Mozilla Chatzilla IRC URI Handler Memory Corruption Vulnerability
BID:9104
Info
Mozilla Chatzilla IRC URI Handler Memory Corruption Vulnerability
| Bugtraq ID: | 9104 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 26 2003 12:00AM |
| Updated: | Nov 26 2003 12:00AM |
| Credit: | Discovery is credited to dr_insane. |
| Vulnerable: |
Mozilla Browser 1.5 Mozilla Browser 1.4 b Mozilla Browser 1.4 a Mozilla Browser 1.4 Mozilla Browser 0.9.48 Mozilla Browser 0.9.35 Mozilla Browser 0.9.4 .1 Mozilla Browser 0.9.4 Mozilla Browser 0.9.3 |
| Not Vulnerable: | |
Discussion
Mozilla Chatzilla IRC URI Handler Memory Corruption Vulnerability
The Mozilla Chatzilla IRC URI handler is prone to a memory corruption vulnerability when handling URIs of excessive length. This will cause the browser to crash. Though unconfirmed, this issue could theoretically be exploited to execute arbitrary code if an attacker can corrupt specific regions of memory and control execution flow of the program.
This issue was reported for Mozilla on Windows platforms. It is not known if other versions are similarly affected.
This issue may be related to BID 4637.
The Mozilla Chatzilla IRC URI handler is prone to a memory corruption vulnerability when handling URIs of excessive length. This will cause the browser to crash. Though unconfirmed, this issue could theoretically be exploited to execute arbitrary code if an attacker can corrupt specific regions of memory and control execution flow of the program.
This issue was reported for Mozilla on Windows platforms. It is not known if other versions are similarly affected.
This issue may be related to BID 4637.
Exploit / POC
Mozilla Chatzilla IRC URI Handler Memory Corruption Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Mozilla Chatzilla IRC URI Handler Memory Corruption Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Mozilla Chatzilla IRC URI Handler Memory Corruption Vulnerability
References:
References:
- Mozilla Homepage (Mozilla Foundation)