Netscape/Mozilla JAR Remote Heap Corruption Vulnerability
BID:6185
Info
Netscape/Mozilla JAR Remote Heap Corruption Vulnerability
| Bugtraq ID: | 6185 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-1308 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 14 2002 12:00AM |
| Updated: | Jul 11 2009 07:16PM |
| Credit: | Discovery of vulnerability is credited to zen-parse. |
| Vulnerable: |
SGI ProPack 2.3 SGI ProPack 2.2.1 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux AS 2.1 Redhat Advanced Workstation for the Itanium Processor 2.1 Netscape Netscape 7.0 Netscape Netscape 6.2.3 Netscape Netscape 6.2.2 Netscape Netscape 6.2.1 Netscape Netscape 6.2 Mozilla Browser 1.1 Mozilla Browser 1.0.2 Mozilla Browser 1.0.1 Mozilla Browser 1.0 Mozilla Browser 0.9.9 Mozilla Browser 0.9.8 Mozilla Browser 0.9.7 Mozilla Browser 0.9.6 |
| Not Vulnerable: | |
Discussion
Netscape/Mozilla JAR Remote Heap Corruption Vulnerability
A vulnerability has been discovered in the JAR URI handler used by Netscape and Mozilla. By constructing a malformed JAR file containing invalid file length information, it is possible to cause heap corruption in a vulnerable browser.
When a client browser attempts to decompress a malicious JAR file, invalid values will be used to allocate buffer space for the inflated data. As there are no checks to prevent this, an overrun condition in the heap may occur if excessive data is decompressed.
A vulnerability has been discovered in the JAR URI handler used by Netscape and Mozilla. By constructing a malformed JAR file containing invalid file length information, it is possible to cause heap corruption in a vulnerable browser.
When a client browser attempts to decompress a malicious JAR file, invalid values will be used to allocate buffer space for the inflated data. As there are no checks to prevent this, an overrun condition in the heap may occur if excessive data is decompressed.
Solution / Fix
Netscape/Mozilla JAR Remote Heap Corruption Vulnerability
Solution:
Red Hat has released a security advisory (RHSA-2003:163-11) to address this issue in Red Hat enterprise Linux. Customers who are potentially affected by this vulnerability are advised to download and apply the appropriate fix as soon as possible. These fixes are available on the Red Hat Network, further information regarding obtaining and applying appropriate fixes is available in the referenced advisory.
Sun have made fixes available to address this issue in Sun Linux 5.0.7. Fixes are linked below.
Red Hat has released an updated advisory RHSA-2003:162-02 to address this issue. See referenced advisory for additional details regarding obtaining and applying fixes.
Red Hat has released advisory RHSA-2003:162-01 to address this issue. See referenced advisory for additional details.
Red Hat has released a security advisory (RHSA-2003-163) including fixes to address this issue in Advanced Workstation and Enterprise server releases. Fixes are available via the Red Hat Network (http://rhn.redhat.com). Further details can be found in the referenced advisory.
Mozilla Browser 0.9.9
SGI ProPack 2.2.1
SGI ProPack 2.3
Solution:
Red Hat has released a security advisory (RHSA-2003:163-11) to address this issue in Red Hat enterprise Linux. Customers who are potentially affected by this vulnerability are advised to download and apply the appropriate fix as soon as possible. These fixes are available on the Red Hat Network, further information regarding obtaining and applying appropriate fixes is available in the referenced advisory.
Sun have made fixes available to address this issue in Sun Linux 5.0.7. Fixes are linked below.
Red Hat has released an updated advisory RHSA-2003:162-02 to address this issue. See referenced advisory for additional details regarding obtaining and applying fixes.
Red Hat has released advisory RHSA-2003:162-01 to address this issue. See referenced advisory for additional details.
Red Hat has released a security advisory (RHSA-2003-163) including fixes to address this issue in Advanced Workstation and Enterprise server releases. Fixes are available via the Red Hat Network (http://rhn.redhat.com). Further details can be found in the referenced advisory.
