FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2008-5502

This CVE name corresponds to:

Entered Topic
2008-12-19 mozilla -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2008-5502
Phase Assigned(20081212)

Description

The layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service (crash) via vectors that trigger memory corruption, related to the GetXMLEntity and FastAppendChar functions.

References

Source Reference
MISC https://bugzilla.mozilla.org/show_bug.cgi?id=458679
CONFIRM http://www.mozilla.org/security/announce/2008/mfsa2008-60.html
MANDRIVA MDVSA-2008:245
REDHAT RHSA-2008:1036
REDHAT RHSA-2008:1037
REDHAT RHSA-2009:0002
SUNALERT 256408
UBUNTU USN-690-1
BID 32882
OVAL oval:org.mitre.oval:def:10001
SECTRACK 1021417
SECUNIA 33216
SECUNIA 33188
SECUNIA 33189
SECUNIA 33203
SECUNIA 33421
SECUNIA 34501
VUPEN ADV-2009-0977
XF firefox-js-deflatestring-code-execution(47408)