FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2008-5282

This CVE name corresponds to:

Entered Topic
2009-02-09 amaya -- multiple buffer overflow vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2008-5282
Phase Assigned(20081128)

Description

Multiple stack-based buffer overflows in W3C Amaya Web Browser 10.0.1 allow remote attackers to execute arbitrary code via (1) a link with a long HREF attribute, and (2) a DIV tag with a long id attribute.

References

Source Reference
BUGTRAQ 20081124 Amaya (URL Bar) Remote Stack Overflow Vulnerability
BUGTRAQ 20081124 Amaya (id) Remote Stack Overflow Vulnerability
MISC http://www.bmgsec.com.au/advisory/40/
MISC http://www.bmgsec.com.au/advisory/41/
BID 32442
VUPEN ADV-2008-3255
OSVDB 50282
OSVDB 50283
SECUNIA 32848
SREASON 4657