Mozilla Firefox SOCKS5 Proxy Response Denial of Service Vulnerability
BID:35925
Info
Mozilla Firefox SOCKS5 Proxy Response Denial of Service Vulnerability
| Bugtraq ID: | 35925 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2009-2470 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 03 2009 12:00AM |
| Updated: | Apr 13 2015 09:47PM |
| Credit: | Andrej Andolsek |
| Vulnerable: |
Sun OpenSolaris build snv_121 Sun OpenSolaris build snv_120 Sun OpenSolaris build snv_119 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux Optional Productivity Application 5.4.z server Redhat Enterprise Linux Optional Productivity Application 5 server Redhat Enterprise Linux ES 4.8.z Redhat Enterprise Linux ES 4 Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux AS 4.8.z Redhat Enterprise Linux AS 4 Redhat Desktop 4.0 Pardus Linux 2009 0 Pardus Linux 2008 0 Mozilla Firefox 3.5.1 Mozilla Firefox 3.5 Mozilla Firefox 3.0.11 Mozilla Firefox 3.0.10 Mozilla Firefox 3.0.9 Mozilla Firefox 3.0.8 Mozilla Firefox 3.0.7 Beta Mozilla Firefox 3.0.7 Mozilla Firefox 3.0.6 Mozilla Firefox 3.0.5 Mozilla Firefox 3.0.4 Mozilla Firefox 3.0.3 Mozilla Firefox 3.0.2 Mozilla Firefox 3.0.1 Mozilla Firefox 3.1 Beta 3 Mozilla Firefox 3.1 Beta 2 Mozilla Firefox 3.1 Beta 1 Mozilla Firefox 3.0 Beta 5 Mozilla Firefox 3.0 |
| Not Vulnerable: |
Sun OpenSolaris build snv_122 Mozilla Firefox 3.5.2 Mozilla Firefox 3.0.12 |
Discussion
Mozilla Firefox SOCKS5 Proxy Response Denial of Service Vulnerability
Mozilla Firefox is prone to a remote denial-of-service vulnerability.
Successful exploits can allow attackers to corrupt response data streams from proxy servers, which may trigger a denial-of-service condition in the browser. Given the nature of this issue, memory corruption or code execution might be possible, but has not been confirmed.
Versions prior to Firefox 3.5.2 and 3.0.12 are vulnerable.
Mozilla Firefox is prone to a remote denial-of-service vulnerability.
Successful exploits can allow attackers to corrupt response data streams from proxy servers, which may trigger a denial-of-service condition in the browser. Given the nature of this issue, memory corruption or code execution might be possible, but has not been confirmed.
Versions prior to Firefox 3.5.2 and 3.0.12 are vulnerable.
Exploit / POC
Mozilla Firefox SOCKS5 Proxy Response Denial of Service Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Mozilla Firefox SOCKS5 Proxy Response Denial of Service Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Mozilla Firefox SOCKS5 Proxy Response Denial of Service Vulnerability
References:
References:
- Mozilla Homepage (Mozilla Foundation)
- 266148 Firefox (Sun)
- Mozilla Foundation Security Advisory 2009-38 (Mozilla Foundation)
- RHSA-2010:0153 thunderbird security update (Red Hat)
- RHSA-2010:0154 thunderbird security update (Red Hat)