Mozilla Browser 0.9.9
-
Red Hat mozilla-1.0.2-1.8.0.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/mozilla-1.0.2-1.8.0.i386.rpm -
Red Hat mozilla-1.0.2-2.7.1.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/mozilla-1.0.2-2.7.1.i386.rpm -
Red Hat mozilla-1.0.2-2.7.2.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/mozilla-1.0.2-2.7.2.i386.rpm -
Red Hat mozilla-1.0.2-2.7.3.i386.rpm
ftp://updates.redhat.com/7.3/en/os/i386/mozilla-1.0.2-2.7.3.i386.rpm -
Red Hat mozilla-chat-1.0.2-1.8.0.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/mozilla-chat-1.0.2-1.8.0.i386. rpm -
Red Hat mozilla-chat-1.0.2-2.7.1.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/mozilla-chat-1.0.2-2.7.1.i386. rpm -
Red Hat mozilla-chat-1.0.2-2.7.2.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/mozilla-chat-1.0.2-2.7.2.i386. rpm -
Red Hat mozilla-chat-1.0.2-2.7.3.i386.rpm
ftp://updates.redhat.com/7.3/en/os/i386/mozilla-chat-1.0.2-2.7.3.i386. rpm -
Red Hat mozilla-devel-1.0.2-1.8.0.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/mozilla-devel-1.0.2-1.8.0.i386 .rpm -
Red Hat mozilla-devel-1.0.2-2.7.1.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/mozilla-devel-1.0.2-2.7.1.i386 .rpm -
Red Hat mozilla-devel-1.0.2-2.7.2.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/mozilla-devel-1.0.2-2.7.2.i386 .rpm -
Red Hat mozilla-devel-1.0.2-2.7.3.i386.rpm
ftp://updates.redhat.com/7.3/en/os/i386/mozilla-devel-1.0.2-2.7.3.i386 .rpm -
Red Hat mozilla-dom-inspector-1.0.2-1.8.0.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/mozilla-dom-inspector-1.0.2-1. 8.0.i386.rpm -
Red Hat mozilla-dom-inspector-1.0.2-2.7.1.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/mozilla-dom-inspector-1.0.2-2. 7.1.i386.rpm -
Red Hat mozilla-dom-inspector-1.0.2-2.7.2.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/mozilla-dom-inspector-1.0.2-2. 7.2.i386.rpm -
Red Hat mozilla-dom-inspector-1.0.2-2.7.3.i386.rpm
ftp://updates.redhat.com/7.3/en/os/i386/mozilla-dom-inspector-1.0.2-2. 7.3.i386.rpm -
Red Hat mozilla-js-debugger-1.0.2-1.8.0.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/mozilla-js-debugger-1.0.2-1.8. 0.i386.rpm -
Red Hat mozilla-js-debugger-1.0.2-2.7.1.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/mozilla-js-debugger-1.0.2-2.7. 1.i386.rpm -
Red Hat mozilla-js-debugger-1.0.2-2.7.2.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/mozilla-js-debugger-1.0.2-2.7. 2.i386.rpm -
Red Hat mozilla-js-debugger-1.0.2-2.7.3.i386.rpm
ftp://updates.redhat.com/7.3/en/os/i386/mozilla-js-debugger-1.0.2-2.7. 3.i386.rpm -
Red Hat mozilla-mail-1.0.2-1.8.0.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/mozilla-mail-1.0.2-1.8.0.i386. rpm -
Red Hat mozilla-mail-1.0.2-2.7.1.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/mozilla-mail-1.0.2-2.7.1.i386. rpm -
Red Hat mozilla-mail-1.0.2-2.7.2.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/mozilla-mail-1.0.2-2.7.2.i386. rpm -
Red Hat mozilla-mail-1.0.2-2.7.3.i386.rpm
ftp://updates.redhat.com/7.3/en/os/i386/mozilla-mail-1.0.2-2.7.3.i386. rpm -
Red Hat mozilla-nspr-1.0.2-1.8.0.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/mozilla-nspr-1.0.2-1.8.0.i386. rpm -
Red Hat mozilla-nspr-1.0.2-2.7.1.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/mozilla-nspr-1.0.2-2.7.1.i386. rpm -
Red Hat mozilla-nspr-1.0.2-2.7.2.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/mozilla-nspr-1.0.2-2.7.2.i386. rpm -
Red Hat mozilla-nspr-1.0.2-2.7.3.i386.rpm
ftp://updates.redhat.com/7.3/en/os/i386/mozilla-nspr-1.0.2-2.7.3.i386. rpm -
Red Hat mozilla-nspr-devel-1.0.2-1.8.0.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/mozilla-nspr-devel-1.0.2-1.8.0 .i386.rpm -
Red Hat mozilla-nspr-devel-1.0.2-2.7.1.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/mozilla-nspr-devel-1.0.2-2.7.1 .i386.rpm -
Red Hat mozilla-nspr-devel-1.0.2-2.7.2.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/mozilla-nspr-devel-1.0.2-2.7.2 .i386.rpm -
Red Hat mozilla-nspr-devel-1.0.2-2.7.3.i386.rpm
ftp://updates.redhat.com/7.3/en/os/i386/mozilla-nspr-devel-1.0.2-2.7.3 .i386.rpm -
Red Hat mozilla-nss-1.0.2-1.8.0.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/mozilla-nss-1.0.2-1.8.0.i386.r pm -
Red Hat mozilla-nss-1.0.2-2.7.1.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/mozilla-nss-1.0.2-2.7.1.i386.r pm -
Red Hat mozilla-nss-1.0.2-2.7.2.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/mozilla-nss-1.0.2-2.7.2.i386.r pm -
Red Hat mozilla-nss-1.0.2-2.7.3.i386.rpm
ftp://updates.redhat.com/7.3/en/os/i386/mozilla-nss-1.0.2-2.7.3.i386.r pm -
Red Hat mozilla-nss-devel-1.0.2-1.8.0.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/mozilla-nss-devel-1.0.2-1.8.0. i386.rpm -
Red Hat mozilla-nss-devel-1.0.2-2.7.1.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/mozilla-nss-devel-1.0.2-2.7.1. i386.rpm -
Red Hat mozilla-nss-devel-1.0.2-2.7.2.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/mozilla-nss-devel-1.0.2-2.7.2. i386.rpm -
Red Hat mozilla-nss-devel-1.0.2-2.7.3.i386.rpm
ftp://updates.redhat.com/7.3/en/os/i386/mozilla-nss-devel-1.0.2-2.7.3. i386.rpm -
Red Hat mozilla-psm-1.0.2-1.8.0.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/mozilla-psm-1.0.2-1.8.0.i386.r pm -
Red Hat mozilla-psm-1.0.2-2.7.1.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/mozilla-psm-1.0.2-2.7.1.i386.r pm -
Red Hat mozilla-psm-1.0.2-2.7.2.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/mozilla-psm-1.0.2-2.7.2.i386.r pm -
Red Hat mozilla-psm-1.0.2-2.7.3.i386.rpm
ftp://updates.redhat.com/7.3/en/os/i386/mozilla-psm-1.0.2-2.7.3.i386.r pm
SGI ProPack 2.2.1
SGI ProPack 2.3
-
SGI Patch 10031
ftp://oss.sgi.com/projects/sgi_propack/download/2.3/updates/RPMS