| Definition Id: oval:org.mitre.oval:def:100052 |
Date: 2007-04-23 |
| Title: |
Mozilla Malicious news: Vulnerability |
| Description: |
Heap-based buffer overflow in MSG_UnEscapeSearchUrl in nsNNTPProtocol.cpp for Mozilla 1.7.3 and earlier allows remote attackers to cause a denial of service (application crash) via an NNTP URL (news:) with a trailing '\' (backslash) character, which prevents a string from being NULL terminated. |
| Version: |
5 |
Class: |
vulnerability |
| Status: |
ACCEPTED |
Reference(s): |
CVE-2004-1316
|
| Family: |
windows |
| Platform(s): |
Microsoft Windows NT Microsoft Windows 2000 Microsoft Windows XP Microsoft Windows Server 2003 |
Product(s): |
mozilla Thunderbird |
| Definition Synopsis: |
- Mozilla Thunderbird version 0.8 or earlier is installed
- OR Mozilla Suite version 1.7.4 or earlier is installed
|