Lucene search

K
mozillaMozilla FoundationMFSA2006-49
HistoryJul 25, 2006 - 12:00 a.m.

Heap buffer overwrite on malformed VCard — Mozilla

2006-07-2500:00:00
Mozilla Foundation
www.mozilla.org
20

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.379

Percentile

97.2%

A VCard attachment with a malformed base64 field (such as a photo) can trigger a heap buffer overwrite. These have proven exploitable in the past, though in this case the overwrite is accompanied by an integer underflow that would attempt to copy more data than the typical machine has, leading to a crash.

Affected configurations

Vulners
Node
mozillaseamonkeyRange<1.0.3
OR
mozillathunderbirdRange<1.5.0.5
VendorProductVersionCPE
mozillaseamonkey*cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*
mozillathunderbird*cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.379

Percentile

97.2%