FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2008-0017

This CVE name corresponds to:

Entered Topic
2008-11-13 mozilla -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2008-0017
Phase Assigned(20071213)

Description

The http-index-format MIME type parser (nsDirIndexParser) in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 does not check for an allocation failure, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP index response with a crafted 200 header, which triggers memory corruption and a buffer overflow.

References

Source Reference
ISS 20081113 Mozilla Unchecked Allocation Remote Code Execution
MISC https://bugzilla.mozilla.org/show_bug.cgi?id=443299
CONFIRM http://www.mozilla.org/security/announce/2008/mfsa2008-54.html
DEBIAN DSA-1669
DEBIAN DSA-1671
DEBIAN DSA-1697
FEDORA FEDORA-2008-9669
FEDORA FEDORA-2008-9667
MANDRIVA MDVSA-2008:228
MANDRIVA MDVSA-2008:230
REDHAT RHSA-2008:0977
REDHAT RHSA-2008:0978
SUNALERT 256408
SUSE SUSE-SA:2008:055
UBUNTU USN-667-1
CERT TA08-319A
BID 32281
OVAL oval:org.mitre.oval:def:11005
SECTRACK 1021185
SECUNIA 34501
SECUNIA 32684
SECUNIA 32713
SECUNIA 32778
SECUNIA 32853
VUPEN ADV-2008-3146
SECUNIA 32721
SECUNIA 32845
SECUNIA 32693
SECUNIA 32694
SECUNIA 32695
SECUNIA 32714
SECUNIA 33433
VUPEN ADV-2009-0977