CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS
Percentile
97.3%
The crypto.signText function in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote attackers to execute arbitrary code via certain optional Certificate Authority name arguments, which causes an invalid array index and triggers a buffer overflow.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
Debian | 999 | all | firefox | < 1.5.dfsg+1.5.0.4-1 | firefox_1.5.dfsg+1.5.0.4-1_all.deb |
Debian | 12 | all | thunderbird | < 1.5.0.4-1 | thunderbird_1.5.0.4-1_all.deb |
Debian | 11 | all | thunderbird | < 1.5.0.4-1 | thunderbird_1.5.0.4-1_all.deb |
Debian | 999 | all | thunderbird | < 1.5.0.4-1 | thunderbird_1.5.0.4-1_all.deb |
Debian | 13 | all | thunderbird | < 1.5.0.4-1 | thunderbird_1.5.0.4-1_all.deb |