MuPDF Firefox Plugin 'pdfmoz_onmouse()' Function Stack Buffer Overflow Vulnerability
BID:47739
Info
MuPDF Firefox Plugin 'pdfmoz_onmouse()' Function Stack Buffer Overflow Vulnerability
| Bugtraq ID: | 47739 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2011-0341 |
| Remote: | Yes |
| Local: | No |
| Published: | May 06 2011 12:00AM |
| Updated: | Mar 19 2015 09:15AM |
| Credit: | Stefan Cornelius, Secunia Research. |
| Vulnerable: |
Artifex Software MuPDF Firefox Plugin 2008.09.02 |
| Not Vulnerable: | |
Discussion
MuPDF Firefox Plugin 'pdfmoz_onmouse()' Function Stack Buffer Overflow Vulnerability
MuPDF Firefox plugin is prone to a stack-based buffer-overflow vulnerability because the application fails to perform adequate boundary-checks on user-supplied input..
An attacker can exploit this issue to execute arbitrary machine code in the context of the application. Failed exploit attempts will likely crash the webserver, denying service to legitimate users.
MuPDF Firefox plugin 2008.09.02 is vulnerable; other versions may also be affected.
MuPDF Firefox plugin is prone to a stack-based buffer-overflow vulnerability because the application fails to perform adequate boundary-checks on user-supplied input..
An attacker can exploit this issue to execute arbitrary machine code in the context of the application. Failed exploit attempts will likely crash the webserver, denying service to legitimate users.
MuPDF Firefox plugin 2008.09.02 is vulnerable; other versions may also be affected.
Exploit / POC
MuPDF Firefox Plugin 'pdfmoz_onmouse()' Function Stack Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
MuPDF Firefox Plugin 'pdfmoz_onmouse()' Function Stack Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
MuPDF Firefox Plugin 'pdfmoz_onmouse()' Function Stack Buffer Overflow Vulnerability
References:
References:
- MuPDF Firefox Plug-in (Artifex Software)
- Secunia Research: MuPDF Firefox Plugin Buffer Overflow Vulnerability (Secunia)