漏洞信息详情
Netscape/Mozilla IRC缓冲区溢出漏洞
- CNNVD编号:CNNVD-200206-003
- 危害等级: 高危
- CVE编号:
CVE-2002-0593
- 漏洞类型:
缓冲区溢出
- 发布时间:
2002-06-18
- 威胁类型:
远程
- 更新时间:
2005-10-20
- 厂 商:
mozilla - 漏洞来源:
Discovery of this … -
漏洞简介
Netscape 6和Mozilla 1.0 RC1及其之前版本存在缓冲区溢出漏洞。远程攻击者借助IRC URI中的超长通道名导致服务拒绝(崩溃)且可能执行任意代码。
漏洞公告
FreeBSD has released an updated version of ports which contains versions mozilla-1.0.rc1_2,1 of Mozilla for FreeBSD, and linux-mozilla-1.0_1 of Mozilla for Linux. The new version of ports may be downloaded from a ports mirror. See referenced advisory for more information.
Fixes are available:
Mozilla Browser 0.9.9
-
Mozilla mozilla-source-1.0rc3.tar.gz
http://ftp.mozilla.org/pub/mozilla/releases/mozilla1.0rc3/src/mozilla-
source-1.0rc3.tar.gz
Mozilla Browser 1.0 RC1
-
Conectiva mozilla-1.0rc2-1U60_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/6.0/RPMS/mozilla-1.0rc2-1U60_1cl.i
386.rpm -
Conectiva mozilla-1.0rc2-1U60_1cl.src.rpmSource RPM.
ftp://atualizacoes.conectiva.com.br/6.0/SRPMS/mozilla-1.0rc2-1U60_1cl.
src.rpm -
Conectiva mozilla-1.0rc2-1U70_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/mozilla-1.0rc2-1U70_1cl.i
386.rpm -
Conectiva mozilla-1.0rc2-1U70_1cl.src.rpmSource RPM.
ftp://atualizacoes.conectiva.com.br/7.0/SRPMS/mozilla-1.0rc2-1U70_1cl.
src.rpm -
Conectiva mozilla-1.0rc2-1U8_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/mozilla-1.0rc2-1U8_1cl.i386
.rpm -
Conectiva mozilla-1.0rc2-1U8_1cl.src.rpmSource RPM.
ftp://atualizacoes.conectiva.com.br/8/SRPMS/mozilla-1.0rc2-1U8_1cl.src
.rpm -
Conectiva mozilla-devel-1.0rc2-1U60_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/6.0/RPMS/mozilla-devel-1.0rc2-1U60
_1cl.i386.rpm -
Conectiva mozilla-devel-1.0rc2-1U70_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/mozilla-devel-1.0rc2-1U70
_1cl.i386.rpm -
Conectiva mozilla-devel-1.0rc2-1U8_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/mozilla-devel-1.0rc2-1U8_1c
l.i386.rpm -
Conectiva mozilla-devel-static-1.0rc2-1U70_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/mozilla-devel-static-1.0r
c2-1U70_1cl.i386.rpm -
Conectiva mozilla-devel-static-1.0rc2-1U8_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/mozilla-devel-static-1.0rc2
-1U8_1cl.i386.rpm -
Conectiva mozilla-irc-1.0rc2-1U70_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/mozilla-irc-1.0rc2-1U70_1
cl.i386.rpm -
Conectiva mozilla-irc-1.0rc2-1U8_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/mozilla-irc-1.0rc2-1U8_1cl.
i386.rpm -
Conectiva mozilla-mail-1.0rc2-1U70_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/mozilla-mail-1.0rc2-1U70_
1cl.i386.rpm -
Conectiva mozilla-mail-1.0rc2-1U8_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/mozilla-mail-1.0rc2-1U8_1cl
.i386.rpm -
Conectiva mozilla-psm-1.0rc2-1U70_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/mozilla-psm-1.0rc2-1U70_1
cl.i386.rpm -
Conectiva mozilla-psm-1.0rc2-1U8_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/mozilla-psm-1.0rc2-1U8_1cl.
i386.rpm -
Mozilla mozilla-source-1.0rc3.tar.gz
http://ftp.mozilla.org/pub/mozilla/releases/mozilla1.0rc3/src/mozilla-
source-1.0rc3.tar.gz
参考网址
来源: BID
名称: 4637
链接:http://www.securityfocus.com/bid/4637
来源: BUGTRAQ
名称: 20020430 RE: Reading local files in Netscape 6 and Mozilla (GM#001-NS)
链接:http://online.securityfocus.com/archive/1/270249
来源: CONECTIVA
名称: CLA-2002:490
链接:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000490
来源: XF
名称: mozilla-netscape-irc-bo(8976)
链接:http://www.iss.net/security_center/static/8976.php
来源: SECUNIA
名称: 8039
链接:http://secunia.com/advisories/8039