Mozilla Invalid Pointer Dereference Vulnerability
BID:11440
Info
Mozilla Invalid Pointer Dereference Vulnerability
| Bugtraq ID: | 11440 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2004-1614 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 18 2004 12:00AM |
| Updated: | Jul 12 2009 08:06AM |
| Credit: | Discovery is credited to Michal Zalewski. |
| Vulnerable: |
Mozilla Browser 1.8 Alpha 2 Mozilla Browser 1.7.3 Mozilla Browser 1.7.2 Mozilla Browser 1.7.1 Mozilla Browser 1.7 rc3 Mozilla Browser 1.7 Mozilla Browser 1.6 Mozilla Browser 1.5 Mozilla Browser 1.4.2 Mozilla Browser 1.4.1 Mozilla Browser 1.4 b Mozilla Browser 1.4 a Mozilla Browser 1.4 Mozilla Browser 1.3.1 Mozilla Browser 1.3 Mozilla Browser 1.2.1 Mozilla Browser 1.2 Beta Mozilla Browser 1.2 Alpha Mozilla Browser 1.2 Mozilla Browser 1.1 Beta Mozilla Browser 1.1 Alpha Mozilla Browser 1.1 Mozilla Browser 1.0.2 Mozilla Browser 1.0.1 Mozilla Browser 1.0 RC2 Mozilla Browser 1.0 RC1 Mozilla Browser 1.0 |
| Not Vulnerable: | |
Discussion
Mozilla Invalid Pointer Dereference Vulnerability
A vulnerability exists in Mozilla that will most likely cause a denial of service. The source of the issue is that an invalid pointer is dereferenced when the browser renders an unusual combination of visual elements.
Although this issue was reported in the Mozilla browser, other applications based on the same code may also be affected such as Firefox/Thunderbird/Netscape.
A vulnerability exists in Mozilla that will most likely cause a denial of service. The source of the issue is that an invalid pointer is dereferenced when the browser renders an unusual combination of visual elements.
Although this issue was reported in the Mozilla browser, other applications based on the same code may also be affected such as Firefox/Thunderbird/Netscape.
Exploit / POC
Mozilla Invalid Pointer Dereference Vulnerability
This issue was discovered with the mangleme Web fuzzer:
http://lcamtuf.coredump.cx/soft/mangleme.tgz
A proof-of-concept is available at the following Web page:
http://lcamtuf.coredump.cx/mangleme/gallery/mozilla_die2.html
---
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
This issue was discovered with the mangleme Web fuzzer:
http://lcamtuf.coredump.cx/soft/mangleme.tgz
A proof-of-concept is available at the following Web page:
http://lcamtuf.coredump.cx/mangleme/gallery/mozilla_die2.html
---
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Mozilla Invalid Pointer Dereference Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.