that the issue originates in the 'nsVCardObj.cpp' file and may allow an attacker to overflow a finite buffer by creating a malformed vcard (vcf) file and sending the file to a vulnerable user in email. Reportedly, this issue occurs when the mail is previewed in the browser.
These vulnerabilities were researched on Mozilla 1.7, however, other versions may be affected as well. Thunderbird 0.7 was tested as well.
Exploit / POC
Mozilla Browser Vcard Handling Remote Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Mozilla Browser Vcard Handling Remote Buffer Overflow Vulnerability
Solution:
This issue has been addressed in Mozilla 1.7.3 and Thunderbird 0.8.
Conectiva has released an advisory (CLA-2004:877) to address various issues including this issue in Mozilla. This advisory contains updated Mozilla packages (1.7.3) for Conectiva Linux 9 and 10. Please see the referenced advisory for more information.
Gentoo has released an advisory (GLSA 200409-26) to address various issues in Mozilla Browsers. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their systems.
emerge sync
emerge -pv your-version
emerge your-version
RedHat Linux has released advisory RHSA-2004:486-18 along with fixes to address this, and other issues for RedHat Enterprise Linux operating systems. Please see the referenced advisory for further information on obtaining fixes.
HP has released an advisory (SSRT4826) dealing with this issue for their Tru64 UNIX platform. Please see the referenced advisory for more information.
SuSE Linux has released advisory SUSE-SA:2004:036 along with fixes dealing with this issue. Please see the referenced advisory for more information.
The Fedora Legacy project has released advisory FLSA-2004:2089 along with fixes to address multiple issues in RedHat Fedora Core 1, and RedHat Linux 7.3 and 9.0. Please see the referenced advisory for further information.
Mozilla Thunderbird 0.6
Mozilla Thunderbird 0.7
Mozilla Thunderbird 0.7.1
Mozilla Thunderbird 0.7.2
Mozilla Thunderbird 0.7.3
Mozilla Browser 1.7
Mozilla Browser 1.7 rc3
Mozilla Browser 1.7.1
Mozilla Browser 1.7.2
Solution:
This issue has been addressed in Mozilla 1.7.3 and Thunderbird 0.8.
Conectiva has released an advisory (CLA-2004:877) to address various issues including this issue in Mozilla. This advisory contains updated Mozilla packages (1.7.3) for Conectiva Linux 9 and 10. Please see the referenced advisory for more information.
Gentoo has released an advisory (GLSA 200409-26) to address various issues in Mozilla Browsers. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their systems.
emerge sync
emerge -pv your-version
emerge your-version
RedHat Linux has released advisory RHSA-2004:486-18 along with fixes to address this, and other issues for RedHat Enterprise Linux operating systems. Please see the referenced advisory for further information on obtaining fixes.
HP has released an advisory (SSRT4826) dealing with this issue for their Tru64 UNIX platform. Please see the referenced advisory for more information.
SuSE Linux has released advisory SUSE-SA:2004:036 along with fixes dealing with this issue. Please see the referenced advisory for more information.
The Fedora Legacy project has released advisory FLSA-2004:2089 along with fixes to address multiple issues in RedHat Fedora Core 1, and RedHat Linux 7.3 and 9.0. Please see the referenced advisory for further information.
Mozilla Thunderbird 0.6
-
Mozilla Thunderbird 0.8
http://www.mozilla.org/products/thunderbird/releases/
Mozilla Thunderbird 0.7
-
Mozilla Thunderbird 0.8
http://www.mozilla.org/products/thunderbird/releases/
Mozilla Thunderbird 0.7.1
-
Mozilla Thunderbird 0.8
http://www.mozilla.org/products/thunderbird/releases/
Mozilla Thunderbird 0.7.2
-
Mozilla Thunderbird 0.8
http://www.mozilla.org/products/thunderbird/releases/
Mozilla Thunderbird 0.7.3
-
Mozilla Thunderbird 0.8
http://www.mozilla.org/products/thunderbird/releases/
Mozilla Browser 1.7
-
Mozilla Mozilla 1.7.3
http://www.mozilla.org/releases/
Mozilla Browser 1.7 rc3
-
Mozilla Mozilla 1.7.3
http://www.mozilla.org/releases/
Mozilla Browser 1.7.1
-
Mozilla Mozilla 1.7.3
http://www.mozilla.org/releases/
Mozilla Browser 1.7.2
-
Mozilla Mozilla 1.7.3
http://www.mozilla.org/releases/
References
Mozilla Browser Vcard Handling Remote Buffer Overflow Vulnerability
References:
References:
- Bugzilla Bug 257314 - stack based buffer overflow with vcards when previewing em (Georgi Guninski
) - Cisco NX-OS Download Page (Cisco)
- Mozilla Homepage (Mozilla Foundation)
- RHSA-2004:486-18 - Updated mozilla packages fix security issues (RedHat)
- VU#414240 - Mozilla Mail vulnerable to buffer overflow via "writeGroup()" functi (US-CERT)