Mozilla Firefox Unicode Data Remote Denial of Service Vulnerability
BID:35707
Info
Mozilla Firefox Unicode Data Remote Denial of Service Vulnerability
| Bugtraq ID: | 35707 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2009-2479 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 15 2009 12:00AM |
| Updated: | Jul 23 2009 04:36PM |
| Credit: | Andrew Haynes and Simon Berry-Byrne |
| Vulnerable: |
Red Hat Fedora 11 Mozilla XULRunner 1.9.1 Mozilla XULRunner 1.9.1.1 Mozilla XULRunner 1.9 Mozilla Firefox 3.5.1 Mozilla Firefox 3.5 Mozilla Firefox 3.0.11 Mozilla Firefox 3.0.10 Mozilla Firefox 3.0.9 Mozilla Firefox 3.0.8 Mozilla Firefox 3.0.7 Mozilla Firefox 3.0.6 Mozilla Firefox 3.0.5 Mozilla Firefox 3.0.4 Mozilla Firefox 3.0.3 Mozilla Firefox 3.0.2 Mozilla Firefox 3.0.1 Mozilla Firefox 3.0 |
| Not Vulnerable: | |
Discussion
Mozilla Firefox Unicode Data Remote Denial of Service Vulnerability
Mozilla Firefox is prone to a remote denial-of-service vulnerability.
Successful exploits may allow an attacker to deny service to legitimate users.
NOTE: This issue cannot be exploited to execute code.
The issue affects Firefox 3.5.1 and prior versions.
Mozilla Firefox is prone to a remote denial-of-service vulnerability.
Successful exploits may allow an attacker to deny service to legitimate users.
NOTE: This issue cannot be exploited to execute code.
The issue affects Firefox 3.5.1 and prior versions.
Exploit / POC
Mozilla Firefox Unicode Data Remote Denial of Service Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
Mozilla Firefox Unicode Data Remote Denial of Service Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Mozilla Firefox Unicode Data Remote Denial of Service Vulnerability
References:
References:
- Bug 504342 - (CVE-2009-2479) Investigate milw0rm 9158 "unicode stack overflow" (Arzhel Younsi [:XioNoX])
- milw0rm 9158 �??stack overflow�?� crash not exploitable (CVE-2009-2479) (Mozilla)
- Vendor Homepage (Mozilla Foundation)